Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security engineer is developing a custom integration for Cortex XSOAR that interacts with an external service. This service requires a client certificate for mutual TLS (mTLS) authentication. The engineer has obtained the client certificate and its corresponding private key. How should these be securely configured within the integration instance in Cortex XSOAR?

  1. AConvert the certificate and private key into a single PKCS#12 (.p12) file and upload it to the XSOAR server.
  2. BUpload the certificate and private key as separate files to the XSOAR server's file system.
  3. CEmbed the certificate and private key directly into the integration Python code.
  4. DDefine two encrypted integration instance parameters: one for the client certificate (PEM format) and one for the private key (PEM format).
Show answer & explanation

Correct answer: D. Define two encrypted integration instance parameters: one for the client certificate (PEM format) and one for the private key (PEM format).

Cortex XSOAR integration instances support encrypted parameters for sensitive data. Client certificates and private keys, typically in PEM format, can be stored as separate encrypted parameters, allowing the integration code to access them at runtime for mTLS without exposing them in plain text.

Why the other options are wrong

  • A. While PKCS#12 is a valid format, XSOAR's `BaseClient` typically expects separate PEM-encoded certificate and key strings for mTLS configuration, making encrypted parameters for each the more direct and manageable approach within the integration context.
  • B. Uploading files directly to the server's file system is generally not the XSOAR-recommended secure method for integration-specific credentials, as it lacks proper management and encryption within the platform.
  • C. Hardcoding sensitive credentials, including certificates and private keys, is a severe security risk and is not recommended.

mTLS Client Certificate Configuration

Configuring a Cortex XSOAR integration to use a client certificate and private key for mutual TLS authentication with an external service, ensuring secure, encrypted communication and client identity verification.

  • Requires both a client certificate and its corresponding private key.
  • Credentials must be stored securely, typically as encrypted integration parameters.
  • The `BaseClient` in Python integrations is used to provide these credentials for HTTP requests.

Memory trick: Client certs and keys need encrypted parameters for trusted two-way talks.

More Integrations questions