<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk AppDynamics HTTP Error 400 Invalid SNI in Splunk AppDynamics</title>
    <link>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/754571#M11980</link>
    <description>&lt;P&gt;Recently I have created a community article regarding the SNI checks for each of the components in AppDynamics product - Controller, ES and EUM server. Please feel free to check it out, I have described exactly how SNI checks work, how to fix this issue permanently, and how to disable the SNI checks for each of the component of AppD:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/AppDynamics-Knowledge-Base/AppDynamics-Platform-Best-Practices-and-Guidance-for-SNI-Checks/ta-p/753919" target="_blank"&gt;https://community.splunk.com/t5/AppDynamics-Knowledge-Base/AppDynamics-Platform-Best-Practices-and-Guidance-for-SNI-Checks/ta-p/753919&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Oct 2025 13:00:00 GMT</pubDate>
    <dc:creator>Maciej_Popek</dc:creator>
    <dc:date>2025-10-22T13:00:00Z</dc:date>
    <item>
      <title>Splunk AppDynamics HTTP Error 400 Invalid SNI</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/741439#M11811</link>
      <description>&lt;P&gt;I am deploying an On-Premises AppDynamics demo for a customer version (25.1.1.10031) and it is running on HTTP (8090). However, when I try to open it &lt;A target="_self"&gt;https://&amp;lt;ip_addr&amp;gt;:8181&lt;/A&gt;, I get the attached error message.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SNI" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38098i71BB2A245EEFB08D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-03-11 at 20-27-22 Error 400 Invalid SNI.png" alt="SNI" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;SNI&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;The screenshot has appd not the IP address just to hide it&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;How do I bypass this error?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 19:54:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/741439#M11811</guid>
      <dc:creator>Osama_Abbas1</dc:creator>
      <dc:date>2025-03-14T19:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: AppDynamics HTTP Error 400 Invalid SNI</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/741465#M11813</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/293023"&gt;@Osama_Abbas1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you configured a&amp;nbsp;&lt;SPAN&gt;APPDYNAMICS_CONTROLLER_HOST_NAME variable when running AppD? If so, is this the IP or hostname for your install?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP addresses cannot be used with SSL Certificate SNI, which explains the error, although I would have expected just a browser warning. This makes me wonder, are you connecting via a proxy from your client to your AppD server? This could be trying to generate an SSL cert for the connection and failing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Worth reading:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.appdynamics.com/appd/23.x/latest/en/application-monitoring/install-app-server-agents/java-agent/administer-the-java-agent/java-agent-configuration-properties#:~:text=Required%3A%20Yes-,Controller%20Host,-The%20hostname%20or" target="_blank"&gt;https://docs.appdynamics.com/appd/23.x/latest/en/application-monitoring/install-app-server-agents/java-agent/administer-the-java-agent/java-agent-configuration-properties#:~:text=Required%3A%20Yes-,Controller%20Host,-The%20hostname%20or&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.appdynamics.com/appd/onprem/23.x/23.6/en/secure-the-platform/controller-ssl-and-certificates" target="_blank"&gt;https://docs.appdynamics.com/appd/onprem/23.x/23.6/en/secure-the-platform/controller-ssl-and-certificates&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 21:24:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/741465#M11813</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-11T21:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: AppDynamics HTTP Error 400 Invalid SNI</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/741474#M11814</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Thanks a lot for your consideration.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I have been going through some jetty related posts (&lt;A href="https://github.com/ring-clojure/ring/blob/cefb95e698eeb8c58a082ddb2eec6fb9958506cb/ring-jetty-adapter/src/ring/adapter/jetty.clj#L276C1-L277C1" target="_blank" rel="noopener"&gt;ring/ring-jetty-adapter/src/ring/adapter/jetty.clj at cefb95e698eeb8c58a082ddb2eec6fb9958506cb · ring-clojure/ring&lt;/A&gt;) in regard to this issue as it is the webserver running the controller. I found out that this is not a real issue with jetty, but rather, it is the default behavior. But luckily, it has a workaround.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;After doing some research, below is the workaround:&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;STRONG&gt;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;This is not a permanent solution as the below changes will revert whenever jetty is upgraded, but it temporarily solves the problem.&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$ cd /opt/appdynamics/platform/product/controller/appserver/jetty/etc
$ cat jetty-ssl.xml
&amp;lt;?xml version="1.0"?&amp;gt;&amp;lt;!DOCTYPE Configure PUBLIC "-//Jetty//Configure//EN" "http://www.eclipse.org/jetty/configure_9_3.dtd"&amp;gt;

&amp;lt;!-- ============================================================= --&amp;gt;
&amp;lt;!-- Base SSL configuration                                        --&amp;gt;
&amp;lt;!-- This configuration needs to be used together with 1 or more   --&amp;gt;
&amp;lt;!-- of jetty-https.xml or jetty-http2.xml                         --&amp;gt;
&amp;lt;!-- ============================================================= --&amp;gt;
&amp;lt;Configure id="Server" class="org.eclipse.jetty.server.Server"&amp;gt;

