<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allow based on certifcate issuer? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allow-based-on-certifcate-issuer/m-p/547435#M4657</link>
    <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider bos bot c d e f g h i j k l m n o p q r s t bou bov w x y z ab ac ae af ag ah ai aj ak"&gt;We are currently having an issue with our database disk images being blocked that are set on rotation cycles. The file name and the hash changes incrementally. All our disk images are signed, using a certificate by the issuer; this was used previously to stop these executables from being blocked.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider bos bot c d e f g h i j k l m n o p q r s t bou bov w x y z ab ac ae af ag ah ai aj ak"&gt;Is there a way to exclude or allow based on the certificate issuer?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Jun 2023 15:24:23 GMT</pubDate>
    <dc:creator>mssp_ctunks</dc:creator>
    <dc:date>2023-06-27T15:24:23Z</dc:date>
    <item>
      <title>Allow based on certifcate issuer?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allow-based-on-certifcate-issuer/m-p/547435#M4657</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider bos bot c d e f g h i j k l m n o p q r s t bou bov w x y z ab ac ae af ag ah ai aj ak"&gt;We are currently having an issue with our database disk images being blocked that are set on rotation cycles. The file name and the hash changes incrementally. All our disk images are signed, using a certificate by the issuer; this was used previously to stop these executables from being blocked.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider bos bot c d e f g h i j k l m n o p q r s t bou bov w x y z ab ac ae af ag ah ai aj ak"&gt;Is there a way to exclude or allow based on the certificate issuer?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 15:24:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allow-based-on-certifcate-issuer/m-p/547435#M4657</guid>
      <dc:creator>mssp_ctunks</dc:creator>
      <dc:date>2023-06-27T15:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Allow based on certifcate issuer?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allow-based-on-certifcate-issuer/m-p/547451#M4659</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/215992"&gt;@mssp_ctunks&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LIVEcommunity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can definitely see how this issue would cause some headaches.&amp;nbsp; I would recommend adding the exception as a folder instead of a file since the names and hashes change.&amp;nbsp; If you can exclude the folder it should exclude any processes running within that folder.&amp;nbsp; I'd like to caution you to be mindful that anything nested in the folder will be excluded as well.&amp;nbsp; I'll leave some information about this right &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-Legacy-Exception-Rule" target="_self"&gt;here&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With the introduction of Cortex XDR 3.5 all of the exception have now been moved to the Global Exceptions Configuraiton which is accessible as seen below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-06-27 at 11.24.14 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51226i8D5F8A8B8E6BB552/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-06-27 at 11.24.14 AM.png" alt="Screenshot 2023-06-27 at 11.24.14 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would just caution that you test this method to verify it's validity before deploying to a production environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Lastly, If that doesn't work out properly.&amp;nbsp; I highly suggest reaching out to &lt;A href="https://support.paloaltonetworks.com/Support/Index" target="_self"&gt;support&lt;/A&gt;&amp;nbsp;&amp;nbsp;as they should be able to provide you with support exception to deal with your issue specifically.&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;I hope you find this information helpful.&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Have a great day!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 16:27:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allow-based-on-certifcate-issuer/m-p/547451#M4659</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-06-27T16:27:11Z</dc:date>
    </item>
  </channel>
</rss>

