<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexer/forwarder SSL communication / sslVerifyServerCert question in Security</title>
    <link>https://community.splunk.com/t5/Security/Indexer-forwarder-SSL-communication-sslVerifyServerCert-question/m-p/273012#M7364</link>
    <description>&lt;P&gt;Yeah that should be fine as far as I know.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Sep 2016 10:53:11 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2016-09-09T10:53:11Z</dc:date>
    <item>
      <title>Indexer/forwarder SSL communication / sslVerifyServerCert question</title>
      <link>https://community.splunk.com/t5/Security/Indexer-forwarder-SSL-communication-sslVerifyServerCert-question/m-p/273011#M7363</link>
      <description>&lt;P&gt;Hello, is it possible that Splunkforwarder still works if the cacert.pem on the indexer is expired and from different certificate authority? We have sslVerifyServerCert = false set on the fwd.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2016 10:00:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-forwarder-SSL-communication-sslVerifyServerCert-question/m-p/273011#M7363</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2016-09-09T10:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer/forwarder SSL communication / sslVerifyServerCert question</title>
      <link>https://community.splunk.com/t5/Security/Indexer-forwarder-SSL-communication-sslVerifyServerCert-question/m-p/273012#M7364</link>
      <description>&lt;P&gt;Yeah that should be fine as far as I know.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2016 10:53:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-forwarder-SSL-communication-sslVerifyServerCert-question/m-p/273012#M7364</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-09-09T10:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer/forwarder SSL communication / sslVerifyServerCert question</title>
      <link>https://community.splunk.com/t5/Security/Indexer-forwarder-SSL-communication-sslVerifyServerCert-question/m-p/273013#M7365</link>
      <description>&lt;P&gt;it is additional step for authenticating your splunk indexers. For example- If it FALSE, setup an indexer, add and define common certificate and configure to forward the event, it will start ingesting. In this case, certificates, verify, whether it is forwarding events/logs to correct indexers only, but based on certificates&lt;/P&gt;

&lt;P&gt;You need to have two more configs need to be added in case, you want it to work,&lt;/P&gt;

&lt;P&gt;output.conf, (splunk forwarder - DS client)&lt;BR /&gt;
sslCommonNameToCheck= server.common.name.com.fqdn&lt;/P&gt;

&lt;P&gt;between server to server&lt;BR /&gt;
sslCommonNameList = splunk.servers.names.with.comma.for.all.making.communication, server1.com, server2.com&lt;/P&gt;

&lt;P&gt;Always configure these config in last, as any communication break, can be rolled back, as this would be only check.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 14:49:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-forwarder-SSL-communication-sslVerifyServerCert-question/m-p/273013#M7365</guid>
      <dc:creator>anand_singh17</dc:creator>
      <dc:date>2017-05-25T14:49:59Z</dc:date>
    </item>
  </channel>
</rss>

