<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable SHA256 in Security</title>
    <link>https://community.splunk.com/t5/Security/Enable-SHA256/m-p/515271#M11724</link>
    <description>&lt;P&gt;What exactly do you wish to encrypt?&lt;/P&gt;&lt;P&gt;Eight years is a very long time in the Splunk world so you're right to question the validity of information that old.&lt;/P&gt;&lt;P&gt;The document you cited is also very old, but, fortunately, there's a newer version available at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Security/Dataintegritycontrol" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Security/Dataintegritycontrol&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/etc/system/local is fairly empty by default.&amp;nbsp; That's because this directory is intended to hold changes made to the local system (get it?) configuration.&amp;nbsp; The only thing you need to add to a local file is the attribute and value you are changing as well as name of the stanza the contains the attribute.&amp;nbsp; For example, to enable SHA256 encryption for outputbound SAML messages, the local/system file might look like this.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[SAML]
signatureAlgorithm = RSA-SHA256&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 20 Aug 2020 17:55:00 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-08-20T17:55:00Z</dc:date>
    <item>
      <title>Enable SHA256</title>
      <link>https://community.splunk.com/t5/Security/Enable-SHA256/m-p/515257#M11723</link>
      <description>&lt;P&gt;Hello again, hope not to disturb&lt;/P&gt;&lt;P&gt;I need to activate SHA256 encryption&lt;/P&gt;&lt;P&gt;What I have investigated is a function that does not come active by default in splunk&lt;/P&gt;&lt;P&gt;This &lt;A href="https://community.splunk.com/t5/Archive/Does-Splunk-Support-ShA-256-or-SHA-1/td-p/87404?sort=newest" target="_self"&gt;link&lt;/A&gt; gives information but I have a couple of doubts, the first is if the information is still valid since it is 8 years ago and second the audit.conf file does not exist in the path &lt;STRONG&gt;/ splunk / etc / system / local&lt;/STRONG&gt; so I understand that I must create it, it is not clear to me what information should go on the white list or on the black list, extension of the logs? the name of any indexer? should it be done in the indexers or in the search head?&lt;/P&gt;&lt;P&gt;I see &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.3.0/Security/Dataintegritycontrol" target="_self"&gt;another article&lt;/A&gt; on the integrity of the information, does the same? or which option is better?&lt;/P&gt;&lt;P&gt;Note: whenever possible, I would appreciate it if you specify the paths when mentioning a file since either I am very stupid or all forum users know by heart the paths where each of the files are located&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 16:09:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Enable-SHA256/m-p/515257#M11723</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2020-08-20T16:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SHA256</title>
      <link>https://community.splunk.com/t5/Security/Enable-SHA256/m-p/515271#M11724</link>
      <description>&lt;P&gt;What exactly do you wish to encrypt?&lt;/P&gt;&lt;P&gt;Eight years is a very long time in the Splunk world so you're right to question the validity of information that old.&lt;/P&gt;&lt;P&gt;The document you cited is also very old, but, fortunately, there's a newer version available at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Security/Dataintegritycontrol" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Security/Dataintegritycontrol&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/etc/system/local is fairly empty by default.&amp;nbsp; That's because this directory is intended to hold changes made to the local system (get it?) configuration.&amp;nbsp; The only thing you need to add to a local file is the attribute and value you are changing as well as name of the stanza the contains the attribute.&amp;nbsp; For example, to enable SHA256 encryption for outputbound SAML messages, the local/system file might look like this.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[SAML]
signatureAlgorithm = RSA-SHA256&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 20 Aug 2020 17:55:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Enable-SHA256/m-p/515271#M11724</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-20T17:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SHA256</title>
      <link>https://community.splunk.com/t5/Security/Enable-SHA256/m-p/515311#M11725</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I really appreciate your answer&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;to encrypt the information that is stored in the indexers, or when the data is stored in the different types of buckets&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;my client wants me to reassure him that the information stored is not readable&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 20:57:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Enable-SHA256/m-p/515311#M11725</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2020-08-20T20:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SHA256</title>
      <link>https://community.splunk.com/t5/Security/Enable-SHA256/m-p/515438#M11726</link>
      <description>Splunk does not support encryption of buckets or indexes.</description>
      <pubDate>Fri, 21 Aug 2020 12:45:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Enable-SHA256/m-p/515438#M11726</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-21T12:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SHA256</title>
      <link>https://community.splunk.com/t5/Security/Enable-SHA256/m-p/515841#M11741</link>
      <description>&lt;P&gt;Tnx&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mw-headline"&gt;Configure data integrity control&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;To configure Data Integrity Control, edit&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;indexes.conf&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to enable the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;enableDataIntegrityControl&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;attribute for each index. The default value for all indexes is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;false&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(off).&lt;/P&gt;&lt;PRE&gt;enableDataIntegrityControl=true&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 16:50:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Enable-SHA256/m-p/515841#M11741</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2020-08-24T16:50:20Z</dc:date>
    </item>
  </channel>
</rss>

