IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: Why Do the Agents & Server Seem to be Reaching Out to Unknown IP Addresses?

App Control: Why Do the Agents & Server Seem to be Reaching Out to Unknown IP Addresses?

Environment

  • App Control Server: All Supported Versions
  • App Control Agent: All Supported Versions
  • Microsoft Windows; All Supported Versions

Question

Why are the Agents and the Server seem to be reaching out to unknown IP Addresses?

Answer

This will occur when the Server or Agent uses the Microsoft CrytoAPI to perform local certificate and publisher validation requests. This is expected behavior.

Additional Notes

  • The App Control server will also reach out in order to verify certificate information once per week to various CRLs
  • If needed Capi logging can be enabled per this article to identify CryptoAPI traffic
  • More information is available in the User Guide:
    Note: Regardless of whether agent-based certificate revocation checks are enabled, the Carbon Black 
    App Control Server validates certificates in its inventory on a recurring basis to make
    sure that they have not been revoked. This validation generally occurs on a weekly basis and
    involves downloading certificate revocation lists (CRLs) from registration authorities or making
    Online Certificate Status Protocol (OCSP) calls to OCSP responders. These downloads can involve
    a variety of sites in a variety of countries.
    
    Server-based validation checks inform administrators when the status of a certificate changes,
    but they do not affect enforcement of rules. Enable agent-based revocation checks if you want
    revocations to affect rule behavior.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
0% helpful (0/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
686
Contributors