<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I now getting &amp;quot;SSL configuration issue: invalid CA public key file&amp;quot; from Splunk Supporting Add-on for Active Directory after upgrading ? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233791#M26271</link>
    <description>&lt;P&gt;I fixed this by turning off the SSL connection to the Domain Controller.&lt;/P&gt;

&lt;P&gt;My next task is to figure out what changed with the DC certificate and get that updated.&lt;/P&gt;

&lt;P&gt;I have Splunk Supporting Add-on for Active Directory 2.1.3, but I found the answer in the docs for version 1.2.2&lt;/P&gt;

&lt;P&gt;From &lt;A href="http://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/ConfiguretheSA-ldapsearchsupportingaddon"&gt;http://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/ConfiguretheSA-ldapsearchsupportingaddon&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Whether or not SA-ldapsearch should attempt to connect to the GC server using Secure Sockets Layer (SSL). Set to true to connect with SSL and false to connect without SSL.

Important: If you specify true for this attribute, then the GC server you specify must have a valid SSL certificate installed. For additional information, review "How to enable LDAP over SSL with a third-party certification authority" (http://support.microsoft.com/kb/321051) and "How to troubleshoot LDAP over SSL connection problems" (http://support.microsoft.com/kb/938703) on Microsoft's support site. Defaults to false.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 19 Oct 2016 13:05:40 GMT</pubDate>
    <dc:creator>reswob4</dc:creator>
    <dc:date>2016-10-19T13:05:40Z</dc:date>
    <item>
      <title>Why am I now getting "SSL configuration issue: invalid CA public key file" from Splunk Supporting Add-on for Active Directory after upgrading ?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233787#M26267</link>
      <description>&lt;P&gt;After upgrading from Splunk Enterprise 6.4.3 to 6.5.0, the ldapsearch in Splunk Supporting Add-on for Active Directory (2.1.3) is now getting the error - "SSL configuration issue: invalid CA public key file".  Searches worked before the upgrade.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 15:10:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233787#M26267</guid>
      <dc:creator>scottrunyon</dc:creator>
      <dc:date>2016-10-05T15:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I now getting "SSL configuration issue: invalid CA public key file" from Splunk Supporting Add-on for Active Directory after upgrading ?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233788#M26268</link>
      <description>&lt;P&gt;This is likely due to the way that Splunk changed the SSL key-value pairs in version 6.5.0. Did you update your local server.conf and ssl.conf configurations with the new SSL stanzas?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sslRootCAPath = 
* Full path to the operating system's root CA (Certificate Authority)
  certificate store.
* The  must refer to a PEM format file containing one or more root CA
  certificates concatenated together.
* Required for Common Criteria.
* NOTE: Splunk plans to submit Splunk Enterprise for Common Criteria
  evaluation. Splunk does not support using the product in Common
  Criteria mode until it has been certified by NIAP. See the "Securing
  Splunk Enterprise" manual for information on the status of Common
  Criteria certification.
* This setting is not used on Windows.
* Default is unset.'

caCertFile = 
'* DEPRECATED; use 'sslRootCAPath' instead.
* Used only if 'sslRootCAPath' is unset.
* File name (relative to 'caPath') of the CA (Certificate Authority)
  certificate PEM format file containing one or more certificates concatenated
  together.
* Default is cacert.pem.'
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 11 Oct 2016 13:32:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233788#M26268</guid>
      <dc:creator>jmaple</dc:creator>
      <dc:date>2016-10-11T13:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I now getting "SSL configuration issue: invalid CA public key file" from Splunk Supporting Add-on for Active Directory after upgrading ?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233789#M26269</link>
      <description>&lt;P&gt;I am running on Windows Server, is this still valid?  &lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2016 14:05:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233789#M26269</guid>
      <dc:creator>scottrunyon</dc:creator>
      <dc:date>2016-10-11T14:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I now getting "SSL configuration issue: invalid CA public key file" from Splunk Supporting Add-on for Active Directory after upgrading ?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233790#M26270</link>
      <description>&lt;P&gt;Because the documentation doesn't give a Windows alternative, I believe it's your best bet to give a try and see if it gets fixed. Otherwise I'd open a ticket with Splunk support.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2016 14:10:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233790#M26270</guid>
      <dc:creator>jmaple</dc:creator>
      <dc:date>2016-10-11T14:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I now getting "SSL configuration issue: invalid CA public key file" from Splunk Supporting Add-on for Active Directory after upgrading ?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233791#M26271</link>
      <description>&lt;P&gt;I fixed this by turning off the SSL connection to the Domain Controller.&lt;/P&gt;

&lt;P&gt;My next task is to figure out what changed with the DC certificate and get that updated.&lt;/P&gt;

&lt;P&gt;I have Splunk Supporting Add-on for Active Directory 2.1.3, but I found the answer in the docs for version 1.2.2&lt;/P&gt;

&lt;P&gt;From &lt;A href="http://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/ConfiguretheSA-ldapsearchsupportingaddon"&gt;http://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/ConfiguretheSA-ldapsearchsupportingaddon&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Whether or not SA-ldapsearch should attempt to connect to the GC server using Secure Sockets Layer (SSL). Set to true to connect with SSL and false to connect without SSL.

