<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Partialy protected in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/partialy-protected/m-p/1256562#M9386</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/796652325"&gt;@E.Istanto&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day and thanks for attaching the snapshot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="346" data-start="0"&gt;The &lt;STRONG data-end="29" data-start="4"&gt;"Partially Protected"&lt;/STRONG&gt; status on Ubuntu 24.04 with a &lt;STRONG data-end="95" data-start="60"&gt;"Linux kernel cannot be loaded"&lt;/STRONG&gt; error typically indicates that the Cortex XDR kernel module (KM) is either blocked from loading by the operating system or is incompatible with the installed kernel version. Ubuntu 24.04 x86_64 is supported starting with Cortex XDR Agent version 9.2.&lt;/P&gt;
&lt;P data-end="346" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="378" data-start="348" data-section-id="4wivyz"&gt;(Common Causes and Solutions)&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="409" data-start="380" data-section-id="1q3dgge"&gt;1. UEFI Secure Boot Block:&lt;/H4&gt;
&lt;P data-end="615" data-start="411"&gt;The most common cause on Ubuntu 24.04 is &lt;STRONG data-end="467" data-start="452"&gt;Secure Boot&lt;/STRONG&gt; being enabled without the Palo Alto Networks kernel module signing certificate being enrolled in the system's &lt;STRONG data-end="605" data-start="578"&gt;Machine Owner Key (MOK)&lt;/STRONG&gt; database.&lt;/P&gt;
&lt;H4 data-end="647" data-start="617"&gt;Verify Secure Boot Status&lt;/H4&gt;
&lt;P data-end="675" data-start="649"&gt;Run the following command:&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;mokutil &lt;SPAN class="ͼ12"&gt;--sb-state&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-end="675" data-start="649"&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-end="783" data-start="709"&gt;If the output shows &lt;STRONG data-end="753" data-start="729"&gt;"SecureBoot enabled"&lt;/STRONG&gt;, enroll the PANW certificate.&lt;/P&gt;
&lt;H5 data-end="812" data-start="785"&gt;Locate the Certificate:&lt;/H5&gt;
&lt;P data-end="890" data-start="814"&gt;Replace &lt;CODE data-end="832" data-start="822"&gt;[distro]&lt;/CODE&gt; with the appropriate directory (for example, &lt;CODE data-end="888" data-start="878"&gt;ubuntu24 )&lt;/CODE&gt;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN class="ͼ10"&gt;ls&lt;/SPAN&gt; &lt;SPAN class="ͼ12"&gt;-l&lt;/SPAN&gt;&lt;SPAN&gt; /opt/traps/download/content/km/modules/[distro]/xdr_kernel_cert.der&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;H4&gt;&lt;SPAN&gt;Import the Certificate:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN class="ͼ10"&gt;sudo&lt;/SPAN&gt;&lt;SPAN&gt; mokutil &lt;/SPAN&gt;&lt;SPAN class="ͼ12"&gt;--import&lt;/SPAN&gt;&lt;SPAN&gt; /opt/traps/download/content/km/modules/[distro]/xdr_kernel_cert.der&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;Set a temporary password, reboot the system, and follow the UEFI prompts to &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;" data-end="1201" data-start="1187"&gt;Enroll MOK&lt;/STRONG&gt;&lt;SPAN&gt; using the password you created.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-end="1238" data-start="1235" /&gt;
&lt;H4&gt;2. Unsupported Kernel Version:&lt;/H4&gt;
&lt;P data-end="1454" data-start="1275"&gt;Ubuntu 24.04 uses newer 6.x kernels (for example, 6.8.x). If the specific kernel version is not yet supported by the installed content package, the kernel module may fail to load.&lt;/P&gt;
&lt;H5 data-end="1498" data-start="1456"&gt;Workaround: Switch to User Space Mode:&lt;/H5&gt;
&lt;P data-end="1583" data-start="1500"&gt;User Space mode (eBPF-based) does not require a kernel module for most protections.&lt;/P&gt;
&lt;OL data-end="1858" data-start="1585"&gt;
