<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR Certificate enforcement for Windows and macOS endpoints in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-certificate-enforcement-for-windows-and-macos/m-p/597495#M7174</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I have a query regarding the Cortex XDR Agent (8.3) Certificate Enforcement settings.&lt;/P&gt;
&lt;P&gt;1. Enable the Certificate Enforcement option.&lt;BR /&gt;2. Decrypt either only Cortex XDR Agent traffic in the firewall or decrypt all traffic related to application servers in the firewall.&lt;/P&gt;
&lt;P&gt;Please confirm if these steps are correct, as I have not found comprehensive documentation on this configuration.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Sep 2024 04:54:39 GMT</pubDate>
    <dc:creator>Vinothkumar_SBA</dc:creator>
    <dc:date>2024-09-11T04:54:39Z</dc:date>
    <item>
      <title>Cortex XDR Certificate enforcement for Windows and macOS endpoints</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-certificate-enforcement-for-windows-and-macos/m-p/597495#M7174</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I have a query regarding the Cortex XDR Agent (8.3) Certificate Enforcement settings.&lt;/P&gt;
&lt;P&gt;1. Enable the Certificate Enforcement option.&lt;BR /&gt;2. Decrypt either only Cortex XDR Agent traffic in the firewall or decrypt all traffic related to application servers in the firewall.&lt;/P&gt;
&lt;P&gt;Please confirm if these steps are correct, as I have not found comprehensive documentation on this configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 04:54:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-certificate-enforcement-for-windows-and-macos/m-p/597495#M7174</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2024-09-11T04:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Certificate enforcement for Windows and macOS endpoints</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-certificate-enforcement-for-windows-and-macos/m-p/597546#M7175</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/243138"&gt;@Vinothkumar_SBA&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Agent Certificate Enforcement is a feature &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/8.3/Cortex-XDR-Agent-Release-Notes/Changes-to-Default-Behavior-in-Cortex-XDR-Agent-8.3" target="_self"&gt;introduced in 8.3&lt;/A&gt; to improve the agent&amp;nbsp;&lt;SPAN&gt;security, by enforcing the use of root CA that is provided by&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="phrase"&gt;Palo Alto Networks&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;rather than on the local machine. You have more information in the&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Set-up-agent-settings-profiles" target="_self"&gt; Agents Settings Profile document.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have SSL Decryption in your firewall, the FQDNS are still needed to be added as an exception for the XDR Agents. &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Resources-Required-to-Enable-Access" target="_self"&gt;Here&lt;/A&gt; you can find the resources to except.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1726061265467.png" style="width: 921px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62172i88DC0BCA88E4E964/image-dimensions/921x145?v=v2" width="921" height="145" role="button" title="jmazzeo_0-1726061265467.png" alt="jmazzeo_0-1726061265467.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 13:31:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-certificate-enforcement-for-windows-and-macos/m-p/597546#M7175</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-09-11T13:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Certificate enforcement for Windows and macOS endpoints</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-certificate-enforcement-for-windows-and-macos/m-p/597639#M7176</link>
      <description>&lt;P&gt;Hi Jmazzeo,&lt;/P&gt;
&lt;P&gt;Thank you for your response. You mentioned that only the Cortex XDR agent URLs should be added to the FQDN exception list, and not all URLs or other application server URLs. Is my understanding correct or incorrect?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 06:10:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-certificate-enforcement-for-windows-and-macos/m-p/597639#M7176</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2024-09-12T06:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Certificate enforcement for Windows and macOS endpoints</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-certificate-enforcement-for-windows-and-macos/m-p/597669#M7178</link>
      <description>&lt;P&gt;Hi, I linked this document that shows all the required URLs:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Resources-Required-to-Enable-Access" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Resources-Required-to-Enable-Access&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not only the tenant URL, there are a few more that the agent needs to communicate. If you have PANW NGFW you can see the&amp;nbsp;App-ID Coverage in that doc.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 13:13:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-certificate-enforcement-for-windows-and-macos/m-p/597669#M7178</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-09-12T13:13:38Z</dc:date>
    </item>
  </channel>
</rss>

