<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which default certificate should I use to certify my HTTP Event Collector in Security</title>
    <link>https://community.splunk.com/t5/Security/Which-default-certificate-should-I-use-to-certify-my-HTTP-Event/m-p/421256#M10010</link>
    <description>&lt;P&gt;Thank you for your answer. I verified that server.pem is in use using openssl. That should be what I need, thanks again&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2019 20:38:25 GMT</pubDate>
    <dc:creator>llovell</dc:creator>
    <dc:date>2019-08-01T20:38:25Z</dc:date>
    <item>
      <title>Which default certificate should I use to certify my HTTP Event Collector</title>
      <link>https://community.splunk.com/t5/Security/Which-default-certificate-should-I-use-to-certify-my-HTTP-Event/m-p/421254#M10008</link>
      <description>&lt;P&gt;I am running some C# code that sends a POST request to my Splunk HTTP Event Collector at the following URL - &lt;A href="https://localhost:8088/services/collector/raw"&gt;https://localhost:8088/services/collector/raw&lt;/A&gt; to submit a log&lt;/P&gt;

&lt;P&gt;I am getting the following error: Peer certificate cannot be authenticated with given CA certificates ( If I make the request in Postman my logs are submitted no problem )&lt;/P&gt;

&lt;P&gt;I am thinking that I need to load my Splunk servers default certificate onto the machine I am making the request from. If this is correct I need to know which of the default certificates ( this is just for testing purposes ) I should be loading that would be specific to my HEC. And also if the correct certificates I'm looking for are located here C:\Program Files\Splunk\etc\auth&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 17:56:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Which-default-certificate-should-I-use-to-certify-my-HTTP-Event/m-p/421254#M10008</guid>
      <dc:creator>llovell</dc:creator>
      <dc:date>2019-08-01T17:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Which default certificate should I use to certify my HTTP Event Collector</title>
      <link>https://community.splunk.com/t5/Security/Which-default-certificate-should-I-use-to-certify-my-HTTP-Event/m-p/421255#M10009</link>
      <description>&lt;P&gt;ca.pem is the splunk ca&lt;BR /&gt;
server.pem is what will run by default on 8089&lt;/P&gt;

&lt;P&gt;I believe it is also used for HEC by default.&lt;/P&gt;

&lt;P&gt;Hope that helps!&lt;/P&gt;

&lt;P&gt;You can check which cert is in use with openssl&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; openssl s_client -connect yourhost:hecport 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Openssl can be found in splunkhome/bin&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 19:44:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Which-default-certificate-should-I-use-to-certify-my-HTTP-Event/m-p/421255#M10009</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-08-01T19:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: Which default certificate should I use to certify my HTTP Event Collector</title>
      <link>https://community.splunk.com/t5/Security/Which-default-certificate-should-I-use-to-certify-my-HTTP-Event/m-p/421256#M10010</link>
      <description>&lt;P&gt;Thank you for your answer. I verified that server.pem is in use using openssl. That should be what I need, thanks again&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 20:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Which-default-certificate-should-I-use-to-certify-my-HTTP-Event/m-p/421256#M10010</guid>
      <dc:creator>llovell</dc:creator>
      <dc:date>2019-08-01T20:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Which default certificate should I use to certify my HTTP Event Collector</title>
      <link>https://community.splunk.com/t5/Security/Which-default-certificate-should-I-use-to-certify-my-HTTP-Event/m-p/421257#M10011</link>
      <description>&lt;P&gt;Cheers!  It was my pleasure!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 21:15:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Which-default-certificate-should-I-use-to-certify-my-HTTP-Event/m-p/421257#M10011</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-08-01T21:15:33Z</dc:date>
    </item>
  </channel>
</rss>