&lt;LI data-end="1664" data-start="1585" data-section-id="1caeqsb"&gt;
&lt;P data-end="1600" data-start="1588"&gt;Navigate to:&lt;/P&gt;
&lt;P data-end="1664" data-start="1605"&gt;&lt;STRONG data-end="1664" data-start="1605"&gt;Endpoints → Policy Management → Agent Settings Profiles&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="1724" data-start="1666" data-section-id="126xc8p"&gt;Edit the profile assigned to the Ubuntu 24.04 endpoint.&lt;/LI&gt;
&lt;LI data-end="1779" data-start="1726" data-section-id="x2cc6p"&gt;Change &lt;STRONG data-end="1760" data-start="1736"&gt;Agent Operation Mode&lt;/STRONG&gt; to &lt;STRONG data-end="1778" data-start="1764"&gt;User Space&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="1858" data-start="1781" data-section-id="1lrpla2"&gt;Save the profile and wait for the agent to heartbeat and apply the change.&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR data-end="1863" data-start="1860" /&gt;
&lt;H4 data-end="1895" data-start="1865" data-section-id="1evlth3"&gt;3. Kernel Module Load Lock&lt;/H4&gt;
&lt;P data-end="2019" data-start="1897"&gt;The agent may create a &lt;STRONG data-end="1936" data-start="1920"&gt;&lt;CODE data-end="1934" data-start="1922"&gt;.load_lock&lt;/CODE&gt;&lt;/STRONG&gt; file after repeated ungraceful shutdowns to prevent further kernel module loading.&lt;/P&gt;
&lt;H4 data-end="2040" data-start="2021"&gt;Clear the Lock:&lt;/H4&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN class="ͼ10"&gt;sudo&lt;/SPAN&gt;&lt;SPAN&gt; /opt/traps/bin/cytool runtime &lt;/SPAN&gt;&lt;SPAN class="ͼ10"&gt;stop&lt;/SPAN&gt;&lt;SPAN&gt; all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="ͼ10"&gt;sudo&lt;/SPAN&gt; &lt;SPAN class="ͼ10"&gt;rm&lt;/SPAN&gt;&lt;SPAN&gt; /opt/traps/km_utils/.load_lock&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="ͼ10"&gt;sudo&lt;/SPAN&gt;&lt;SPAN&gt; /opt/traps/bin/cytool runtime &lt;/SPAN&gt;&lt;SPAN class="ͼ10"&gt;start&lt;/SPAN&gt;&lt;SPAN&gt; all&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;On some Ubuntu versions, the lock file may instead reside at:&lt;/SPAN&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;/etc/traps/km/.load_lock&lt;/CODE&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;H5&gt;&lt;SPAN&gt;(Verification)&lt;/SPAN&gt;&lt;/H5&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="2362" data-start="2306"&gt;After applying the above steps, verify the agent status:&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;SPAN class="ͼ10"&gt;sudo&lt;/SPAN&gt; /opt/traps/bin/cytool status&lt;/CODE&gt;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;Look for one of the following statuses:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL data-end="2502" data-start="2452"&gt;
&lt;LI data-end="2481" data-start="2452" data-section-id="ts2ms4"&gt;&lt;STRONG data-end="2481" data-start="2454"&gt;Kernel Module is Loaded&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-end="2502" data-start="2482" data-section-id="1skzuht"&gt;&lt;STRONG data-end="2502" data-start="2484"&gt;Bpf is Running&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="2574" data-start="2504"&gt;These indicate that endpoint protection has been successfully enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jun 2026 12:25:14 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-06-17T12:25:14Z</dc:date>
    <item>
      <title>Partialy protected</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/partialy-protected/m-p/1256523#M9384</link>
      <description>&lt;P&gt;Hello everyone, I'm having issues with my Cortex XDR agent. The operational status is partially protected, with the following details:&lt;BR /&gt;1. The OS I'm using is Ubuntu 24.04.0&lt;BR /&gt;2. I'm using the latest agent installer, version 9.2.0.119&lt;BR /&gt;3. The operational status details generally state that the Linux kernel cannot be loaded.&lt;/P&gt;
