Carbon Black Cloud: Does Disabling the CRL Check on Sensors Open Communications to Man in the Middle Attacks?
search cancel

Carbon Black Cloud: Does Disabling the CRL Check on Sensors Open Communications to Man in the Middle Attacks?


Article ID: 288890


Updated On:


Carbon Black Cloud Endpoint Standard (formerly Cb Defense) Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)


Does disabling the Certificate Revocation List (CRL) check at the time of Sensor install result in the Sensor becoming open to man-in-the-middle attacks?


  • Carbon Black Cloud Sensor: All Supported VersionsĀ 
  • Microsoft Windows: All supported versions


Disabling the CRL check does not immediately open the Sensor to man in the middle attacks

Additional Information

  • CRL checks often fail when proxies are involved because the CRL check process is offloaded to WinHTTP