Trendmicro application identified as "ssl" despite of proper SNI, CN, SAN.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Trendmicro application identified as "ssl" despite of proper SNI, CN, SAN.

L0 Member
  • We have the Trend Micro agent installed on the endpoints, and it is running smoothly. However, the application is still being identified as "ssl", even though the packet captures show the correct SNI value in the Client Hello. In the Server Hello, both the SAN and CN fields contain multiple wildcard entries ending with *.trendmicro.com.

  • The URL category is successfully identified as “Trendmicro.”

We filtered for the Server Hello packets and confirmed that the certificate includes the Common Name and SAN fields with multiple wildcard entries ending in *.trendmicro.com.

We are not opting for App Override or creating a custom application because the other firewalls are able to identify this traffic correctly even without decryption.

0 REPLIES 0
  • 31 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!