Closed f47sh33p closed 1 month ago
Hello, thank you for reporting the issue. I'm looking into it but a question to be sure: is the http-playbook.json the one that we provide?
Yes, that's correct. I haven't made any changes to it. Additionally, I encounter the same error with the other two playbooks in the example folder.
We have reproduced it for us it seems to be a DNS issue with docker. Can you give us your trace
logs of the soarca_server?
According to the logs, the following error occurred.
{"component":"soarca/models/decoder","level":"error","msg":"jsonschema https://raw.githubusercontent.com/opencybersecurityalliance/cacao-roaster/main/lib/cacao-json-schemas/schemas/playbook.json compilation failed: Get \"https://raw.githubusercontent.com/opencybersecurityalliance/cacao-roaster/main/lib/cacao-json-schemas/schemas/playbook.json\": tls: failed to verify certificate: x509: certificate signed by unknown authority","time":"2024-07-25T02:45:55Z"}
SOARCA is connected under a proxy and decrypts SSL encryption. Therefore, it seems that configuring the proxy certificate might resolve the issue. Could you please advise on how to set it up?
The docker container now only imports the default root CA certificates, if you use your own certificates those are (by design) not trusted and rejected in SOARCA. For the capabilities we created a way to allow self signed certificates. But for getting the schema's we did not make this exception. As we want to move the schema's inside of SOARCA this will be resolved in the future. You could do several things:
If you have any further questions let me know
Thank you for the information. I plan to try the third method, but I have a couple of questions: (1) It seems that there is no "bin" directory in the GitHub repository. How should I create it? (2) What should be specified for the VERSION mentioned in the Dockerfile?
You can use make docker
to compile and build the docker image. This will create the bin folder with the latest build and add the git version.
@f47sh33p I've updated the schema validation to be local to SOARCA in #199 if that is merged you can use the dockerhub soaca:development
tag to use this for your application.
Describe the bug When attempting to execute the playbook, a 400 error occurs.
To Reproduce provide details logs and steps The error occurs when following the steps outlined in the documentation.
Expected behavior The process should complete without encountering a 400 error.
Environment information The environment is deployed using Docker.