A security engineer is troubleshooting a custom integration that is failing to connect to an external REST API. The error message in the integration logs is `SSL: CERTIFICATE_VERIFY_FAILED`. The external API uses a self-signed SSL certificate that is not trusted by default by standard certificate authorities. What is the most secure and recommended way to resolve this issue in Cortex XSOAR?
- AInstall the self-signed certificate directly onto the operating system of the XSOAR server.
- BModify the integration code to bypass the certificate validation for only the problematic endpoint.
- CUpload the self-signed certificate as a file-type integration parameter and configure the `BaseClient` to trust it.
- DDisable SSL verification entirely in the integration's HTTP requests by setting `verify=False`.
Show answer & explanationAnswer & explanation
Correct answer: C. Upload the self-signed certificate as a file-type integration parameter and configure the `BaseClient` to trust it.
The most secure and recommended approach for trusting self-signed certificates in Cortex XSOAR is to upload the certificate as a file-type integration parameter. XSOAR then manages its secure storage and provides a path that the `BaseClient` can use to explicitly trust this specific certificate during SSL verification, without compromising overall security.
Why the other options are wrong
- A. Installing certificates directly on the XSOAR server's OS is not scalable for distributed environments, bypasses XSOAR's secure parameter management, and makes certificate management more complex.
- B. Bypassing validation for a specific endpoint via code is still insecure, as it hardcodes a security bypass and does not leverage XSOAR's secure certificate management features.
- D. Disabling SSL verification (`verify=False`) is highly insecure as it makes the connection vulnerable to Man-in-the-Middle attacks and should never be used in a production environment.
Trusting Self-Signed Certificates
To securely enable trust for a self-signed SSL certificate in a Cortex XSOAR custom integration, the certificate should be uploaded as a file-type integration parameter. This allows the integration's `BaseClient` to specifically use and trust that certificate during TLS handshake.
- Avoids insecurely disabling SSL verification.
- Leverages XSOAR's secure file management for certificates.
- Provides granular trust for specific self-signed certificates.
Memory trick: Trust the File, Don't Blindly Verify.