Cortex XDR Agent certificate enforcement

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR Agent certificate enforcement

L3 Networker

Hi Team,

I have enabled the Cortex XDR agent settings for certificate enforcement. However, endpoints are showing as only partially protected, and the Operational Status Details indicate that certificate enforcement is disabled against policy (Failed to enable certificate enforcement due to local store fallback). Could you please help with this issue?

3 REPLIES 3

L5 Sessionator

Hello @Vinothkumar_SBA ,

 

As you have mentioned the error is "Failed to enable certificate enforcement due to local-store fallback". That means Certificate enforcement is not enabled and instead of root.pem , the agent is using Local store certificate which is not recommended. Hence, partially protected.

 

The solution is not disabling the policy, it is finding out why it is falling back. The reason may be that, you are decrypting the agent traffic or SSL inspection is enabled in your proxy or VPN.

 

Hence, please open a TAC support case to troubleshoot further.

 

If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".

Ashutosh Patil

L0 Member

Dear Aspatil,

I have the same problem, does this error affect the protection ability or even the functionality of the Agent?

 

What adjustments would you recommend? Thank you.

Hi, same problem here and yes, we're doing deep packet inspection, as many others do. Strangely, not all the endpoints are in partially protected state while they all have their traffic scanned with DPI. What toubleshooting is required in this case, as we can confirm that we have DPI in place? Would they add our private CA to the root ca pem file?

  • 1327 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!