<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policies without certificate enforcement enabled warning message in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578782#M6202</link>
    <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Until now, typically certificates are validated by checking the signature hierarchy; &lt;/SPAN&gt;&lt;STRONG&gt;MyCert&lt;/STRONG&gt;&lt;SPAN&gt; is signed by &lt;/SPAN&gt;&lt;STRONG&gt;IntermediateCert&lt;/STRONG&gt;&lt;SPAN&gt; which is signed by &lt;/SPAN&gt;&lt;STRONG&gt;RootCert&lt;/STRONG&gt;&lt;SPAN&gt;, and &lt;/SPAN&gt;&lt;STRONG&gt;RootCert&lt;/STRONG&gt;&lt;SPAN&gt; is listed in my computer's "certificates to trust" store.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Enabling the feature, makes the agent not to use the Local Root CA certificate Store anymore and use only the pinned roots.pem certificate file, this way protecting from Man In The Middle (MITM) attacks. For this the requirement for the agent is 8.3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Below is the path for the supported OS, where you can find the certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Windows – "C:\Program Files\Palo Alto Networks\Traps\config\roots.pem”&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;macOS – “/Library/Application Support/PaloAltoNetworks/Traps/config”&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;For example, MITM attack can be implemented, where an attacker can configure a malicious secure proxy communication that will be used by the machine, diverting and intercepting all the agent’s communication securely. The secure communication can can be achieved by using a legitimate Root certificate installed by the attacker in the machine’s Root certificate store&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Not using the Local Store and only using the trusted roots.pem file, can avoid this kind of attack.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Talking about the impact, please find the below information:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The agent checks for the root certificate in the roots.pem.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;If the Root signer is not found in roots.pem, the agent will check in the machine’s local store as fallback&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the agent can verify the certificate using one of the methods above, the communications succeeds.&lt;BR /&gt;&lt;BR /&gt;Kindly find more information on enforcement levels:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aspatil_0-1709187024650.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57938i66792FE94EEF0AC9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="aspatil_0-1709187024650.png" alt="aspatil_0-1709187024650.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Disabled (notify) default:&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Agents use using the computer’s Trusted Root Certification Authority Store (aka Local Store)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;All risky notification banners will show&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Disabled:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Agents use using the computer’s Trusted Root Certification Authority Store (aka Local Store)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;All risky notification banners will show&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Enabled:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Agents starts with learning mode phase&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Verify these 2 conditions&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt; For at least 20 minutes, agents did not fallback to the local store&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt; At least 2 successful heartbeats in the last 20 minutes&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;If succeeded, changes from &lt;/SPAN&gt;&lt;STRONG&gt;learning mode&lt;/STRONG&gt;&lt;SPAN&gt; to Checks 2 conditions first&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;In learning mode, agent’s operational status may show &lt;/SPAN&gt;&lt;STRONG&gt;“Partially Protected”&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Failure to pass the learning mode, agents stay in Partially protected until the feature is Disabled/disabled (notify)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Feb 2024 06:13:18 GMT</pubDate>
    <dc:creator>aspatil</dc:creator>
    <dc:date>2024-02-29T06:13:18Z</dc:date>
    <item>
      <title>Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578590#M6180</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently I got a warning message in cortex saying that "&lt;SPAN&gt;&lt;SPAN class="ui-provider ed bci bcj bck bcl bcm bcn bco bcp bcq bcr bcs bct bcu bcv bcw bcx bcy bcz bda bdb bdc bdd bde bdf bdg bdh bdi bdj bdk bdl bdm bdn bdo bdp"&gt;&lt;I&gt;&lt;STRONG&gt;Some of your endpoints have policies without Certificate Enforcement enabled&lt;/STRONG&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;". And by checking it further I could see that, this is to increase protection on the agent's communication by enforcing the use of root CA provided by Cortex (rather than on the local machine).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It was in disabled state since I started using it and why it gives warning message now?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can I get more clarity on this and what will be the impact if I enable this feature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using Cortex XDR Version 3.9&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 05:47:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578590#M6180</guid>
      <dc:creator>Aneesh</dc:creator>
      <dc:date>2024-02-28T05:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578592#M6181</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/322192"&gt;@Aneesh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for reaching out on LiveCommunity!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The banner showing&amp;nbsp;&lt;CODE class="c-mrkdwn__code" data-stringify-type="code"&gt;Some of your endpoints have policies without Certificate Enforcement enabled&lt;/CODE&gt;&amp;nbsp;is by design. Notify(Disabled) will be the default setting. The main motivation is to push customers to enable (or disable) the feature and move from Notify to one of the other modes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 06:28:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578592#M6181</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-02-28T06:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578606#M6183</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the speedy response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand this but my query was,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It was in disabled state since I started using it and why it gives warning message now?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can I get more clarity on this and what will be the impact if I enable this feature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 08:58:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578606#M6183</guid>
      <dc:creator>Aneesh</dc:creator>