&lt;P&gt;Is there a solution I can try, or has anyone else experienced something similar before?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 05:05:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/partialy-protected/m-p/1256523#M9384</guid>
      <dc:creator>E.Istanto</dc:creator>
      <dc:date>2026-06-17T05:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: Partialy protected</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/partialy-protected/m-p/1256562#M9386</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/796652325"&gt;@E.Istanto&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day and thanks for attaching the snapshot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="346" data-start="0"&gt;The &lt;STRONG data-end="29" data-start="4"&gt;"Partially Protected"&lt;/STRONG&gt; status on Ubuntu 24.04 with a &lt;STRONG data-end="95" data-start="60"&gt;"Linux kernel cannot be loaded"&lt;/STRONG&gt; error typically indicates that the Cortex XDR kernel module (KM) is either blocked from loading by the operating system or is incompatible with the installed kernel version. Ubuntu 24.04 x86_64 is supported starting with Cortex XDR Agent version 9.2.&lt;/P&gt;
&lt;P data-end="346" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="378" data-start="348" data-section-id="4wivyz"&gt;(Common Causes and Solutions)&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="409" data-start="380" data-section-id="1q3dgge"&gt;1. UEFI Secure Boot Block:&lt;/H4&gt;
&lt;P data-end="615" data-start="411"&gt;The most common cause on Ubuntu 24.04 is &lt;STRONG data-end="467" data-start="452"&gt;Secure Boot&lt;/STRONG&gt; being enabled without the Palo Alto Networks kernel module signing certificate being enrolled in the system's &lt;STRONG data-end="605" data-start="578"&gt;Machine Owner Key (MOK)&lt;/STRONG&gt; database.&lt;/P&gt;
&lt;H4 data-end="647" data-start="617"&gt;Verify Secure Boot Status&lt;/H4&gt;
&lt;P data-end="675" data-start="649"&gt;Run the following command:&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;mokutil &lt;SPAN class="ͼ12"&gt;--sb-state&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-end="675" data-start="649"&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-end="783" data-start="709"&gt;If the output shows &lt;STRONG data-end="753" data-start="729"&gt;"SecureBoot enabled"&lt;/STRONG&gt;, enroll the PANW certificate.&lt;/P&gt;
&lt;H5 data-end="812" data-start="785"&gt;Locate the Certificate:&lt;/H5&gt;
&lt;P data-end="890" data-start="814"&gt;Replace &lt;CODE data-end="832" data-start="822"&gt;[distro]&lt;/CODE&gt; with the appropriate directory (for example, &lt;CODE data-end="888" data-start="878"&gt;ubuntu24 )&lt;/CODE&gt;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN class="ͼ10"&gt;ls&lt;/SPAN&gt; &lt;SPAN class="ͼ12"&gt;-l&lt;/SPAN&gt;&lt;SPAN&gt; /opt/traps/download/content/km/modules/[distro]/xdr_kernel_cert.der&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;H4&gt;&lt;SPAN&gt;Import the Certificate:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN class="ͼ10"&gt;sudo&lt;/SPAN&gt;&lt;SPAN&gt; mokutil &lt;/SPAN&gt;&lt;SPAN class="ͼ12"&gt;--import&lt;/SPAN&gt;&lt;SPAN&gt; /opt/traps/download/content/km/modules/[distro]/xdr_kernel_cert.der&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;Set a temporary password, reboot the system, and follow the UEFI prompts to &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;" data-end="1201" data-start="1187"&gt;Enroll MOK&lt;/STRONG&gt;&lt;SPAN&gt; using the password you created.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-end="1238" data-start="1235" /&gt;
&lt;H4&gt;2. Unsupported Kernel Version:&lt;/H4&gt;
&lt;P data-end="1454" data-start="1275"&gt;Ubuntu 24.04 uses newer 6.x kernels (for example, 6.8.x). If the specific kernel version is not yet supported by the installed content package, the kernel module may fail to load.&lt;/P&gt;
