<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Root CA password in Security</title>
    <link>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67806#M2229</link>
    <description>&lt;P&gt;okay same here and same for this guy &lt;A href="http://splunk-base.splunk.com/answers/28342/self-signed-cert-creation-issues-with-422"&gt;http://splunk-base.splunk.com/answers/28342/self-signed-cert-creation-issues-with-422&lt;/A&gt; maybe it's really a bug or we are doing it worng &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Sep 2011 06:52:22 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2011-09-01T06:52:22Z</dc:date>
    <item>
      <title>Root CA password</title>
      <link>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67801#M2224</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm testing how to create a new root CA to enable SSL authentication. It seems that the default script for this, genRootCA.sh doesn't set a password for the certificate by default, but I can change this behaviour with -p.&lt;/P&gt;

&lt;P&gt;However, when trying to generate server keys with 'splunk create-ssl server-cert', Splunk doesn't ask for the CA password and is consequently unable to load the CA private key. Is this expected behaviour or a bug? Is it somehow recommended not to protect the CA private key with a password?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2011 13:29:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67801#M2224</guid>
      <dc:creator>echalex</dc:creator>
      <dc:date>2011-08-31T13:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Root CA password</title>
      <link>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67802#M2225</link>
      <description>&lt;P&gt;Hi echalex&lt;/P&gt;

&lt;P&gt;your command &lt;EM&gt;&lt;CODE&gt;splunk create-ssl server-cert&lt;/CODE&gt;&lt;/EM&gt; gives me an error:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Command error: 'create-ssl' is not a valid command.  Please run 'splunk help' to&lt;BR /&gt;
 see the valid commands.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;but you can find &lt;A href="http://splunk-base.splunk.com/answers/7164/how-do-i-set-up-ssl-forwarding-with-new-self-signed-certificates-and-authentication"&gt;here&lt;/A&gt; a perfect instruction from hexx on how to create a CA with splunk, hope this helps.&lt;/P&gt;

&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2011 13:56:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67802#M2225</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2011-08-31T13:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: Root CA password</title>
      <link>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67803#M2226</link>
      <description>&lt;P&gt;Thanks, MuS.&lt;/P&gt;

&lt;P&gt;Are you using 4.2.3? I am. (Misspelled the command. It's actually createssl, without the hyphen.):  &lt;/P&gt;

&lt;P&gt;splunk@srv:/opt/splunk$ bin/genSignedServerCert.sh -d /tmp/ -n test&lt;BR /&gt;&lt;BR /&gt;
++python bin/genSignedServerCert.py -d /tmp/ -n test&lt;BR /&gt;&lt;BR /&gt;
NOTE: This script is deprecated.  Instead, use "splunk createssl server-cert".&lt;BR /&gt;&lt;BR /&gt;
...&lt;SNIP&gt;&lt;/SNIP&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2011 15:59:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67803#M2226</guid>
      <dc:creator>echalex</dc:creator>
      <dc:date>2011-08-31T15:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Root CA password</title>
      <link>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67804#M2227</link>
      <description>&lt;P&gt;The link you sent doesn't mention anything about CA password, which is my main issue, really.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2011 16:49:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67804#M2227</guid>
      <dc:creator>echalex</dc:creator>
      <dc:date>2011-08-31T16:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Root CA password</title>
      <link>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67805#M2228</link>
      <description>&lt;P&gt;Yes, using 4.2.3 as well and many other releases &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; I will try it tomorrow and see what will happen. cheers&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2011 18:16:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67805#M2228</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2011-08-31T18:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Root CA password</title>
      <link>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67806#M2229</link>
      <description>&lt;P&gt;okay same here and same for this guy &lt;A href="http://splunk-base.splunk.com/answers/28342/self-signed-cert-creation-issues-with-422"&gt;http://splunk-base.splunk.com/answers/28342/self-signed-cert-creation-issues-with-422&lt;/A&gt; maybe it's really a bug or we are doing it worng &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2011 06:52:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67806#M2229</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2011-09-01T06:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: Root CA password</title>
      <link>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67807#M2230</link>
      <description>&lt;P&gt;MuS, I have hard time believing we're all doing it wrong. Sadly, the createssl command isn't well documented at all.&lt;BR /&gt;
The solution I came to was to disregard the helper scripts and just use the CA.pl-script that is included in $SPLUNK_HOME/openssl/misc. I believe it's a standard part of any openssl distribution.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2011 07:42:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67807#M2230</guid>
      <dc:creator>echalex</dc:creator>
      <dc:date>2011-09-02T07:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Root CA password</title>
      <link>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67808#M2231</link>
      <description>&lt;P&gt;echalex, have you filed a bug report for that?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2011 11:57:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67808#M2231</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2011-09-02T11:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: Root CA password</title>
      <link>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67809#M2232</link>
      <description>&lt;P&gt;MuS, a little late to answer. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Nope, I haven't. I'm not sure if it's a bug, since I get the feeling the script isn't meant  to be used for creating more advanced CAs.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2012 14:47:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67809#M2232</guid>
      <dc:creator>echalex</dc:creator>
      <dc:date>2012-08-06T14:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: Root CA password</title>
      <link>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67810#M2233</link>
      <description>&lt;P&gt;Answering my own question: the &lt;CODE&gt;genRootCA.sh&lt;/CODE&gt; script doesn't seem to be created for the purpose of creating more advanced CAs. If you really want to, you can edit the script and change the values of &lt;CODE&gt;-passin&lt;/CODE&gt; and &lt;CODE&gt;-passout&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;For more generic usage, use your organization's root CA or use OpenSSL to create a new root CA to use with Splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2012 14:53:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Root-CA-password/m-p/67810#M2233</guid>
      <dc:creator>echalex</dc:creator>
      <dc:date>2012-08-06T14:53:32Z</dc:date>
    </item>
  </channel>
</rss>