  &amp;lt;!-- =========================================================== --&amp;gt;
  &amp;lt;!-- Create a TLS specific HttpConfiguration based on the        --&amp;gt;
  &amp;lt;!-- common HttpConfiguration defined in jetty.xml               --&amp;gt;
  &amp;lt;!-- Add a SecureRequestCustomizer to extract certificate and    --&amp;gt;
  &amp;lt;!-- session information                                         --&amp;gt;
  &amp;lt;!-- =========================================================== --&amp;gt;
  &amp;lt;New id="sslHttpConfig" class="org.eclipse.jetty.server.HttpConfiguration"&amp;gt;
    &amp;lt;Arg&amp;gt;&amp;lt;Ref refid="httpConfig"/&amp;gt;&amp;lt;/Arg&amp;gt;
    &amp;lt;Call name="addCustomizer"&amp;gt;
      &amp;lt;Arg&amp;gt;
        &amp;lt;New class="org.eclipse.jetty.server.SecureRequestCustomizer"&amp;gt;
          &amp;lt;Arg name="sniRequired" type="boolean"&amp;gt;&amp;lt;Property name="jetty.ssl.sniRequired" default="false"/&amp;gt;&amp;lt;/Arg&amp;gt;
          &amp;lt;Arg name="sniHostCheck" type="boolean"&amp;gt;&amp;lt;Property name="jetty.ssl.sniHostCheck" default="true"/&amp;gt;&amp;lt;/Arg&amp;gt;
          &amp;lt;Arg name="stsMaxAgeSeconds" type="int"&amp;gt;&amp;lt;Property name="jetty.ssl.stsMaxAgeSeconds" default="-1"/&amp;gt;&amp;lt;/Arg&amp;gt;
          &amp;lt;Arg name="stsIncludeSubdomains" type="boolean"&amp;gt;&amp;lt;Property name="jetty.ssl.stsIncludeSubdomains" default="false"/&amp;gt;&amp;lt;/Arg&amp;gt;
        &amp;lt;/New&amp;gt;
      &amp;lt;/Arg&amp;gt;
    &amp;lt;/Call&amp;gt;
  &amp;lt;/New&amp;gt;

&amp;lt;/Configure&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In the example above (&lt;EM&gt;jetty-ssl.xml&amp;nbsp;&lt;/EM&gt;file), the default value for&amp;nbsp;jetty.ssl.sniHostCheck is "true". This value has to be changed to default="false" to bypass the &lt;EM&gt;sniHostCheck&lt;/EM&gt;.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;New id="sslHttpConfig" class="org.eclipse.jetty.server.HttpConfiguration"&amp;gt;
    &amp;lt;Arg&amp;gt;&amp;lt;Ref refid="httpConfig"/&amp;gt;&amp;lt;/Arg&amp;gt;
    &amp;lt;Call name="addCustomizer"&amp;gt;
      &amp;lt;Arg&amp;gt;
        &amp;lt;New class="org.eclipse.jetty.server.SecureRequestCustomizer"&amp;gt;
          &amp;lt;!-- output truncated --&amp;gt;
          &amp;lt;Arg name="sniHostCheck" type="boolean"&amp;gt;&amp;lt;Property name="jetty.ssl.sniHostCheck" default="false"/&amp;gt;&amp;lt;/Arg&amp;gt;
          &amp;lt;!-- output truncated --&amp;gt;
        &amp;lt;/New&amp;gt;
      &amp;lt;/Arg&amp;gt;
    &amp;lt;/Call&amp;gt;
  &amp;lt;/New&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;You may also need to change it in &lt;FONT color="#FF0000"&gt;jetty-ssl.xml.j2&lt;/FONT&gt; file&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Then, you &lt;STRONG&gt;have to restart&lt;/STRONG&gt; the Controller AppServer.&lt;/P&gt;&lt;P&gt;After the controller AppServer restart is completed, you will be able to access the AppDynamics Controller via &lt;A target="_self"&gt;https://&amp;lt;controller_ip_addr&amp;gt;:8181&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="HTTPs.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38112iC7669ED1CD084F53/image-size/large?v=v2&amp;amp;px=999" role="button" title="HTTPs.jpg" alt="HTTPs.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 22:13:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/741474#M11814</guid>
      <dc:creator>Osama_Abbas1</dc:creator>
      <dc:date>2025-03-11T22:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: AppDynamics HTTP Error 400 Invalid SNI</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/741503#M11816</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/293023"&gt;@Osama_Abbas1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for letting us know how you resolved it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Good luck with your future AppD work!&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 07:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/741503#M11816</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-12T07:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: AppDynamics HTTP Error 400 Invalid SNI</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/741538#M11817</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks! I appreciate it. Wishing you the best too! &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 10:10:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/741538#M11817</guid>
      <dc:creator>Osama_Abbas1</dc:creator>
      <dc:date>2025-03-12T10:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk AppDynamics HTTP Error 400 Invalid SNI</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/754571#M11980</link>
      <description>&lt;P&gt;Recently I have created a community article regarding the SNI checks for each of the components in AppDynamics product - Controller, ES and EUM server. Please feel free to check it out, I have described exactly how SNI checks work, how to fix this issue permanently, and how to disable the SNI checks for each of the component of AppD:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/AppDynamics-Knowledge-Base/AppDynamics-Platform-Best-Practices-and-Guidance-for-SNI-Checks/ta-p/753919" target="_blank"&gt;https://community.splunk.com/t5/AppDynamics-Knowledge-Base/AppDynamics-Platform-Best-Practices-and-Guidance-for-SNI-Checks/ta-p/753919&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2025 13:00:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Splunk-AppDynamics-HTTP-Error-400-Invalid-SNI/m-p/754571#M11980</guid>
      <dc:creator>Maciej_Popek</dc:creator>
      <dc:date>2025-10-22T13:00:00Z</dc:date>
    </item>
  </channel>
</rss>

