For the certificate PEM file, you must concatenate the certificate
chain one after the other in the file. The SSL certificate should
come first, and the CA certificate(s) second. Only the certificate
itself is needed, i.e. the text between and including
You can store the key and certificate in a different location,
by changing the
adding the locations below:
Ensure both files have the correct ownership: demisto:demisto
If your private key is encrypted, you need to add the key password
to the one-time-configuration (OTC) file located in
After the file is saved and the Cortex XSOAR server is restarted,
the OTC file is automatically deleted. Add the following content
to the OTC file.
Cortex XSOAR server does not support PKCS#8 encrypted PEM files.To
validate that the file is supported, check that the "DEK-Info" header exists.
When using a Safari browser, the self-signed
certificate must be added to the OS Keychain.