Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security engineer is developing a custom integration for Cortex XSOAR that interacts with an external service requiring client certificate authentication (mTLS). The service provides a client certificate file (`client.crt`) and a private key file (`client.key`). How should these files be securely configured within the integration instance to enable mTLS?

  1. AUpload `client.crt` and `client.key` as regular integration parameters, then reference their paths in the HTTP request.
  2. BUpload `client.crt` and `client.key` as file-type integration parameters, which XSOAR stores securely and provides paths to the integration.
  3. CPlace `client.crt` and `client.key` in the `/opt/demisto/certs/` directory on the XSOAR server, then reference them by name.
  4. DStore the `client.crt` and `client.key` files directly in the integration's Python code as base64 encoded strings.
Show answer & explanation

Correct answer: B. Upload `client.crt` and `client.key` as file-type integration parameters, which XSOAR stores securely and provides paths to the integration.

Cortex XSOAR provides a secure mechanism for handling sensitive files like client certificates and private keys. By uploading them as file-type integration parameters, XSOAR encrypts and stores them, then exposes their secure paths to the integration's runtime environment.

Why the other options are wrong

  • A. Uploading as regular parameters is insecure as the files would be stored unencrypted and potentially exposed in logs or UI.
  • C. Placing files directly on the server's filesystem is not scalable for multi-engine deployments and bypasses XSOAR's secure credential management capabilities.
  • D. Embedding sensitive files directly in code, even base64 encoded, is a security anti-pattern and makes certificate rotation difficult.

Client Certificate (mTLS) Configuration

In Cortex XSOAR, client certificates and private keys for mTLS (mutual TLS) authentication should be uploaded and managed as secure file-type integration parameters to ensure their encryption, secure storage, and controlled access by the integration.

  • Uses secure file-type integration parameters.
  • XSOAR encrypts and stores the files.
  • Integration receives secure paths to the files at runtime.

Memory trick: Files as Parameters, Securely Handled.

More Integrations questions