Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security engineer is developing a custom integration for Cortex XSOAR that needs to interact with an internal web service. This web service is protected by a self-signed SSL certificate. When the integration attempts to connect, it consistently fails with an `SSL_CERTIFICATE_VERIFY_FAILED` error. How should the engineer configure the integration to successfully connect to this web service without compromising security on other connections?

  1. ADisable SSL verification globally in the XSOAR server settings.
  2. BAdd the self-signed certificate to the XSOAR server's trusted CA store.
  3. CUse HTTP instead of HTTPS for the connection.
  4. DSet the `verify` parameter to `False` in the `_http_request` method call within the integration.
Show answer & explanation

Correct answer: B. Add the self-signed certificate to the XSOAR server's trusted CA store.

Adding the self-signed certificate to the XSOAR server's trusted CA store (or to the trusted CA bundle used by the integration's Python environment) is the most secure and recommended way to resolve `SSL_CERTIFICATE_VERIFY_FAILED` errors for specific trusted endpoints. This allows the integration to trust that particular certificate while maintaining strict SSL verification for all other connections.

Why the other options are wrong

  • A. Disabling SSL verification globally is a major security risk as it bypasses certificate checks for *all* connections.
  • C. Using HTTP removes encryption and authentication, severely compromising security and is not a solution for an SSL verification failure.
  • D. Setting `verify=False` in `_http_request` disables verification for *that specific integration's calls*, which is better than global but still bypasses verification rather than establishing trust. It's often a temporary workaround.

Trusting Self-Signed Certificates

To securely resolve `SSL_CERTIFICATE_VERIFY_FAILED` errors for a self-signed certificate, the certificate should be added to the operating system's or application's trusted Certificate Authority (CA) store, or specified directly in the integration's `_http_request` call.

  • SSL verification ensures endpoint authenticity.
  • Self-signed certs are not trusted by default.
  • Add to trusted CA store for secure, targeted trust.

Memory trick: Trust the cert, don't just ignore it.

More Integrations questions