<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Expired SSL Cert? in Security</title>
    <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55062#M1845</link>
    <description>&lt;P&gt;Thanks for the help&lt;/P&gt;</description>
    <pubDate>Sat, 08 Sep 2012 05:18:40 GMT</pubDate>
    <dc:creator>mntbighker</dc:creator>
    <dc:date>2012-09-08T05:18:40Z</dc:date>
    <item>
      <title>Expired SSL Cert?</title>
      <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55060#M1843</link>
      <description>&lt;P&gt;It seems that on Aug. 15th my vanilla Splunk SSL cert expired:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;09-07-2012 17:28:38.987 -0700 ERROR TcpInputProc - Error encountered for connection from src=xxx.xxx.xxx.xxx:3353. error:14094415:SSL routines:SSL3_READ_BYTES:sslv3 alert certificate expired
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have never wanted or needed to mess with my own cert. Our only requirement has been to encrypt over the wire. So all my log aggregation it seems came to a grinding halt 3 weeks ago. Is Splunk going to publish a process to fix this or will it be an excruciating manual process involving every host including the forwarders and the server? I'm running 4.3.3 on the server.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2012 01:04:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55060#M1843</guid>
      <dc:creator>mntbighker</dc:creator>
      <dc:date>2012-09-08T01:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Expired SSL Cert?</title>
      <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55061#M1844</link>
      <description>&lt;P&gt;Unless the rootCA has expired, you only need a new server certificate. Use &lt;CODE&gt;splunk createssl server-cert&lt;/CODE&gt; to create a new one certificate to replace the one you are using. You don't say how you have configured anything, but presumably you're using the default server.pem on the server, and no certificates on the client. Of course if you did enable client certificate verification, those will have to be regenerated as well.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2012 03:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55061#M1844</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-09-08T03:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Expired SSL Cert?</title>
      <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55062#M1845</link>
      <description>&lt;P&gt;Thanks for the help&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2012 05:18:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55062#M1845</guid>
      <dc:creator>mntbighker</dc:creator>
      <dc:date>2012-09-08T05:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Expired SSL Cert?</title>
      <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55063#M1846</link>
      <description>&lt;P&gt;mntbighker - did this answer actually help you? I sense sarcasm (good for you if it was).&lt;/P&gt;

&lt;P&gt;At any rate, I'm having the same issue now. I tracked it back to expired certs - 3 years to the day of installing Splunk, all my forwarders have crapped out with the same errors you are seeing. &lt;/P&gt;

&lt;P&gt;I have regenerated the $SPLUNK_HOME/etc/auth/server.pem on my master Splunk server using &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;splunk createssl server-cert&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I am still getting the errors. &lt;/P&gt;

&lt;P&gt;When we installed Splunk and the forwarders, all of this was generated automatically behind the scenes (or at least the majority). &lt;/P&gt;

&lt;P&gt;Here's the problems I have with this issue: &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;I'm seeing tons of users on Splunk.com reporting this issue - some as old as 2008 at least&lt;/LI&gt;
&lt;LI&gt;We received no warning from Splunk - this is kind of important - why isn't Splunk checking itself for this?&lt;/LI&gt;
&lt;LI&gt;This is internal to the Splunk tool itself - why does it not auto-generate new certs (if you're using self signed certs anyway). &lt;/LI&gt;
&lt;LI&gt;Why are there no clear documents on how to fix this? The forums are nice, but this is a problem that ALL of Splunk's users will encounter at some point&lt;/LI&gt;
&lt;LI&gt;Why is Splunk not putting effort into making this better / fixing this? To get to this error, you had to be a paying customer for 3+ years. You should really want to keep us happy. &lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I want a patch, or a very clear path to fixing this. I have a dozen forwarders that have been silent for a week before anyone noticed. &lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2014 22:17:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55063#M1846</guid>
      <dc:creator>mdaedalus</dc:creator>
      <dc:date>2014-05-21T22:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Expired SSL Cert?</title>
      <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55064#M1847</link>
      <description>&lt;P&gt;I have been asking them to support SSL enabled forwarders in the web GUI and NOTHING has improved in many versions. In fact it takes major effort to make them understand what I mean, so I must presume that most people never bother with SSL (weird). Anyway, if they have this general attitude, then this situation about no support on expiring certs does'nt not surprise me in the least.&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2014 00:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55064#M1847</guid>
      <dc:creator>mntbighker</dc:creator>
      <dc:date>2014-05-22T00:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Expired SSL Cert?</title>
      <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55065#M1848</link>
      <description>&lt;P&gt;This isn't an answer - it's a question (and continuation of the other question asked by the original poster). &lt;/P&gt;

