Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard

A security analyst is troubleshooting a custom integration that is failing to connect to an internal REST API. The error message in the Cortex XSOAR logs indicates `SSL: CERTIFICATE_VERIFY_FAILED`. The internal API uses a self-signed certificate. What is the MOST appropriate action to resolve this issue securely?

  1. ADisable SSL certificate verification in the integration's configuration.
  2. BRestart the Cortex XSOAR engine service.
  3. CImport the self-signed certificate into the XSOAR engine's trust store.
  4. DReconfigure the internal REST API to use a publicly trusted certificate.
Show answer & explanation

Correct answer: C. Import the self-signed certificate into the XSOAR engine's trust store.

When `SSL: CERTIFICATE_VERIFY_FAILED` occurs with a self-signed certificate, the secure and proper resolution is to make the self-signed certificate trusted by the XSOAR engine. This is achieved by importing the certificate into the engine's trust store, allowing the engine to validate the server's identity without compromising security by disabling verification.

Why the other options are wrong

  • A. Disabling SSL verification is a security risk and should only be done in controlled, temporary debugging scenarios, not as a permanent solution.
  • B. Restarting the engine will not resolve a certificate trust issue; it only reloads the current configuration.
  • D. While a good long-term solution, this requires changes to the external API and might not be immediately feasible or under the analyst's control.

Self-Signed Certificate Trust

To securely resolve `SSL: CERTIFICATE_VERIFY_FAILED` errors when connecting to services using self-signed certificates in Cortex XSOAR, import the self-signed certificate into the XSOAR engine's trusted certificate store.

  • Maintains secure communication (SSL/TLS).
  • Establishes trust for non-public CAs.
  • Avoids disabling certificate verification.

Memory trick: When the 'lock' says 'no trust', you need to 'trust the key' (certificate).

More Integrations questions