      <dc:date>2024-02-28T08:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578612#M6184</link>
      <description>&lt;P&gt;It gives also a Risk warning for Default Policy, which I cannot edit (or I don't know how).&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 09:46:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578612#M6184</guid>
      <dc:creator>Rindsland</dc:creator>
      <dc:date>2024-02-28T09:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578731#M6200</link>
      <description>&lt;P&gt;I am also curious what is the user impact, or the impact of enabling this feature?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 02:07:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578731#M6200</guid>
      <dc:creator>Blake_Volk</dc:creator>
      <dc:date>2024-02-29T02:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578782#M6202</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Until now, typically certificates are validated by checking the signature hierarchy; &lt;/SPAN&gt;&lt;STRONG&gt;MyCert&lt;/STRONG&gt;&lt;SPAN&gt; is signed by &lt;/SPAN&gt;&lt;STRONG&gt;IntermediateCert&lt;/STRONG&gt;&lt;SPAN&gt; which is signed by &lt;/SPAN&gt;&lt;STRONG&gt;RootCert&lt;/STRONG&gt;&lt;SPAN&gt;, and &lt;/SPAN&gt;&lt;STRONG&gt;RootCert&lt;/STRONG&gt;&lt;SPAN&gt; is listed in my computer's "certificates to trust" store.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Enabling the feature, makes the agent not to use the Local Root CA certificate Store anymore and use only the pinned roots.pem certificate file, this way protecting from Man In The Middle (MITM) attacks. For this the requirement for the agent is 8.3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Below is the path for the supported OS, where you can find the certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Windows – "C:\Program Files\Palo Alto Networks\Traps\config\roots.pem”&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;macOS – “/Library/Application Support/PaloAltoNetworks/Traps/config”&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;For example, MITM attack can be implemented, where an attacker can configure a malicious secure proxy communication that will be used by the machine, diverting and intercepting all the agent’s communication securely. The secure communication can can be achieved by using a legitimate Root certificate installed by the attacker in the machine’s Root certificate store&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Not using the Local Store and only using the trusted roots.pem file, can avoid this kind of attack.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Talking about the impact, please find the below information:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The agent checks for the root certificate in the roots.pem.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;If the Root signer is not found in roots.pem, the agent will check in the machine’s local store as fallback&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the agent can verify the certificate using one of the methods above, the communications succeeds.&lt;BR /&gt;&lt;BR /&gt;Kindly find more information on enforcement levels:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aspatil_0-1709187024650.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57938i66792FE94EEF0AC9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="aspatil_0-1709187024650.png" alt="aspatil_0-1709187024650.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Disabled (notify) default:&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Agents use using the computer’s Trusted Root Certification Authority Store (aka Local Store)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;All risky notification banners will show&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Disabled:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Agents use using the computer’s Trusted Root Certification Authority Store (aka Local Store)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;All risky notification banners will show&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Enabled:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Agents starts with learning mode phase&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Verify these 2 conditions&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt; For at least 20 minutes, agents did not fallback to the local store&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt; At least 2 successful heartbeats in the last 20 minutes&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;If succeeded, changes from &lt;/SPAN&gt;&lt;STRONG&gt;learning mode&lt;/STRONG&gt;&lt;SPAN&gt; to Checks 2 conditions first&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;In learning mode, agent’s operational status may show &lt;/SPAN&gt;&lt;STRONG&gt;“Partially Protected”&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Failure to pass the learning mode, agents stay in Partially protected until the feature is Disabled/disabled (notify)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 06:13:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578782#M6202</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-02-29T06:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578783#M6203</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/201986"&gt;@Rindsland&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;You can edit the default policy and update the Agent profile with the certificate enforcement enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 06:14:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578783#M6203</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-02-29T06:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578835#M6213</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for this explanation. Does the certificate enforcement only affect the XDR agent communication or the whole communication of the OS?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 13:30:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578835#M6213</guid>
      <dc:creator>micomi</dc:creator>
      <dc:date>2024-02-29T13:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578882#M6221</link>
      <description>&lt;P&gt;How do you edit the Default Agent Settings profile though?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JGrover1_0-1709232165786.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57956i5157F083946E1D98/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JGrover1_0-1709232165786.png" alt="JGrover1_0-1709232165786.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 18:43:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578882#M6221</guid>
      <dc:creator>JGrover1</dc:creator>
