<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Splunk management port 8089 certificate in Security</title>
    <link>https://community.splunk.com/t5/Security/Custom-Splunk-management-port-8089-certificate/m-p/538147#M12072</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/171872"&gt;@splunkreal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Since Splunk Web is communicating with splunkd running on 8089, you should update web.conf too.&lt;/P&gt;&lt;P&gt;If this server is Deployment server, you should distribute the certificate to clients too. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Feb 2021 18:32:55 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2021-02-01T18:32:55Z</dc:date>
    <item>
      <title>Custom Splunk management port 8089 certificate</title>
      <link>https://community.splunk.com/t5/Security/Custom-Splunk-management-port-8089-certificate/m-p/538142#M12071</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;tried to update server.conf but Splunk crashed with handshake failure accessing &lt;A href="https://localhost:8089" target="_blank"&gt;https://localhost:8089&lt;/A&gt;&lt;/P&gt;&lt;P&gt;[sslConfig]&lt;BR /&gt;#sslPassword = $7$OXZyp5GzoeMoXOIUSMqIFC+4Od7JKUacyjpUPBRobqwXbKYgAoObNg==&lt;BR /&gt;serverCert = $SPLUNK_HOME/etc/apps/APP_OUTPUTS/default/preproduction-server.pem&lt;BR /&gt;sslPassword = xxx&lt;BR /&gt;sslRootCAPath = $SPLUNK_HOME/etc/apps/APP_OUTPUTS/default/preproduction-cacert.pem&lt;BR /&gt;requireClientCert = true&lt;/P&gt;&lt;P&gt;Is it necessary to also update web.conf according to &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.4/Security/Securingyourdeploymentserverandclients?" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.4/Security/Securingyourdeploymentserverandclients?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;May it break the deployment server / DS clients?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also does it impact implementation of [tcp-ssl] port?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 18:23:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Custom-Splunk-management-port-8089-certificate/m-p/538142#M12071</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2021-02-01T18:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Splunk management port 8089 certificate</title>
      <link>https://community.splunk.com/t5/Security/Custom-Splunk-management-port-8089-certificate/m-p/538147#M12072</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/171872"&gt;@splunkreal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Since Splunk Web is communicating with splunkd running on 8089, you should update web.conf too.&lt;/P&gt;&lt;P&gt;If this server is Deployment server, you should distribute the certificate to clients too. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 18:32:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Custom-Splunk-management-port-8089-certificate/m-p/538147#M12072</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-01T18:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Splunk management port 8089 certificate</title>
      <link>https://community.splunk.com/t5/Security/Custom-Splunk-management-port-8089-certificate/m-p/538247#M12073</link>
      <description>&lt;P&gt;Thanks it works &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I used&amp;nbsp;requireClientCert&amp;nbsp; = false as certification is not dedicated to my host otherwise do you mean we should distribute the certificates to deployment clients, this would be time-consuming and out of Splunk scope (deploy certs through Puppet/Ansible for instance)?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 09:30:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Custom-Splunk-management-port-8089-certificate/m-p/538247#M12073</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2021-02-02T09:30:27Z</dc:date>
    </item>
  </channel>
</rss>

