<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned in Security</title>
    <link>https://community.splunk.com/t5/Security/SSL-routines-SSL3-GET-CLIENT-CERTIFICATE-no-certificate-returned/m-p/19061#M622</link>
    <description>&lt;P&gt;Trying to configure SplunkLightForwarder with SSL for both encryption and mutual authentication, but no connection is made. On the receiver the connection is failing with the error message:
ERROR TcpInputProc - Error encountered for connection from host=10.2.3.4, ip=10.2.3.4. error:140890B2:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned&lt;/P&gt;

&lt;P&gt;On the sender side:
sslCertPath=$SPLUNK_HOME/etc/auth/cert/sender.pem
sslPassword=password
sslRootCAPath=$SPLUNK_HOME/etc/auth/cert/root.crt
sslVerifyServerCert=true
sslCommonNameToCheck=receiver.example.com&lt;/P&gt;

&lt;P&gt;On the receiver side:
[splunktcp-ssl://12345]
disabled = false
[SSL]
serverCert=$SPLUNK_HOME/etc/auth/cert/reciever.pem
password=password
RootCA=$SPLUNK_HOME/etc/auth/cert/root.crt
dhfile=$SPLUNK_HOME/etc/auth/cert/dhparams.pem
requireClientCert=true&lt;/P&gt;

&lt;P&gt;Thoughts anyone???&lt;/P&gt;</description>
    <pubDate>Thu, 30 Dec 2010 05:15:26 GMT</pubDate>
    <dc:creator>castle1126</dc:creator>
    <dc:date>2010-12-30T05:15:26Z</dc:date>
    <item>
      <title>SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned</title>
      <link>https://community.splunk.com/t5/Security/SSL-routines-SSL3-GET-CLIENT-CERTIFICATE-no-certificate-returned/m-p/19061#M622</link>
      <description>&lt;P&gt;Trying to configure SplunkLightForwarder with SSL for both encryption and mutual authentication, but no connection is made. On the receiver the connection is failing with the error message:
ERROR TcpInputProc - Error encountered for connection from host=10.2.3.4, ip=10.2.3.4. error:140890B2:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned&lt;/P&gt;

&lt;P&gt;On the sender side:
sslCertPath=$SPLUNK_HOME/etc/auth/cert/sender.pem
sslPassword=password
sslRootCAPath=$SPLUNK_HOME/etc/auth/cert/root.crt
sslVerifyServerCert=true
sslCommonNameToCheck=receiver.example.com&lt;/P&gt;

&lt;P&gt;On the receiver side:
[splunktcp-ssl://12345]
disabled = false
[SSL]
serverCert=$SPLUNK_HOME/etc/auth/cert/reciever.pem
password=password
RootCA=$SPLUNK_HOME/etc/auth/cert/root.crt
dhfile=$SPLUNK_HOME/etc/auth/cert/dhparams.pem
requireClientCert=true&lt;/P&gt;

&lt;P&gt;Thoughts anyone???&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2010 05:15:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/SSL-routines-SSL3-GET-CLIENT-CERTIFICATE-no-certificate-returned/m-p/19061#M622</guid>
      <dc:creator>castle1126</dc:creator>
      <dc:date>2010-12-30T05:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned</title>
      <link>https://community.splunk.com/t5/Security/SSL-routines-SSL3-GET-CLIENT-CERTIFICATE-no-certificate-returned/m-p/19062#M623</link>
      <description>&lt;P&gt;Does it work if you specify the default splunk cacert.pem and server.pem?  If so, this would indicate a problem with your custom root cert and/or server cert.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2010 08:39:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/SSL-routines-SSL3-GET-CLIENT-CERTIFICATE-no-certificate-returned/m-p/19062#M623</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2010-12-30T08:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned</title>
      <link>https://community.splunk.com/t5/Security/SSL-routines-SSL3-GET-CLIENT-CERTIFICATE-no-certificate-returned/m-p/19063#M624</link>
      <description>&lt;P&gt;No I haven't tried with the Splunk PEMs created during install.  These are certs built against our PKI infrastructure here, and check out as valid and correct within our environment.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2010 01:45:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/SSL-routines-SSL3-GET-CLIENT-CERTIFICATE-no-certificate-returned/m-p/19063#M624</guid>
      <dc:creator>castle1126</dc:creator>
      <dc:date>2010-12-31T01:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned</title>
      <link>https://community.splunk.com/t5/Security/SSL-routines-SSL3-GET-CLIENT-CERTIFICATE-no-certificate-returned/m-p/19064#M625</link>
      <description>&lt;P&gt;I would suggest a review of the procedure detailed in &lt;A href="http://www.splunk.com/wiki/Community:Splunk2Splunk_SSL_3rdPartyCA"&gt;this tutorial &lt;/A&gt; to set up splunk-2-splunk communication using SSL certificates signed by a 3rd party certificate authority.&lt;/P&gt;

&lt;P&gt;The troubleshooting section might help you to pinpoint where the issue with your current configuration is.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2012 22:12:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/SSL-routines-SSL3-GET-CLIENT-CERTIFICATE-no-certificate-returned/m-p/19064#M625</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2012-01-26T22:12:10Z</dc:date>
    </item>
  </channel>
</rss>