&lt;H5 data-end="1498" data-start="1456"&gt;Workaround: Switch to User Space Mode:&lt;/H5&gt;
&lt;P data-end="1583" data-start="1500"&gt;User Space mode (eBPF-based) does not require a kernel module for most protections.&lt;/P&gt;
&lt;OL data-end="1858" data-start="1585"&gt;
&lt;LI data-end="1664" data-start="1585" data-section-id="1caeqsb"&gt;
&lt;P data-end="1600" data-start="1588"&gt;Navigate to:&lt;/P&gt;
&lt;P data-end="1664" data-start="1605"&gt;&lt;STRONG data-end="1664" data-start="1605"&gt;Endpoints → Policy Management → Agent Settings Profiles&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="1724" data-start="1666" data-section-id="126xc8p"&gt;Edit the profile assigned to the Ubuntu 24.04 endpoint.&lt;/LI&gt;
&lt;LI data-end="1779" data-start="1726" data-section-id="x2cc6p"&gt;Change &lt;STRONG data-end="1760" data-start="1736"&gt;Agent Operation Mode&lt;/STRONG&gt; to &lt;STRONG data-end="1778" data-start="1764"&gt;User Space&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="1858" data-start="1781" data-section-id="1lrpla2"&gt;Save the profile and wait for the agent to heartbeat and apply the change.&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR data-end="1863" data-start="1860" /&gt;
&lt;H4 data-end="1895" data-start="1865" data-section-id="1evlth3"&gt;3. Kernel Module Load Lock&lt;/H4&gt;
&lt;P data-end="2019" data-start="1897"&gt;The agent may create a &lt;STRONG data-end="1936" data-start="1920"&gt;&lt;CODE data-end="1934" data-start="1922"&gt;.load_lock&lt;/CODE&gt;&lt;/STRONG&gt; file after repeated ungraceful shutdowns to prevent further kernel module loading.&lt;/P&gt;
&lt;H4 data-end="2040" data-start="2021"&gt;Clear the Lock:&lt;/H4&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN class="ͼ10"&gt;sudo&lt;/SPAN&gt;&lt;SPAN&gt; /opt/traps/bin/cytool runtime &lt;/SPAN&gt;&lt;SPAN class="ͼ10"&gt;stop&lt;/SPAN&gt;&lt;SPAN&gt; all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="ͼ10"&gt;sudo&lt;/SPAN&gt; &lt;SPAN class="ͼ10"&gt;rm&lt;/SPAN&gt;&lt;SPAN&gt; /opt/traps/km_utils/.load_lock&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="ͼ10"&gt;sudo&lt;/SPAN&gt;&lt;SPAN&gt; /opt/traps/bin/cytool runtime &lt;/SPAN&gt;&lt;SPAN class="ͼ10"&gt;start&lt;/SPAN&gt;&lt;SPAN&gt; all&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;On some Ubuntu versions, the lock file may instead reside at:&lt;/SPAN&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;/etc/traps/km/.load_lock&lt;/CODE&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;H5&gt;&lt;SPAN&gt;(Verification)&lt;/SPAN&gt;&lt;/H5&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="2362" data-start="2306"&gt;After applying the above steps, verify the agent status:&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;&lt;SPAN class="ͼ10"&gt;sudo&lt;/SPAN&gt; /opt/traps/bin/cytool status&lt;/CODE&gt;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;Look for one of the following statuses:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL data-end="2502" data-start="2452"&gt;
&lt;LI data-end="2481" data-start="2452" data-section-id="ts2ms4"&gt;&lt;STRONG data-end="2481" data-start="2454"&gt;Kernel Module is Loaded&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-end="2502" data-start="2482" data-section-id="1skzuht"&gt;&lt;STRONG data-end="2502" data-start="2484"&gt;Bpf is Running&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="2574" data-start="2504"&gt;These indicate that endpoint protection has been successfully enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 12:25:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/partialy-protected/m-p/1256562#M9386</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-06-17T12:25:14Z</dc:date>
    </item>
  </channel>
</rss>

