- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-12-2024 12:38 AM
Hi Team,
I have enabled the Cortex XDR agent settings for certificate enforcement. However, endpoints are showing as only partially protected, and the Operational Status Details indicate that certificate enforcement is disabled against policy (Failed to enable certificate enforcement due to local store fallback). Could you please help with this issue?
06-12-2024 12:41 AM
Hello @Vinothkumar_SBA ,
As you have mentioned the error is "Failed to enable certificate enforcement due to local-store fallback". That means Certificate enforcement is not enabled and instead of root.pem , the agent is using Local store certificate which is not recommended. Hence, partially protected.
The solution is not disabling the policy, it is finding out why it is falling back. The reason may be that, you are decrypting the agent traffic or SSL inspection is enabled in your proxy or VPN.
Hence, please open a TAC support case to troubleshoot further.
If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".
08-13-2024 08:00 PM
Dear Aspatil,
I have the same problem, does this error affect the protection ability or even the functionality of the Agent?
What adjustments would you recommend? Thank you.
09-30-2024 12:44 PM
Hi, same problem here and yes, we're doing deep packet inspection, as many others do. Strangely, not all the endpoints are in partially protected state while they all have their traffic scanned with DPI. What toubleshooting is required in this case, as we can confirm that we have DPI in place? Would they add our private CA to the root ca pem file?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!