<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk 6.3 forwarder is not sending data using SSL however Splunk 6.6 is working fine with the same settings in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-6-3-forwarder-is-not-sending-data-using-SSL-however/m-p/373594#M9223</link>
    <description>&lt;P&gt;Check your underlying cert on 6.3.  Believe this default expired last year.  You'll want 6.4 or higher if using default cert.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Aug 2017 13:38:10 GMT</pubDate>
    <dc:creator>n028167</dc:creator>
    <dc:date>2017-08-18T13:38:10Z</dc:date>
    <item>
      <title>Splunk 6.3 forwarder is not sending data using SSL however Splunk 6.6 is working fine with the same settings</title>
      <link>https://community.splunk.com/t5/Security/Splunk-6-3-forwarder-is-not-sending-data-using-SSL-however/m-p/373593#M9222</link>
      <description>&lt;P&gt;Splunk 6.3 forwarder is not sending data using SSL while Splunk 6.6 is working fine with the same settings. &lt;/P&gt;

&lt;P&gt;Following entries are added in outputs.conf on forwarder:&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup =Splunk_Indexers&lt;/P&gt;

&lt;P&gt;[tcpout:Splunk_Indexers]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
server = servername:9997&lt;BR /&gt;
compressed = false&lt;BR /&gt;
sslRootCAPath = "splunk-home"\etc\auth\NewAuth\CARoot.crt&lt;BR /&gt;
sslCertPath = "splunk-home"\etc\auth\NewAuth\servercert.pem&lt;/P&gt;

&lt;P&gt;Following entries are added in inputs.conf on indexer:&lt;BR /&gt;
[splunktcp-ssl://9997]&lt;BR /&gt;
connection_host = ip&lt;/P&gt;

&lt;P&gt;[SSL]&lt;BR /&gt;
compressed = false&lt;BR /&gt;
password = $5SD$==&lt;BR /&gt;
requireClientCert = false&lt;BR /&gt;
rootCA = "splunk-home"\etc\auth\NewAuth\CARoot.crt&lt;BR /&gt;
serverCert = "splunk-home"\etc\auth\NewAuth\servercert.pem&lt;/P&gt;

&lt;P&gt;Can please help to fix this issue as the above settings are working fine in Splunk 6.6 forwarder but giving following error in splunkd.log on Splunk 6.3 forwarder:&lt;BR /&gt;
"Connection to host=servername:9997 failed. sock_error = 0. SSL Error = error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed"&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-6-3-forwarder-is-not-sending-data-using-SSL-however/m-p/373593#M9222</guid>
      <dc:creator>reach2tushar</dc:creator>
      <dc:date>2020-09-29T15:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6.3 forwarder is not sending data using SSL however Splunk 6.6 is working fine with the same settings</title>
      <link>https://community.splunk.com/t5/Security/Splunk-6-3-forwarder-is-not-sending-data-using-SSL-however/m-p/373594#M9223</link>
      <description>&lt;P&gt;Check your underlying cert on 6.3.  Believe this default expired last year.  You'll want 6.4 or higher if using default cert.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2017 13:38:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-6-3-forwarder-is-not-sending-data-using-SSL-however/m-p/373594#M9223</guid>
      <dc:creator>n028167</dc:creator>
      <dc:date>2017-08-18T13:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6.3 forwarder is not sending data using SSL however Splunk 6.6 is working fine with the same settings</title>
      <link>https://community.splunk.com/t5/Security/Splunk-6-3-forwarder-is-not-sending-data-using-SSL-however/m-p/373595#M9224</link>
      <description>&lt;P&gt;Hi, We are using our own CA certificates in both 6.3 and 6.6. Could you please suggest?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 07:00:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-6-3-forwarder-is-not-sending-data-using-SSL-however/m-p/373595#M9224</guid>
      <dc:creator>reach2tushar</dc:creator>
      <dc:date>2017-08-21T07:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6.3 forwarder is not sending data using SSL however Splunk 6.6 is working fine with the same settings</title>
      <link>https://community.splunk.com/t5/Security/Splunk-6-3-forwarder-is-not-sending-data-using-SSL-however/m-p/373596#M9225</link>
      <description>&lt;P&gt;I'm seeing the same problems. Likely due to cipher issues with certain ciphers being deprecated.&lt;/P&gt;

&lt;P&gt;Even the if mentioned here for 6.0 and 6.1 does not help.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.3/ReleaseNotes/KnownIssues#Data_input_issues"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.3/ReleaseNotes/KnownIssues#Data_input_issues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 01:31:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-6-3-forwarder-is-not-sending-data-using-SSL-however/m-p/373596#M9225</guid>
      <dc:creator>cameronjust</dc:creator>
      <dc:date>2017-10-03T01:31:47Z</dc:date>
    </item>
  </channel>
</rss>

