IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: Why Is the Server Generating Alerts for Revoked Certificates?

App Control: Why Is the Server Generating Alerts for Revoked Certificates?

Environment

  • App Control Console: All Supported Versions

Question

Why is the Server generating Revoked Certificate Alerts similar to:
Server detected revocation of certificate 'ABC123'. Error: 04000025:CERT_TRUST_IS_NOT_TIME_VALID:CERT_TRUST_IS_REVOKED:CERT_TRUST_IS_UNTRUSTED_ROOT:CERT_TRUST_IS_EXPLICIT_DISTRUST

Answer

The Built-in Revoked Certificate Alert (Tools > Alerts > Revoked Certificate Alert) has been Enabled. This Alert is designed to trigger when a Certificate Authority has revoked a Certificate that matches one in the environment.

Additional Notes

  • Typically a certificate would be revoked due to encryption keys being compromised, inaccurate information in the certificate, or if the Certificate Owner is no longer deemed as trusted.
  • In some instances customers configure this Alert so that they can take further action. This may include removing a Certificate Approval, or verifying no new files signed with the Revoked Certificate exist in the environment 
  • The Alert can be configured to trigger only for specific Publishers, "Example: Apple, Inc".

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
0% helpful (0/1)
Article Information
Author:
Creation Date:
‎03-09-2023
Views:
551
Contributors