Error:
An unexpected error occurred. Please click Reload to try again.
Error:
An unexpected error occurred. Please click Reload to try again.
Prisma Cloud Defender showing Status Error "Failed to update admission control settings failed loading admission controller certificates: failed to decode key" under Features section

Prisma Cloud Defender showing Status Error "Failed to update admission control settings failed loading admission controller certificates: failed to decode key" under Features section

4700
Created On 10/31/22 04:28 AM - Last Modified 12/08/22 03:32 AM


Symptom


  • Prisma Cloud Defender showing Status Error "Failed to update admission control settings failed loading admission controller certificates: failed to decode key" under Features section
Screenshot 2022-10-31 at 12.04.12 PM.png


Environment


  • Prisma Cloud (Compute section)


Cause


  • An admission controller is a piece of code that intercepts requests to the Kubernetes API server prior to persistence of the object, but after the request is authenticated and authorized.
  • For the same, it observes requests to approve 'CertificateSigningRequest' resources and performs additional authorization checks to ensure the approving user has the permission.
  • The Privilege Level set during the Defender Deployment may fail the requirement to load the admission controller certificates for authorization.


Resolution


  • Enable the Privileged level (or change it to True) during the Defender Daemonset Deployment.
Screenshot 2022-10-31 at 12.15.26 PM.png
  • This can be confirmed in the downloaded YAML file.
Screenshot 2022-10-31 at 12.16.15 PM.png
  • Once this is done, redeploy the Defender.


Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kEuGCAU&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language