<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexer cluster SSL migration from default SSL to self-signed with least downtime? in Security</title>
    <link>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288733#M7711</link>
    <description>&lt;P&gt;SSL certificates migration process is not documented at all. also i am not seeing &lt;STRONG&gt;any&lt;/STRONG&gt; posts related to this topic. Wondering how !!!&lt;/P&gt;</description>
    <pubDate>Fri, 25 Aug 2017 07:14:28 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2017-08-25T07:14:28Z</dc:date>
    <item>
      <title>Indexer cluster SSL migration from default SSL to self-signed with least downtime?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288732#M7710</link>
      <description>&lt;P&gt;Hi, &lt;BR /&gt;
1. Lets assume I have around 4 cluster peers with Splunk's default SSL. To migrate from Splunk's default SSL to self-signed SSL, &lt;BR /&gt;
can I migrate the cluster peers one by one? I mean, on an indexer cluster, can I have two sets of SSL certificates (Splunk's default SSL and my own self-signed SSL)?&lt;BR /&gt;
2. During the migration, the deployment server should be sending the new self-signed SSL certificates to forwarders. Is this possible? &lt;BR /&gt;
I mean, one deployment server, handling two sets of SSL certificates. &lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 04:09:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288732#M7710</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-08-24T04:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer cluster SSL migration from default SSL to self-signed with least downtime?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288733#M7711</link>
      <description>&lt;P&gt;SSL certificates migration process is not documented at all. also i am not seeing &lt;STRONG&gt;any&lt;/STRONG&gt; posts related to this topic. Wondering how !!!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 07:14:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288733#M7711</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-08-25T07:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer cluster SSL migration from default SSL to self-signed with least downtime?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288734#M7712</link>
      <description>&lt;P&gt;Theres no documented process for this, but thinking about a few different scenarios here, here's what I see as working without downtime..&lt;/P&gt;

&lt;P&gt;General Outline--&lt;BR /&gt;
1) Add a new &lt;STRONG&gt;splunktcp-ssl&lt;/STRONG&gt; input on your indexers, via the cluster master, on a different port then your current port. E.g. 9998 instead of 9997. This should require a rolling restart to enable the config&lt;BR /&gt;
2) Create a new app that has the new certs and outputs.conf to point to the splunktcp-ssl on 9998 on your indexer cluster&lt;BR /&gt;
3) Use the DS to deploy this to clients, and remove the other outputs.conf&lt;/P&gt;

&lt;P&gt;As clean up, you can validate that all of your clients are sending to the splunktcp-ssl input on your indexers. Once validated, you can disabled the the non-SSL port on the cluster, and copy the splunktcp-ssl config to 9997 with the same cert. You can then update the primary outputs.conf app on your DS and your clients will get updated and send to 9997.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 08:09:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288734#M7712</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2017-08-25T08:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer cluster SSL migration from default SSL to self-signed with least downtime?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288735#M7713</link>
      <description>&lt;P&gt;Thanks Esix,.. any ideas and suggestions about without using the 2nd port?&lt;BR /&gt;
on a indexer cluster, all cluster peers should have the SSL certificate(s) from same root CA, right&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 08:37:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288735#M7713</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-08-25T08:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer cluster SSL migration from default SSL to self-signed with least downtime?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288736#M7714</link>
      <description>&lt;P&gt;Hi All, any ideas and suggestions about without using the 2nd port please.. as you know, on production systems it would be difficult to get 2nd port opened for this task alone.. &lt;BR /&gt;
any other ideas, suggestions please.. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 11:18:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288736#M7714</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-08-29T11:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer cluster SSL migration from default SSL to self-signed with least downtime?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288737#M7715</link>
      <description>&lt;P&gt;Hi Esix/All, &lt;/P&gt;

&lt;P&gt;on an indexer cluster, can I have two sets of SSL certificates (Splunk's default SSL and my own self-signed SSL)?&lt;BR /&gt;
lets assume i have an indexer cluster with 10 indexers. can i have 8 indexers with Splunk default SSL certificates and 2 indexers with my own self signed certificates? is that possible, please suggest. &lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 12:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288737#M7715</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-11-02T12:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer cluster SSL migration from default SSL to self-signed with least downtime?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288738#M7716</link>
      <description>&lt;P&gt;Do you want to use SSL certificates for encrypting communication between forwarder and indexer or you are referring to changing SSL certificates for Management port ?&lt;/P&gt;

&lt;P&gt;With Splunk 6.3 and above it uses same certificates for all the nodes within indexer cluster including master node. &lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 12:32:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288738#M7716</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2017-11-02T12:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer cluster SSL migration from default SSL to self-signed with least downtime?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288739#M7717</link>
      <description>&lt;P&gt;we want to use SSL certificates for encrypting communication between forwarder and indexer &lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 12:38:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-cluster-SSL-migration-from-default-SSL-to-self-signed/m-p/288739#M7717</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-11-02T12:38:44Z</dc:date>
    </item>
  </channel>
</rss>

