<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificate Enforcement issue in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588305#M6760</link>
    <description>&lt;P&gt;We have several machines that are now reporting "Partially Protected" when we enabled Certificate Enforcement on them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First they started to show "Local-Store fallback used" in audit logs (informational severity), now we see "Failed to enable certificate enforcement due to local-store fallback" high severity messages and a Partially Protected Operational status for the hosts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am seeing policy and content updates coming through just fine, and the hosts stay connected to the portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) What exactly does Partially Protected status mean for hosts with this particular problem?&lt;/P&gt;
&lt;P&gt;2) How is this issue fixed?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 May 2024 21:39:30 GMT</pubDate>
    <dc:creator>rufat87</dc:creator>
    <dc:date>2024-05-29T21:39:30Z</dc:date>
    <item>
      <title>Certificate Enforcement issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588305#M6760</link>
      <description>&lt;P&gt;We have several machines that are now reporting "Partially Protected" when we enabled Certificate Enforcement on them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First they started to show "Local-Store fallback used" in audit logs (informational severity), now we see "Failed to enable certificate enforcement due to local-store fallback" high severity messages and a Partially Protected Operational status for the hosts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am seeing policy and content updates coming through just fine, and the hosts stay connected to the portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) What exactly does Partially Protected status mean for hosts with this particular problem?&lt;/P&gt;
&lt;P&gt;2) How is this issue fixed?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 21:39:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588305#M6760</guid>
      <dc:creator>rufat87</dc:creator>
      <dc:date>2024-05-29T21:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Enforcement issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588333#M6761</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209466"&gt;@rufat87&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out on Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Enabling the feature, makes the agent not to use the Local Root CA certificate Store anymore and use only the pinned roots.pem certificate file, this way protecting from Man In The Middle (MITM) attacks.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please check in Endpoints Tab, there is a Last Certificate Enforcement Fallback field. If you find the values appearing there that means the Agent is not using the root.pem certificate and falling back to local store.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Once you enable the feature, the agent starts with learning mode phase. Failure to pass the learning mode results into agent stay in Partially Protected until the feature is disabled.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please ensure that you are not decrypting the agent traffic or SSL inspection is not enabled in your proxy or VPN. You can open a TAC case for further support.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 05:37:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588333#M6761</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-05-30T05:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Enforcement issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588405#M6775</link>
      <description>&lt;P&gt;You have not really answered on what protection for the host is now partial? What protection modules are disabled for such hosts?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is disabling Certificate Enforcement for such hosts a feasible solution - temporarily or permanently?&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 14:02:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588405#M6775</guid>
      <dc:creator>rufat87</dc:creator>
      <dc:date>2024-05-30T14:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Enforcement issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588406#M6776</link>
      <description>&lt;P&gt;It seems you didn't notice the below statement:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Once you enable the feature, the agent starts with learning mode phase. Failure to pass the learning mode results into agent stay in Partially Protected until the feature is disabled.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As you have mentioned the error is&amp;nbsp;"Failed to enable certificate enforcement due to local-store fallback". That means Certificate enforcement is not enabled and instead of root.pem , the agent is using Local store certificate which is not recommended. Hence, partially protected.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The solution is not disabling the policy, it is finding out why it is falling back. The reason may be that, you are decrypting the agent traffic or SSL inspection is enabled in your proxy or VPN.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hence, please open a TAC support case to troubleshoot further.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 14:13:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588406#M6776</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-05-30T14:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Enforcement issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588417#M6777</link>
      <description>&lt;P&gt;No, I have read your comment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So it is falling back to use local cert which is "not recommended" and therefore is becoming vulnerable to possible "&lt;SPAN&gt;Man In The Middle (MITM) attacks". That's the only reason XDR is tagging these as Partially Protected, everything else works just fine in regards to prevention modules and operationally.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We will investigate this further with TAC, thanks for response.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 18:01:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588417#M6777</guid>
      <dc:creator>rufat87</dc:creator>
      <dc:date>2024-05-30T18:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Enforcement issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588449#M6778</link>
      <description>&lt;P&gt;That's right. Hope this get resolve asap.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 04:13:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/certificate-enforcement-issue/m-p/588449#M6778</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-05-31T04:13:15Z</dc:date>
    </item>
  </channel>
</rss>

