Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security analyst is troubleshooting a custom integration that is failing to connect to a partner's API. The partner uses a self-signed SSL certificate, and the integration logs show `SSL_CERTIFICATE_VERIFY_FAILED` errors. The analyst confirms that the self-signed certificate is valid but not trusted by default. Which integration instance setting should be enabled to allow the integration to connect to the partner's API without compromising the security of other connections?

  1. AEnable `Trust any certificate` in the integration instance settings.
  2. BInstall the self-signed certificate into the XSOAR server's system trust store.
  3. CConfigure a proxy server to handle the SSL/TLS termination.
  4. DDisable SSL/TLS verification globally on the XSOAR engine.
Show answer & explanation

Correct answer: A. Enable `Trust any certificate` in the integration instance settings.

Enabling `Trust any certificate` (often labeled 'Insecure' or similar) for the specific integration instance allows it to connect to endpoints with untrusted or self-signed certificates without affecting other integrations' SSL/TLS verification, which remain secure by default.

Why the other options are wrong

  • B. Installing the certificate into the XSOAR server's trust store would make it trusted system-wide, which might be acceptable but is less granular than an instance-specific setting and requires access to the underlying OS.
  • C. While a proxy could terminate SSL, it's an overly complex solution for simply trusting a self-signed certificate for one integration and might introduce other issues.
  • D. Disabling SSL/TLS verification globally would compromise the security of *all* connections from the XSOAR engine, which is a major security risk and not recommended.

Self-Signed Certificate Trust

To allow a specific integration instance to connect to an API using a self-signed SSL certificate, the `Trust any certificate` setting should be enabled for that instance.

  • Bypasses SSL/TLS validation for the instance.
  • Does not affect other integrations.
  • Used for untrusted or self-signed certificates.

Memory trick: To trust a 'self-signed' certificate, you need to 'tell' XSOAR.

More Integrations questions