The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

web client ssl

Prev Next

To configure security for the HTTP/HTTPS client, use the web client command in configuration mode.

Syntax

[no] web client ssl ca-list {none | default-ca-list}

[no] web client ssl cert-verify

[no] web client ssl cipher-list {original | fips | cc-ndcpp | fips-and-cc-ndcpp | high-security | compatible}

[no] web client ssl min-version {tls1 | tls1.1 | tls1.2}

Parameters

ssl ca-list {none | default-ca-list}

Configures supplemental CA certificates for the verification of server certificates during HTTPS file transfers:

  • none—No supplemental list; use built-in list only.

  • default-ca-list—Default supplemental CA certificate list

ssl cert-verify

Enables the verification of server certificates during HTTPS file transfers.

ssl cipher-list {original | fips | cc-ndcpp | fips-and-cc-ndcpp | high-security | compatible}

Configures the SSL settings:

  • original—Original Trellix cipher list (maximum compatibility)

  • fips—Compliant with FIPS

  • cc-ndcpp—Compliant with CC-NDPP

  • fips-and-cc-ndcpp—Compliant with both FIPS and CC-NDPP

  • high-security—High security (might include ciphers not compliant with FIPS or CC-NDPP)

  • compatible—Improved security while maintaining backward compatibility

{tls1 | tls1.1 | tls1.2}

Configures the minimum required version of the SSL protocol:

  • tls1—Requires TLSv1 or higher.

  • tls1.1—Requires TLSv1.1 or higher.

  • tls1.2—Requires TLSv1.2 or higher (default).

Example

The following example enables the verification of server certificates during HTTPS file transfers:

hostname (config) # web client ssl cert-verify

User role

Admin or Operator

Command mode

Config

Supported appliances

  • Command introduced in Release 7.6.0.