<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using X509 certificates in Security</title>
    <link>https://community.splunk.com/t5/Security/Using-X509-certificates/m-p/583749#M15872</link>
    <description>&lt;P&gt;This is not Splunk Support. Splunk Support is a service you pay for.&lt;/P&gt;&lt;P&gt;This is a community forum. We share knowledge out of our own free will.&lt;/P&gt;&lt;P&gt;Ok, we got this out of the way.&lt;/P&gt;&lt;P&gt;If you have a certificate installed for the web server it's up to the client who connects to the server to decide whether he wants to connect to a server which presents an invalid certificate or not.&lt;/P&gt;&lt;P&gt;There is an option for server.conf and outputs.conf called sslVerifyServerCert but I'm not sure if it disables expiry verification or only name/CA verification.&lt;/P&gt;&lt;P&gt;Anyway, you don't want expired certificates. Keep your environment current and secured.&lt;/P&gt;</description>
    <pubDate>Fri, 04 Feb 2022 17:22:48 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2022-02-04T17:22:48Z</dc:date>
    <item>
      <title>Using X509 certificates</title>
      <link>https://community.splunk.com/t5/Security/Using-X509-certificates/m-p/583748#M15871</link>
      <description>&lt;P&gt;Dear Support,&lt;/P&gt;&lt;P&gt;We use X509 certificates provided by our customer certificate authority, in order to use HTTPS protocol for web pages and to encrypt the communication between instances in TLS 1.2.&lt;/P&gt;&lt;P&gt;- Modification of the file &lt;EM&gt;/opt/splunk/etc/system/local/web.conf&lt;/EM&gt; for the Web Pages&lt;/P&gt;&lt;P&gt;- Modification of the file &lt;EM&gt;/opt/splunk/etc/system/local/server.conf&lt;/EM&gt; for the encryption of the communication between the instances&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If these certificates are expired, can you tell us if an issue is expected or if the solution will still work in a degraded mode, with warning messages indicating that the certificates are expired?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance for your answer.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Malik GHALEB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 17:11:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Using-X509-certificates/m-p/583748#M15871</guid>
      <dc:creator>mghaleb</dc:creator>
      <dc:date>2022-02-04T17:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Using X509 certificates</title>
      <link>https://community.splunk.com/t5/Security/Using-X509-certificates/m-p/583749#M15872</link>
      <description>&lt;P&gt;This is not Splunk Support. Splunk Support is a service you pay for.&lt;/P&gt;&lt;P&gt;This is a community forum. We share knowledge out of our own free will.&lt;/P&gt;&lt;P&gt;Ok, we got this out of the way.&lt;/P&gt;&lt;P&gt;If you have a certificate installed for the web server it's up to the client who connects to the server to decide whether he wants to connect to a server which presents an invalid certificate or not.&lt;/P&gt;&lt;P&gt;There is an option for server.conf and outputs.conf called sslVerifyServerCert but I'm not sure if it disables expiry verification or only name/CA verification.&lt;/P&gt;&lt;P&gt;Anyway, you don't want expired certificates. Keep your environment current and secured.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 17:22:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Using-X509-certificates/m-p/583749#M15872</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-04T17:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Using X509 certificates</title>
      <link>https://community.splunk.com/t5/Security/Using-X509-certificates/m-p/583768#M15873</link>
      <description>&lt;P&gt;For TLS if the certificate expires you will not get data sent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 19:49:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Using-X509-certificates/m-p/583768#M15873</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2022-02-04T19:49:30Z</dc:date>
    </item>
  </channel>
</rss>

