<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Enterprise 8089 Vulnerability Scan Results: How do I resolve these SSL errors? in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287522#M7678</link>
    <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I'm required to scan my Splunk Enterprise environment for compliance reasons. When I'm scanning my search heads and indexers ,I keep getting multiple SSL errors for the management port 8089. I've searched and haven't found a way figure out a method to upload a third party cert to fix this or if this is something that I'll just have to make not isn't fixable. I've included some of the vulnerability issues I've found. Not sure if opening a ticket with support would get me the information I need. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;SSL Version 2 and 3 Protocol Detected&lt;/LI&gt;
&lt;LI&gt;SSL Cert Signed Using Weak Hashing Algorithm (SHA1)&lt;/LI&gt;
&lt;LI&gt;SSL Certificate Wrong Hostname (Splunk Self Signed Cert running on 8089)&lt;/LI&gt;
&lt;LI&gt;TLS CRIME Vulnerability&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jul 2016 16:25:53 GMT</pubDate>
    <dc:creator>serwin</dc:creator>
    <dc:date>2016-07-29T16:25:53Z</dc:date>
    <item>
      <title>Splunk Enterprise 8089 Vulnerability Scan Results: How do I resolve these SSL errors?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287522#M7678</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I'm required to scan my Splunk Enterprise environment for compliance reasons. When I'm scanning my search heads and indexers ,I keep getting multiple SSL errors for the management port 8089. I've searched and haven't found a way figure out a method to upload a third party cert to fix this or if this is something that I'll just have to make not isn't fixable. I've included some of the vulnerability issues I've found. Not sure if opening a ticket with support would get me the information I need. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;SSL Version 2 and 3 Protocol Detected&lt;/LI&gt;
&lt;LI&gt;SSL Cert Signed Using Weak Hashing Algorithm (SHA1)&lt;/LI&gt;
&lt;LI&gt;SSL Certificate Wrong Hostname (Splunk Self Signed Cert running on 8089)&lt;/LI&gt;
&lt;LI&gt;TLS CRIME Vulnerability&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 16:25:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287522#M7678</guid>
      <dc:creator>serwin</dc:creator>
      <dc:date>2016-07-29T16:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 8089 Vulnerability Scan Results: How do I resolve these SSL errors?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287523#M7679</link>
      <description>&lt;P&gt;What version of Splunk?&lt;/P&gt;

&lt;P&gt;If you 6.3+ you can have splunk use TLV1.2 cipherSuite OR upgrade Splunk to 6.4. Add that in your server.conf and everywhere else (inputs/outputs and web)  Hope this helps!&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Raghav&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 16:45:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287523#M7679</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2016-07-29T16:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 8089 Vulnerability Scan Results: How do I resolve these SSL errors?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287524#M7680</link>
      <description>&lt;P&gt;using splunk 6.4.1, you got a link handy and i'll read through that? &lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 16:47:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287524#M7680</guid>
      <dc:creator>serwin</dc:creator>
      <dc:date>2016-07-29T16:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 8089 Vulnerability Scan Results: How do I resolve these SSL errors?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287525#M7681</link>
      <description>&lt;P&gt;You sure they can't allow exclusions? Generally all servers must be scanned to pass security compliance but even so exceptions are usually made provided justification for enterprise systems&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 16:50:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287525#M7681</guid>
      <dc:creator>Jarohnimo</dc:creator>
      <dc:date>2016-07-29T16:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 8089 Vulnerability Scan Results: How do I resolve these SSL errors?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287526#M7682</link>
      <description>&lt;P&gt;Generally, yes I should be able to exclude if I need to but...  more than likely I'll need a reason why I'm leaving this enabled (yay compliance). Thanks for the suggestion though, that may be what has to happen. &lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 16:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287526#M7682</guid>
      <dc:creator>serwin</dc:creator>
      <dc:date>2016-07-29T16:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 8089 Vulnerability Scan Results: How do I resolve these SSL errors?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287527#M7683</link>
      <description>&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;SSL Version 2 and 3 Protocol Detected&lt;BR /&gt;
=&amp;gt; Disable SSLv2 and SSLv3, or specify tls1.2 &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/Security/SetyourSSLversion"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/Security/SetyourSSLversion&lt;/A&gt;&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;SSL Cert Signed Using Weak Hashing Algorithm (SHA1)
=&amp;gt; Avoid using Splunk default certificate, and create your own certificate with stronger signiture (sha2 type) asking trusted CA.
=&amp;gt; openssl has option such as -sha256. For more detail, pleaes consult  your trusted CA or google it regarding how to crate certificate with SHA256 or something like that! 
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/Security/Howtogetthird-partycertificates"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/Security/Howtogetthird-partycertificates&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;SSL Certificate Wrong Hostname (Splunk Self Signed Cert running on 8089)
=&amp;gt; You need to craete your own certificate and use proper HostName. Splunk default cert does not use server's host name &lt;/LI&gt;
&lt;LI&gt;TLS CRIME Vulnerability
&lt;A href="https://answers.splunk.com/answers/65218/splunk-shows-vulnerable-to-cve-2012-4929-in-my-nessus-vulnerability-scan-what-is-going-on.html"&gt;https://answers.splunk.com/answers/65218/splunk-shows-vulnerable-to-cve-2012-4929-in-my-nessus-vulnerability-scan-what-is-going-on.html&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 29 Jul 2016 19:49:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287527#M7683</guid>
      <dc:creator>Masa</dc:creator>
      <dc:date>2016-07-29T19:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 8089 Vulnerability Scan Results: How do I resolve these SSL errors?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287528#M7684</link>
      <description>&lt;P&gt;Awesome! &lt;/P&gt;

&lt;P&gt;That's what i was looking for!&lt;/P&gt;

&lt;P&gt;Quick question, for 1,2,3 do those fixes apply for stuff on the management port (8089)? &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 20:09:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287528#M7684</guid>
      <dc:creator>serwin</dc:creator>
      <dc:date>2016-07-29T20:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 8089 Vulnerability Scan Results: How do I resolve these SSL errors?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287529#M7685</link>
      <description>&lt;P&gt;Yes, all of them can apply to the Splunk management port (default is 8089)&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 23:44:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287529#M7685</guid>
      <dc:creator>Masa</dc:creator>
      <dc:date>2016-08-04T23:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 8089 Vulnerability Scan Results: How do I resolve these SSL errors?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287530#M7686</link>
      <description>&lt;P&gt;Thanks . This will be helpful &lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 05:42:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287530#M7686</guid>
      <dc:creator>syadavsplunk</dc:creator>
      <dc:date>2018-03-14T05:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 8089 Vulnerability Scan Results: How do I resolve these SSL errors?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287531#M7687</link>
      <description>&lt;P&gt;i am using 6.4..4 and by scaning we got issue on 8008 port as SHA 1 alert &lt;BR /&gt;
so how to make 8008 port (vmware DCN port) as secure?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 14:56:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/287531#M7687</guid>
      <dc:creator>splunk24</dc:creator>
      <dc:date>2018-06-07T14:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 8089 Vulnerability Scan Results: How do I resolve these SSL errors?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/519941#M11803</link>
      <description>&lt;P&gt;Is there a version of the Universal forwarder that isn't prone to this issue?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 14:39:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-How-do-I/m-p/519941#M11803</guid>
      <dc:creator>usenetim</dc:creator>
      <dc:date>2020-09-16T14:39:56Z</dc:date>
    </item>
  </channel>
</rss>

