<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Puppetizing Splunk for SSL-enabled Light Forwarding in Security</title>
    <link>https://community.splunk.com/t5/Security/Puppetizing-Splunk-for-SSL-enabled-Light-Forwarding/m-p/72413#M2381</link>
    <description>&lt;P&gt;I've seen &lt;A href="http://answers.splunk.com/questions/345/does-splunk-play-nice-with-puppet" rel="nofollow"&gt;http://answers.splunk.com/questions/345/does-splunk-play-nice-with-puppet&lt;/A&gt; and there is a Puppet manifest in the answer but the manifest doesn't address some of the entries in it.&lt;/P&gt;

&lt;P&gt;The question is: What is the purpose of the files in $SPLUNK_HOME/etc/auth? Many of them are explained by &lt;A href="http://www.splunk.com/base/Documentation/latest/admin/Secureaccesstoyoursplunkserverwithssl" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/admin/Secureaccesstoyoursplunkserverwithssl&lt;/A&gt; but some are still not explained.&lt;/P&gt;

&lt;P&gt;On a new Splunk 4.1.5 installation that was turned into a light forwarder I have these files in $SPLUNK_HOME/etc/auth&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;.:
total 36
drwx--x--x 2 root   root   4096 Oct 14 14:18 audit
-r--r--r-- 1 splunk splunk  912 Sep  4 05:53 cacert.pem
-r--r--r-- 1 splunk splunk 1875 Sep  4 05:53 ca.pem
-rw------- 1 root   root     17 Oct 14 14:30 ca.srl
drwx--x--x 2 root   root   4096 Oct 14 14:18 distServerKeys
-rw------- 1 root   root    951 Oct 14 14:30 privkeySecure.pem
-rw------- 1 root   root    595 Oct 14 14:30 req.pem
-rw------- 1 root   root   2689 Oct 14 14:30 server.pem
-r-------- 1 root   root    255 Oct 14 14:30 splunk.secret

./audit:
total 8
-rw------- 1 root root 887 Oct 14 14:18 private.pem
-rw------- 1 root root 272 Oct 14 14:18 public.pem

./distServerKeys:
total 8
-rw------- 1 root root 887 Oct 14 14:18 private.pem
-rw------- 1 root root 272 Oct 14 14:18 trusted.pem
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What is the function of each file listed and which of them can (and should) be omitted from a forwarder?&lt;/P&gt;</description>
    <pubDate>Tue, 19 Oct 2010 02:34:25 GMT</pubDate>
    <dc:creator>lisa_1</dc:creator>
    <dc:date>2010-10-19T02:34:25Z</dc:date>
    <item>
      <title>Puppetizing Splunk for SSL-enabled Light Forwarding</title>
      <link>https://community.splunk.com/t5/Security/Puppetizing-Splunk-for-SSL-enabled-Light-Forwarding/m-p/72413#M2381</link>
      <description>&lt;P&gt;I've seen &lt;A href="http://answers.splunk.com/questions/345/does-splunk-play-nice-with-puppet" rel="nofollow"&gt;http://answers.splunk.com/questions/345/does-splunk-play-nice-with-puppet&lt;/A&gt; and there is a Puppet manifest in the answer but the manifest doesn't address some of the entries in it.&lt;/P&gt;

&lt;P&gt;The question is: What is the purpose of the files in $SPLUNK_HOME/etc/auth? Many of them are explained by &lt;A href="http://www.splunk.com/base/Documentation/latest/admin/Secureaccesstoyoursplunkserverwithssl" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/admin/Secureaccesstoyoursplunkserverwithssl&lt;/A&gt; but some are still not explained.&lt;/P&gt;

&lt;P&gt;On a new Splunk 4.1.5 installation that was turned into a light forwarder I have these files in $SPLUNK_HOME/etc/auth&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;.:
total 36
drwx--x--x 2 root   root   4096 Oct 14 14:18 audit
-r--r--r-- 1 splunk splunk  912 Sep  4 05:53 cacert.pem
-r--r--r-- 1 splunk splunk 1875 Sep  4 05:53 ca.pem
-rw------- 1 root   root     17 Oct 14 14:30 ca.srl
drwx--x--x 2 root   root   4096 Oct 14 14:18 distServerKeys
-rw------- 1 root   root    951 Oct 14 14:30 privkeySecure.pem
-rw------- 1 root   root    595 Oct 14 14:30 req.pem
-rw------- 1 root   root   2689 Oct 14 14:30 server.pem
-r-------- 1 root   root    255 Oct 14 14:30 splunk.secret

./audit:
total 8
-rw------- 1 root root 887 Oct 14 14:18 private.pem
-rw------- 1 root root 272 Oct 14 14:18 public.pem

./distServerKeys:
total 8
-rw------- 1 root root 887 Oct 14 14:18 private.pem
-rw------- 1 root root 272 Oct 14 14:18 trusted.pem
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What is the function of each file listed and which of them can (and should) be omitted from a forwarder?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2010 02:34:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Puppetizing-Splunk-for-SSL-enabled-Light-Forwarding/m-p/72413#M2381</guid>
      <dc:creator>lisa_1</dc:creator>
      <dc:date>2010-10-19T02:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: Puppetizing Splunk for SSL-enabled Light Forwarding</title>
      <link>https://community.splunk.com/t5/Security/Puppetizing-Splunk-for-SSL-enabled-Light-Forwarding/m-p/72414#M2382</link>
      <description>&lt;P&gt;You should synchronize the whole auth directory for consistency.   Those files are their for the ssl communication and password configuration.  As the other Splunk Answers question and answer states, you should also sync the etc/system/local/server.conf and the etc/passwd file.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2010 02:39:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Puppetizing-Splunk-for-SSL-enabled-Light-Forwarding/m-p/72414#M2382</guid>
      <dc:creator>Simeon</dc:creator>
      <dc:date>2010-10-19T02:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Puppetizing Splunk for SSL-enabled Light Forwarding</title>
      <link>https://community.splunk.com/t5/Security/Puppetizing-Splunk-for-SSL-enabled-Light-Forwarding/m-p/72415#M2383</link>
      <description>&lt;P&gt;I've come up with a Puppet class to do just this: &lt;A href="https://github.com/TransGaming/puppet/tree/master/splunk" rel="nofollow"&gt;https://github.com/TransGaming/puppet/tree/master/splunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2010 22:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Puppetizing-Splunk-for-SSL-enabled-Light-Forwarding/m-p/72415#M2383</guid>
      <dc:creator>lisa_1</dc:creator>
      <dc:date>2010-11-25T22:53:04Z</dc:date>
    </item>
  </channel>
</rss>

