Validation of Peer Certificate

AsyncOS provides a common configuration to control X.509 validation of the peer certificate for the following services under SSL configuration during TLS communication:

  • Outbound SMTP

  • LDAP

  • Updater

  • Alert over TLS

  • Syslog Server

  • Smart Licensing Server

  • Security Services Exchange Connector

  • Security Services Exchange Server

However, you must manually enable the X.509 validation of the peer certificate for Outbound SMTP, LDAP, Updater, and Alert over TLS. The X.509 validation of the peer certificate for the Syslog Server, Smart Licensing Server, Security Services Exchange Connector, and Security Services Exchange Server is performed by default.

You can configure the X.509 validation of the peer certificate using the web interface or CLI.

Related Topics