<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are wildcard certificates supported with Splunk and https? in Security</title>
    <link>https://community.splunk.com/t5/Security/Are-wildcard-certificates-supported-with-Splunk-and-https/m-p/38458#M1290</link>
    <description>&lt;P&gt;I've used splunkweb with wildcard certificates before with no problems - Have you tried accessing it with openssl to see if that reveals any more specific information?  Also check web_service.log to confirm that it's loaded the certificate without error&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;openssl s_client -connect hostname:port 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 07 Jul 2011 03:57:31 GMT</pubDate>
    <dc:creator>gareth</dc:creator>
    <dc:date>2011-07-07T03:57:31Z</dc:date>
    <item>
      <title>Are wildcard certificates supported with Splunk and https?</title>
      <link>https://community.splunk.com/t5/Security/Are-wildcard-certificates-supported-with-Splunk-and-https/m-p/38457#M1289</link>
      <description>&lt;P&gt;wondering if Splunk https works with third-party wildcard certs.&lt;/P&gt;

&lt;P&gt;so far I got my Splunk indexer to start using my third-party wildcard cert by changing web.conf to use the absolute path vs the relative path that the Splunk doc pages suggest, but splunk/https won't serve pages.&lt;/P&gt;

&lt;P&gt;We have a third-party cert we use so that https://*.com  is signed.&lt;/P&gt;

&lt;P&gt;Since this can be insecure and may be hard to do, many vendors will only support certificates that go to a specific dns cname or a record, such as &lt;A href="https://splunk.abc123.com" target="_blank"&gt;https://splunk.abc123.com&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;My web.conf is:&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
[settings]&lt;BR /&gt;
enableSplunkWebSSL = 1&lt;BR /&gt;
privKeyPath =  /etc/foo/certs/_.abc123.com.pem&lt;BR /&gt;
caCertPath =  /etc/foo/cert.pem&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Splunk Web server starts with no errors, but when I hit the login page I get:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;BR /&gt;
    ssl_error_no_cypher_overlap&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Can anyone confirm if wildcard certs with Splunk are really supported or not?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:43:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Are-wildcard-certificates-supported-with-Splunk-and-https/m-p/38457#M1289</guid>
      <dc:creator>maverick</dc:creator>
      <dc:date>2020-09-28T09:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Are wildcard certificates supported with Splunk and https?</title>
      <link>https://community.splunk.com/t5/Security/Are-wildcard-certificates-supported-with-Splunk-and-https/m-p/38458#M1290</link>
      <description>&lt;P&gt;I've used splunkweb with wildcard certificates before with no problems - Have you tried accessing it with openssl to see if that reveals any more specific information?  Also check web_service.log to confirm that it's loaded the certificate without error&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;openssl s_client -connect hostname:port 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 07 Jul 2011 03:57:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Are-wildcard-certificates-supported-with-Splunk-and-https/m-p/38458#M1290</guid>
      <dc:creator>gareth</dc:creator>
      <dc:date>2011-07-07T03:57:31Z</dc:date>
    </item>
  </channel>
</rss>

