<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Pro on Linux Mint in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-on-linux-mint/m-p/394217#M647</link>
    <description>&lt;P&gt;So, PA Customer support shut this down by saying Linux Mint is an unsupported OS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internally what we found that _may_ explain the situation is that PA have a self-signed anchor issue on the SSL certificate chain.&amp;nbsp; You can see this on a Qualys SSL scan of&amp;nbsp;distributions.traps.paloaltonetworks.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't prove it at this point, but the thinking internally is that either Mint or the app or a combination in some way&amp;nbsp; follow the entire chain and fail validation because it sees the final certificate in the chain is self signed even though it is in the trusted root store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given that PA won't entertain any further investigation I've had to move on, their list of supported Linux OS is very small and contains no specific desktop variants or flavours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/cortex-xdr/where-can-i-install-the-cortex-xdr-agent.html" target="_blank"&gt;Where Can I Install the Cortex XDR Agent? (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point I don't consider that XDR fully supports Linux and certainly not Linux for desktop\client endpoints .&lt;/P&gt;</description>
    <pubDate>Fri, 26 Mar 2021 09:27:58 GMT</pubDate>
    <dc:creator>ianatgrafton</dc:creator>
    <dc:date>2021-03-26T09:27:58Z</dc:date>
    <item>
      <title>Cortex XDR Pro on Linux Mint</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-on-linux-mint/m-p/393308#M643</link>
      <description>&lt;P&gt;I am having an issue with an installation of XDR on Linux Mint 20.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found this post with no resolution&amp;nbsp; and one of the comments from &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/111312"&gt;@MartinSauer&lt;/a&gt;&amp;nbsp;&amp;nbsp;suggests someone else was seeing the same issue.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/error-14090086-ssl-routines-ssl3-get-server-certificate/td-p/317055" target="_blank" rel="noopener"&gt;LIVEcommunity - ERROR:14090086:SSL routines: SSL3_GET_SERVER_CERTIFICATE: certificate verify failed - LIVEcommunity - 317055 (paloaltonetworks.com)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the trapsd.log I can see the error:&lt;/P&gt;&lt;P&gt;&lt;!--  StartFragment   --&gt;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;{trapsd:Communication:Heartbeat:Scheduled:&lt;A href="https://distributions.traps.paloaltonetworks.com/operations/provision/register-url/&amp;lt;dist-id" target="_blank" rel="noopener"&gt;https://distributions.traps.paloaltonetworks.com/operations/provision/register-url/&amp;lt;dist-id&lt;/A&gt;&amp;gt;} HTTP request failed due to an SSL error (0): SSL Exception: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;If I curl that URI it connects fine and I can see the TLS handshake and TLS v1.2 is used, it returns a status 200 message and a resource URI, similarly, if I browse to the URI using Firefox ESR I get a valid response with a resource URI with no certificate errors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why cant the XDR Agent validate the cert and is this limited to an issue with Linux Mint 20?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Support are driving me mad&amp;nbsp; and keep telling me its a certificate issue asking me to install certificates which I have demonstrated&amp;nbsp;are installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anybody else come across this?&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;!--  EndFragment   --&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 14:41:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-on-linux-mint/m-p/393308#M643</guid>
      <dc:creator>ianatgrafton</dc:creator>
      <dc:date>2021-03-24T14:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Pro on Linux Mint</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-on-linux-mint/m-p/394217#M647</link>
      <description>&lt;P&gt;So, PA Customer support shut this down by saying Linux Mint is an unsupported OS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internally what we found that _may_ explain the situation is that PA have a self-signed anchor issue on the SSL certificate chain.&amp;nbsp; You can see this on a Qualys SSL scan of&amp;nbsp;distributions.traps.paloaltonetworks.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't prove it at this point, but the thinking internally is that either Mint or the app or a combination in some way&amp;nbsp; follow the entire chain and fail validation because it sees the final certificate in the chain is self signed even though it is in the trusted root store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given that PA won't entertain any further investigation I've had to move on, their list of supported Linux OS is very small and contains no specific desktop variants or flavours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/cortex-xdr/where-can-i-install-the-cortex-xdr-agent.html" target="_blank"&gt;Where Can I Install the Cortex XDR Agent? (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point I don't consider that XDR fully supports Linux and certainly not Linux for desktop\client endpoints .&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 09:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-on-linux-mint/m-p/394217#M647</guid>
      <dc:creator>ianatgrafton</dc:creator>
      <dc:date>2021-03-26T09:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Pro on Linux Mint</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-on-linux-mint/m-p/546791#M4623</link>
      <description>&lt;P&gt;Ubuntu is Cortex XDR supported:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Compatibility-Matrix/Linux" target="_blank" rel="noopener"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Compatibility-Matrix/Linux&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Linux Mint 21.1 "Vera" is basically a fork of Ubuntu 22.04 "jammy" with some changes:&lt;/P&gt;
&lt;P&gt;$cat /etc/upstream-release/lsb-release&lt;/P&gt;
&lt;P&gt;DISTRIB_ID=Ubuntu&lt;BR /&gt;DISTRIB_RELEASE=22.04&lt;BR /&gt;DISTRIB_CODENAME=jammy&lt;BR /&gt;DISTRIB_DESCRIPTION="Ubuntu Jammy Jellyfish"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Except Cortex XDR is looking at /etc/lsb-release and not the upstream and will generate this error and not be able to figure out what to do with CA certificates it wants to add:&lt;/P&gt;
&lt;P&gt;{trapsd:Communication:Startup:} Could not resolve CA certificates bundle path, unrecognized Linux distribution&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can work-around this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT color="#FF0000"&gt;sudo cp -av /etc/release-lsb /etc/release-lsb.orig ; sudo ln -s ./upstream-release/lsb-release /etc&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Now it will be happy with the Linux distribution detection and add the CA certificate properly.&lt;/P&gt;
&lt;P&gt;To remove this work-around, just restore the original file:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT color="#FF0000"&gt;sudo rm /etc/lsb-release ; sudo cp -av /etc/release-lsb.orig /etc/release-lsb&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;After this fix, a SSL error most likely points to SSL decryption somewhere along the way.&amp;nbsp; Either configure PAN FW to not decrypt Traps traffic, or add the CA for the decryption PAN FW to the OS certificate store:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;To add:&amp;nbsp;
&lt;OL&gt;
&lt;LI&gt;Copy your CA to&amp;nbsp;&lt;CODE&gt;ls /usr/local/share/ca-certificates/&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Use command:&amp;nbsp;&lt;CODE&gt;sudo cp foo.crt /usr/local/share/ca-certificates/foo.crt&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Update the CA store:&amp;nbsp;&lt;CODE&gt;sudo update-ca-certificates&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;To remove:
&lt;OL&gt;
&lt;LI&gt;Remove your CA: &lt;CODE&gt;rm /usr/local/share/ca-certificates/foo.crt&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Update the CA store:&amp;nbsp;&lt;CODE&gt;sudo update-ca-certificates --fresh&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 15:41:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-on-linux-mint/m-p/546791#M4623</guid>
      <dc:creator>jasonroy</dc:creator>
      <dc:date>2023-06-23T15:41:39Z</dc:date>
    </item>
  </channel>
</rss>