&lt;P&gt;I tried to convert this answer to a question and keep getting a 500 error from the web server.&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2014 19:36:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55065#M1848</guid>
      <dc:creator>mdaedalus</dc:creator>
      <dc:date>2014-05-23T19:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: Expired SSL Cert?</title>
      <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55066#M1849</link>
      <description>&lt;P&gt;heh, ya "thanks for the help". I'm looking for this answer, and the best I can find are half-answers from 2012.&lt;/P&gt;

&lt;P&gt;My guess is not many people are even paying attention to this. In our case, the expired certs are setting off alerts with other IDS/IPS sensors, so we want to address it. Even the &lt;EM&gt;/splunk help createssl&lt;/EM&gt; documentation sucks, including line formatting and spacing that's all jacked up -- signs that no one is actually putting any energy into improving this situation.&lt;/P&gt;

&lt;P&gt;Folks, when someone asks how to do something, as long as it's not completely in left-field, please answer it completely, or not at all. Assume defaults if information is omitted (avoid:  "well, you didn't say what O/S, or your server's name, or your blood-type..."). For example the "answer above" does not work, there are other parameters that are required, and yet, it's the "accepted answer". Gah! Also the link to RTFM that discusses certs in general terms, does NOT explain how to renew a cert. Gah! Don't try to up your "answer" count with links to docs that discuss the issue at 20,000 feet. It's a question, looking for an answer. Period. &lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 12:56:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55066#M1849</guid>
      <dc:creator>Michael</dc:creator>
      <dc:date>2015-10-23T12:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Expired SSL Cert?</title>
      <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55067#M1850</link>
      <description>&lt;P&gt;/opt/splunk/bin/splunk createssl server-cert -d /opt/splunk/etc/auth -n ${server_name} -c ${server_name}.fqdn&lt;BR /&gt;
Then cp ${server_name}.pem to server.pem&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55067#M1850</guid>
      <dc:creator>jd260</dc:creator>
      <dc:date>2020-09-29T12:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: Expired SSL Cert?</title>
      <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55068#M1851</link>
      <description>&lt;P&gt;Thanks.  This saved me a lot of time.  I swore I had it noted down somewhere, but alas..&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 20:33:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55068#M1851</guid>
      <dc:creator>edekker</dc:creator>
      <dc:date>2017-03-14T20:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Expired SSL Cert?</title>
      <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55069#M1852</link>
      <description>&lt;P&gt;I downvoted this post because this is not enough of an answer. according to the official docs of the cli command [./bin/splunk help createssl] there are 2 flags that are required to be filled in (-d for directory of cert and -n for the name)&lt;/P&gt;

&lt;P&gt;this answer does not also advise to backup your original cert or where to store it after you generate.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 12:53:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55069#M1852</guid>
      <dc:creator>mweissha</dc:creator>
      <dc:date>2017-05-12T12:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: Expired SSL Cert?</title>
      <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55070#M1853</link>
      <description>&lt;P&gt;This answer is far closer to an actually helpful response. This command, and looking at the help for splunk cli &lt;CODE&gt;./bin/splunk help createssl&lt;/CODE&gt;, was what eliminated my ssl errors. Thanks jd260!&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 12:56:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55070#M1853</guid>
      <dc:creator>mweissha</dc:creator>
      <dc:date>2017-05-12T12:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Expired SSL Cert?</title>
      <link>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55071#M1854</link>
      <description>&lt;P&gt;Thanks @jd260.   If I had found this answer this morning, it would have saved me hours of work.&lt;/P&gt;

&lt;P&gt;Why this isn't in the Splunk docs is a mystery.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 19:44:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Expired-SSL-Cert/m-p/55071#M1854</guid>
      <dc:creator>reswob4</dc:creator>
      <dc:date>2017-08-23T19:44:26Z</dc:date>
    </item>
  </channel>
</rss>

