Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard
A security engineer is developing a custom integration that needs to connect to an external service using a self-signed SSL certificate for its endpoint. During initial testing, the integration consistently fails with an SSL certificate validation error. The engineer has already confirmed the certificate is valid on the endpoint. What is the most appropriate action to resolve this issue within the Cortex XSOAR integration code or configuration?
- AImport the self-signed certificate into the XSOAR engine's trusted certificate store.
- BSet `verify_ssl` to `False` in the `BaseClient` configuration.
- CChange the API endpoint from HTTPS to HTTP to bypass SSL/TLS.
- DGenerate a new, publicly signed SSL certificate for the external service.
Show answer & explanationAnswer & explanation
Correct answer: A. Import the self-signed certificate into the XSOAR engine's trusted certificate store.
For self-signed certificates, the XSOAR engine (or the `requests` library it uses) will not trust them by default. The correct and secure way to resolve this is to import the self-signed certificate into the trusted certificate store of the XSOAR engine. This allows the engine to validate the certificate without compromising security by disabling SSL verification.
Why the other options are wrong
- B. Setting `verify_ssl` to `False` disables SSL certificate validation entirely, which is a security risk and generally not recommended in production.
- C. Changing to HTTP removes encryption and authentication, which is a severe security degradation and likely unacceptable for an external service.
- D. While generating a publicly signed certificate is ideal, it's often not feasible or under the control of the integration developer for an existing external service.
Self-Signed Certificate Trust
Ensuring an XSOAR integration trusts a server's self-signed SSL certificate by adding it to the engine's trusted certificate store.
- Self-signed certificates are not trusted by default.
- Importing to the trust store enables validation.
- Disabling `verify_ssl` is a security risk.
- Maintains secure communication (HTTPS).
Memory trick: Trust the self-signed by adding it to the book, don't just ignore the look.