      <dc:date>2024-02-29T18:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578978#M6224</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41187"&gt;@micomi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;It only affects Agent communication.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 08:02:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578978#M6224</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-03-01T08:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578979#M6225</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/217720"&gt;@JGrover1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It talks about the policy, you can duplicate the default agent settings profile, enable the Certificate enforcement and append to all the policies which uses default Agent setting profiles.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 08:03:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/578979#M6225</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-03-01T08:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579017#M6228</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/217720"&gt;@JGrover1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the same problem that you can't adjust or delete the default profiles and the warning still appears.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 12:57:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579017#M6228</guid>
      <dc:creator>Geismann</dc:creator>
      <dc:date>2024-03-01T12:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579172#M6239</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;,&amp;nbsp;I hope you are doing well.&lt;/P&gt;
&lt;P&gt;Do you know if is there a KB or a kind of documentation with such a level of detail that you said?&lt;/P&gt;
&lt;P&gt;Unfortunately, the release notes of version 8.3 doesn't bring this level of detailing.&lt;/P&gt;
&lt;P&gt;Thanks a lot for your explanation!&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 18:44:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579172#M6239</guid>
      <dc:creator>Silva</dc:creator>
      <dc:date>2024-03-04T18:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579253#M6242</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1473380123"&gt;@Silva&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can find it in Changed Features section:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Release-Notes/February-2024" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Release-Notes/February-2024&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 05:10:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579253#M6242</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-03-05T05:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579254#M6243</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/151694"&gt;@Geismann&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would suggest you to reach out to SE or open a TAC case for more information&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 05:11:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579254#M6243</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-03-05T05:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579324#M6257</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;&amp;nbsp;thanks for your answer.&lt;/P&gt;
&lt;P&gt;You described the changes about local and Palo Alto certificates with too much clarity upper in this post.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I couldn't find these details in the Changes Features section of the Release Information, like:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;For at least 20 minutes, agents did not fallback to the local store&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;At least 2 successful heartbeats in the last 20 minutes&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;The release note doesn't mention it, also doesn't mention several other things you said in the post here:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="brucsilva_0-1709658030939.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58059iD85F278B213A3D33/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="brucsilva_0-1709658030939.png" alt="brucsilva_0-1709658030939.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So where did find it?&lt;BR /&gt;PS: I'm new with Palo Alto and Cortex, so I'm having a little difficulty finding good and reliable information&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 17:05:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579324#M6257</guid>
      <dc:creator>Silva</dc:creator>
      <dc:date>2024-03-05T17:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579409#M6262</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the explanation.&lt;/P&gt;
&lt;P&gt;Could you please clarify the steps involved in 'enabled' state for better understanding.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;Aneesh.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 06:54:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579409#M6262</guid>
      <dc:creator>Aneesh</dc:creator>
      <dc:date>2024-03-06T06:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579411#M6263</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/322192"&gt;@Aneesh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you confirm which steps are you asking about. The complete information has been shared with what Enable means?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are looking for how to enable it, Please follow below instructions:&lt;/P&gt;
&lt;P&gt;1. Endpoints-&amp;gt; Policy Management-&amp;gt; Prevention Profile&lt;/P&gt;
&lt;P&gt;2. Edit all the Agent setting profiles and under Agent Certificate section enable it&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 07:01:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579411#M6263</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-03-06T07:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579425#M6265</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I was referring to the steps in enabled state which you have mentioned in your reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please find the below snip for your reference.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Aneesh_0-1709715236730.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58097iC7D7E435CD644C51/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Aneesh_0-1709715236730.png" alt="Aneesh_0-1709715236730.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;Aneesh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 08:58:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/579425#M6265</guid>
      <dc:creator>Aneesh</dc:creator>
      <dc:date>2024-03-06T08:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: Policies without certificate enforcement enabled warning message</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/580280#M6321</link>
      <description>&lt;P&gt;Like a few here, I have no issue with the change and editing my custom Prevention profiles, but how does one edit the Default profiles to make this change? They do not appear to be editable but are associated with the risk. How do we edit those default Prevention Profiles to change the agent certificate setting?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ScottCloster_0-1710362439934.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58284i1C7197565B743BF5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ScottCloster_0-1710362439934.png" alt="ScottCloster_0-1710362439934.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 20:40:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/policies-without-certificate-enforcement-enabled-warning-message/m-p/580280#M6321</guid>
      <dc:creator>ScottCloster</dc:creator>
      <dc:date>2024-03-13T20:40:56Z</dc:date>
    </item>
  </channel>
</rss>

