A security engineer is developing a custom integration for Cortex XSOAR that needs to interact with an internal web service. This web service is protected by a self-signed SSL certificate. When the integration attempts to connect, it consistently fails with an `SSL_CERTIFICATE_VERIFY_FAILED` error. How should the engineer configure the integration to successfully connect to this web service without compromising security on other connections?
- ADisable SSL verification globally in the XSOAR server settings.
- BAdd the self-signed certificate to the XSOAR server's trusted CA store.
- CUse HTTP instead of HTTPS for the connection.
- DSet the `verify` parameter to `False` in the `_http_request` method call within the integration.
Show answer & explanationAnswer & explanation
Correct answer: B. Add the self-signed certificate to the XSOAR server's trusted CA store.
Adding the self-signed certificate to the XSOAR server's trusted CA store (or to the trusted CA bundle used by the integration's Python environment) is the most secure and recommended way to resolve `SSL_CERTIFICATE_VERIFY_FAILED` errors for specific trusted endpoints. This allows the integration to trust that particular certificate while maintaining strict SSL verification for all other connections.
Why the other options are wrong
- A. Disabling SSL verification globally is a major security risk as it bypasses certificate checks for *all* connections.
- C. Using HTTP removes encryption and authentication, severely compromising security and is not a solution for an SSL verification failure.
- D. Setting `verify=False` in `_http_request` disables verification for *that specific integration's calls*, which is better than global but still bypasses verification rather than establishing trust. It's often a temporary workaround.
Trusting Self-Signed Certificates
To securely resolve `SSL_CERTIFICATE_VERIFY_FAILED` errors for a self-signed certificate, the certificate should be added to the operating system's or application's trusted Certificate Authority (CA) store, or specified directly in the integration's `_http_request` call.
- SSL verification ensures endpoint authenticity.
- Self-signed certs are not trusted by default.
- Add to trusted CA store for secure, targeted trust.
Memory trick: Trust the cert, don't just ignore it.