<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guidance on “Unverified Insecure SSH Private Key” flagged by Defender for Cloud in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Guidance-on-Unverified-Insecure-SSH-Private-Key-flagged-by/m-p/2530957#M32226</link>
    <description>&lt;P&gt;Is it same for the ".Local Certificates" folder ?&lt;/P&gt;</description>
    <pubDate>Tue, 16 Sep 2025 14:18:57 GMT</pubDate>
    <dc:creator>fabdulazeez</dc:creator>
    <dc:date>2025-09-16T14:18:57Z</dc:date>
    <item>
      <title>Guidance on “Unverified Insecure SSH Private Key” flagged by Defender for Cloud</title>
      <link>https://community.qlik.com/t5/Management-Governance/Guidance-on-Unverified-Insecure-SSH-Private-Key-flagged-by/m-p/2530940#M32224</link>
      <description>&lt;P&gt;Defender for Cloud has raised an alert: &lt;STRONG&gt;“Unverified insecure SSH Private Key.”&lt;/STRONG&gt;&lt;BR /&gt;It appears to be pointing to the &lt;STRONG&gt;Exported Certificates&lt;/STRONG&gt; folder created by Qlik Sense.&lt;/P&gt;&lt;P&gt;C:\ProgramData\Qlik\Sense\Repository\Exported Certificates&lt;/P&gt;&lt;P&gt;I would like to know:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;How can we mitigate this alert?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Is it safe to delete all the folders within &lt;EM&gt;Exported Certificates including .Local&lt;/EM&gt;?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;What would be the impact on Qlik Sense services if these folders are deleted?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Is there an alternative approach (e.g., securing or relocating the keys) instead of deletion?&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;We have a single node Qlik sense Enterprise on Windows may 2025 version on azure VM.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 12:34:28 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Guidance-on-Unverified-Insecure-SSH-Private-Key-flagged-by/m-p/2530940#M32224</guid>
      <dc:creator>fabdulazeez</dc:creator>
      <dc:date>2025-09-16T12:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Guidance on “Unverified Insecure SSH Private Key” flagged by Defender for Cloud</title>
      <link>https://community.qlik.com/t5/Management-Governance/Guidance-on-Unverified-Insecure-SSH-Private-Key-flagged-by/m-p/2530954#M32225</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/10066"&gt;@fabdulazeez&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;those certificates are not explicitly used by Qlik Sense Enterprise during its activity.&lt;/P&gt;
&lt;P&gt;They are just exports that are usually manually created by the administrators when needed for third party purposes (like API calls).&lt;BR /&gt;See&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Export-client-certificate-and-root-certificate-to-make-API-calls/ta-p/1715515" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Official-Support-Articles/Export-client-certificate-and-root-certificate-to-make-API-calls/ta-p/1715515&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://help.qlik.com/en-US/sense-admin/May2025/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/export-certificates.htm" target="_blank"&gt;https://help.qlik.com/en-US/sense-admin/May2025/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/export-certificates.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Once the certificates have been properly reimported for use by third party tools or the user making the API calls, they can be deleted or stored in another safe location. They can also be re-exported to the same folder in any moment, if needed.&lt;/P&gt;
&lt;P&gt;I hope this clarifies it!&lt;BR /&gt;&lt;BR /&gt;Daniele&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 14:09:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Guidance-on-Unverified-Insecure-SSH-Private-Key-flagged-by/m-p/2530954#M32225</guid>
      <dc:creator>Daniele_Purrone</dc:creator>
      <dc:date>2025-09-16T14:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Guidance on “Unverified Insecure SSH Private Key” flagged by Defender for Cloud</title>
      <link>https://community.qlik.com/t5/Management-Governance/Guidance-on-Unverified-Insecure-SSH-Private-Key-flagged-by/m-p/2530957#M32226</link>
      <description>&lt;P&gt;Is it same for the ".Local Certificates" folder ?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 14:18:57 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Guidance-on-Unverified-Insecure-SSH-Private-Key-flagged-by/m-p/2530957#M32226</guid>
      <dc:creator>fabdulazeez</dc:creator>
      <dc:date>2025-09-16T14:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Guidance on “Unverified Insecure SSH Private Key” flagged by Defender for Cloud</title>
      <link>https://community.qlik.com/t5/Management-Governance/Guidance-on-Unverified-Insecure-SSH-Private-Key-flagged-by/m-p/2530966#M32227</link>
      <description>&lt;P&gt;Yes. None of the certificates used in "&lt;SPAN&gt;Exported Certificates" are actively used.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you want to be safe, you can zip the folders and store them somewhere else.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 14:41:37 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Guidance-on-Unverified-Insecure-SSH-Private-Key-flagged-by/m-p/2530966#M32227</guid>
      <dc:creator>Daniele_Purrone</dc:creator>
      <dc:date>2025-09-16T14:41:37Z</dc:date>
    </item>
  </channel>
</rss>

