<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using apache ssl reverse proxy in front of splunk web 6.2.1? in Security</title>
    <link>https://community.splunk.com/t5/Security/Using-apache-ssl-reverse-proxy-in-front-of-splunk-web-6-2-1/m-p/151626#M4619</link>
    <description>&lt;P&gt;This is working for me (enable SSL for splunk and use ProxyPass with https):&lt;/P&gt;

&lt;P&gt;Apache Config (using https):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ProxyPass           &lt;A href="https://123.123.123.123:8000/splunk" target="test_blank"&gt;https://123.123.123.123:8000/splunk&lt;/A&gt; retry=60 timeout=300 ttl=600 flushwait=600
ProxyPassReverse    &lt;A href="https://123.123.123.123:8000/splunk" target="test_blank"&gt;https://123.123.123.123:8000/splunk&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunks web.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;enableSplunkWebSSL = 1

privKeyPath = etc/auth/splunkweb/privkey.pem
caCertPath = etc/auth/splunkweb/cert.pem

supportSSLV3Only = False
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'd rather not have to encrypt/decrypt everything twice but at least it works..&lt;/P&gt;</description>
    <pubDate>Sat, 10 Oct 2015 19:14:38 GMT</pubDate>
    <dc:creator>phwinkler</dc:creator>
    <dc:date>2015-10-10T19:14:38Z</dc:date>
    <item>
      <title>Using apache ssl reverse proxy in front of splunk web 6.2.1?</title>
      <link>https://community.splunk.com/t5/Security/Using-apache-ssl-reverse-proxy-in-front-of-splunk-web-6-2-1/m-p/151624#M4617</link>
      <description>&lt;P&gt;So I have a config where I have a few web services running on the same machine, and I use httpd listening on 443 to distribute the requests.  Httpd handles the SSL connection to/from the client, and uses regular http to talk to the locally-running services over lo.&lt;/P&gt;

&lt;P&gt;I've also read every post I can find on this issue, and none of them have helped fix this.&lt;/P&gt;

&lt;P&gt;Specifically, when I hit a splunk URL that generates a redirect, splunk attempts to redirect the browser using a document.location statement in the page itself: &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;document.location = "&lt;A href="http://myserver.xyz/splunk/en-US/"&gt;http://myserver.xyz/splunk/en-US/&lt;/A&gt;" + hashTag;\n&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;where "myserver.xyz" is actually the correct FQDN.  This fails b/c nothing is listening for http externally.&lt;/P&gt;

&lt;P&gt;If I hit a splunk URL that doesn't generate a redirect, I get the page I was expecting.&lt;/P&gt;

&lt;P&gt;Based on what I've read, here's my web.conf for splunk:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[settings]&lt;BR /&gt;
enableSplunkWebSSL = 0&lt;BR /&gt;
httpport = 8800&lt;BR /&gt;
root_endpoint = /splunk&lt;BR /&gt;
tools.proxy.base = &lt;A href="https://myserver.xyz"&gt;https://myserver.xyz&lt;/A&gt;&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;And my httpd config:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;SSLProxyEngine On&lt;BR /&gt;
ProxyRequests Off&lt;BR /&gt;
ProxyPreserveHost On&lt;BR /&gt;
ProxyPass /splunk &lt;A href="http://internal:8800/splunk"&gt;http://internal:8800/splunk&lt;/A&gt;&lt;BR /&gt;
ProxyPassReverse /splunk &lt;A href="http://internal:8800/splunk"&gt;http://internal:8800/splunk&lt;/A&gt;&lt;BR /&gt;
Location /splunk&amp;gt;&lt;BR /&gt;
  Order allow,deny&lt;BR /&gt;
  Allow from all&lt;BR /&gt;
/Location&amp;gt;&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;where "internal" is the local machine hostname; and the Location block uses proper syntax (wikimarkup is breaking the opening '&amp;lt;' along with the newlines; the preview works fine, so what is that about?!?).&lt;/P&gt;

&lt;P&gt;Based on everything I've read, this should work.  So why does splunk still issue redirects back to the http:// URL?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Feb 2015 23:24:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Using-apache-ssl-reverse-proxy-in-front-of-splunk-web-6-2-1/m-p/151624#M4617</guid>
      <dc:creator>huntd</dc:creator>
      <dc:date>2015-02-25T23:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: Using apache ssl reverse proxy in front of splunk web 6.2.1?</title>
      <link>https://community.splunk.com/t5/Security/Using-apache-ssl-reverse-proxy-in-front-of-splunk-web-6-2-1/m-p/151625#M4618</link>
      <description>&lt;P&gt;I have the same problem here. Did you find how to make it work? Does anybody have an answer?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 15:36:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Using-apache-ssl-reverse-proxy-in-front-of-splunk-web-6-2-1/m-p/151625#M4618</guid>
      <dc:creator>pduflot</dc:creator>
      <dc:date>2015-07-02T15:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: Using apache ssl reverse proxy in front of splunk web 6.2.1?</title>
      <link>https://community.splunk.com/t5/Security/Using-apache-ssl-reverse-proxy-in-front-of-splunk-web-6-2-1/m-p/151626#M4619</link>
      <description>&lt;P&gt;This is working for me (enable SSL for splunk and use ProxyPass with https):&lt;/P&gt;

&lt;P&gt;Apache Config (using https):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ProxyPass           &lt;A href="https://123.123.123.123:8000/splunk" target="test_blank"&gt;https://123.123.123.123:8000/splunk&lt;/A&gt; retry=60 timeout=300 ttl=600 flushwait=600
ProxyPassReverse    &lt;A href="https://123.123.123.123:8000/splunk" target="test_blank"&gt;https://123.123.123.123:8000/splunk&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunks web.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;enableSplunkWebSSL = 1

privKeyPath = etc/auth/splunkweb/privkey.pem
caCertPath = etc/auth/splunkweb/cert.pem

supportSSLV3Only = False
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'd rather not have to encrypt/decrypt everything twice but at least it works..&lt;/P&gt;</description>
      <pubDate>Sat, 10 Oct 2015 19:14:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Using-apache-ssl-reverse-proxy-in-front-of-splunk-web-6-2-1/m-p/151626#M4619</guid>
      <dc:creator>phwinkler</dc:creator>
      <dc:date>2015-10-10T19:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Using apache ssl reverse proxy in front of splunk web 6.2.1?</title>
      <link>https://community.splunk.com/t5/Security/Using-apache-ssl-reverse-proxy-in-front-of-splunk-web-6-2-1/m-p/151627#M4620</link>
      <description>&lt;P&gt;Worked fine to me!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2016 20:06:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Using-apache-ssl-reverse-proxy-in-front-of-splunk-web-6-2-1/m-p/151627#M4620</guid>
      <dc:creator>rafamss</dc:creator>
      <dc:date>2016-07-22T20:06:19Z</dc:date>
    </item>
  </channel>
</rss>