Important: If you specify true for this attribute, then the GC server you specify must have a valid SSL certificate installed. For additional information, review "How to enable LDAP over SSL with a third-party certification authority" (http://support.microsoft.com/kb/321051) and "How to troubleshoot LDAP over SSL connection problems" (http://support.microsoft.com/kb/938703) on Microsoft's support site. Defaults to false.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 19 Oct 2016 13:05:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233791#M26271</guid>
      <dc:creator>reswob4</dc:creator>
      <dc:date>2016-10-19T13:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I now getting "SSL configuration issue: invalid CA public key file" from Splunk Supporting Add-on for Active Directory after upgrading ?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233792#M26272</link>
      <description>&lt;P&gt;I opened a ticket with with support.  To resolve my issue i added a ssl.conf to \etc\system\local.&lt;/P&gt;

&lt;P&gt;ssl.conf contained - &lt;/P&gt;

&lt;P&gt;[sslConfig]&lt;/P&gt;

&lt;P&gt;sslVersions = tls&lt;BR /&gt;
caCertFile = E:\Splunk\etc\auth\cacert.pem&lt;/P&gt;

&lt;P&gt;Note - entire path was needed to get it to see the cert.  &lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2016 20:11:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233792#M26272</guid>
      <dc:creator>scottrunyon</dc:creator>
      <dc:date>2016-10-19T20:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I now getting "SSL configuration issue: invalid CA public key file" from Splunk Supporting Add-on for Active Directory after upgrading ?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233793#M26273</link>
      <description>&lt;P&gt;I'm glad that solution worked for you.  Unfortunately, it did not work for me.&lt;/P&gt;

&lt;P&gt;The docs for the add-on (&lt;A href="http://docs.splunk.com/Documentation/SA-LdapSearch/2.1.3/User/ConfiguretheSplunkSupportingAdd-onforActiveDirectory"&gt;http://docs.splunk.com/Documentation/SA-LdapSearch/2.1.3/User/ConfiguretheSplunkSupportingAdd-onforActiveDirectory&lt;/A&gt;) say ssl.conf should be in $SPLUNK_HOME/etc/apps/SA-ldapsearch/local.&lt;/P&gt;

&lt;P&gt;So here is the ssl.conf file I created: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[sslconfig]
sslVersions = tls
caCertFile=/opt/splunk/etc/auth/cacert.pem
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I then re-enabled SSL to the DC.&lt;/P&gt;

&lt;P&gt;But after I restarted Splunk, with the ssl.conf in the $SPLUNK_HOME/etc/apps/SA-ldapsearch/local folder, I get the original error.  If I put ssl.conf in the location suggested by tech support, I get the following errors on restart:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Invalid key in stanza [sslconfig] in /opt/splunk/etc/system/local/ssl.conf, line 2: sslVersions  (value:  tls).
Invalid key in stanza [sslconfig] in /opt/splunk/etc/system/local/ssl.conf, line 3: caCertFile (value: /opt/splunk/etc/auth/cacert.pem).
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;AND I still get the original error.&lt;/P&gt;

&lt;P&gt;So I guess I'm going to have to open my own ticket.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2016 11:44:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233793#M26273</guid>
      <dc:creator>reswob4</dc:creator>
      <dc:date>2016-10-20T11:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I now getting "SSL configuration issue: invalid CA public key file" from Splunk Supporting Add-on for Active Directory after upgrading ?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233794#M26274</link>
      <description>&lt;P&gt;This also worked for me...just added the below in the local ssl.conf; &lt;/P&gt;

&lt;P&gt;caCertFile = E:\Splunk\etc\auth\cacert.pem&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2016 13:33:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233794#M26274</guid>
      <dc:creator>dewald13</dc:creator>
      <dc:date>2016-10-20T13:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I now getting "SSL configuration issue: invalid CA public key file" from Splunk Supporting Add-on for Active Directory after upgrading ?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233795#M26275</link>
      <description>&lt;P&gt;This also helped me solving the issue. &lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2016 13:14:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233795#M26275</guid>
      <dc:creator>ttchorz</dc:creator>
      <dc:date>2016-10-31T13:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I now getting "SSL configuration issue: invalid CA public key file" from Splunk Supporting Add-on for Active Directory after upgrading ?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233796#M26276</link>
      <description>&lt;P&gt;&lt;CODE&gt;sslConfig&lt;/CODE&gt; is case sensitive.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 23:26:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233796#M26276</guid>
      <dc:creator>jreuter_splunk</dc:creator>
      <dc:date>2017-03-23T23:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I now getting "SSL configuration issue: invalid CA public key file" from Splunk Supporting Add-on for Active Directory after upgrading ?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233797#M26277</link>
      <description>&lt;P&gt;Don't put a full path on the CertFile. This worked for me: &lt;/P&gt;

&lt;P&gt;[sslConfig]&lt;BR /&gt;
sslVersions = tls&lt;BR /&gt;
caCertFile = cacert.pem&lt;/P&gt;

&lt;P&gt;FYI: support also said that it is there by default in v2.1.4 of the SA-ldapsearch app. So if it does not work for you, you may try upgrading. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 17:41:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/233797#M26277</guid>
      <dc:creator>aliakseidzianis</dc:creator>
      <dc:date>2017-03-24T17:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I now getting "SSL configuration issue: invalid CA public key file" from Splunk Supporting Add-on f</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/555686#M65882</link>
      <description>&lt;P&gt;My situation with this error:&lt;/P&gt;&lt;P&gt;I had established my own certs (including a CACert.pem file) and placed them in a folder:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;/opt/splunk/etc/auth/my_certs&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;... and everything worked fine, except for ldap-search it was complaining of an 'invalid CA public key file'&lt;/P&gt;&lt;P&gt;in the SA-ldapsearch/default folder is the file ssl.conf with an entry:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[sslConfig]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sslVersions = tls&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;caCertFile = cacert.pm&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well.. because my CA cert was named "CACert.pem" -- the add-on couldn't find it.&lt;/P&gt;&lt;P&gt;I copied my &lt;STRONG&gt;CACert.pem&lt;/STRONG&gt; to '&lt;STRONG&gt;cacert.pem&lt;/STRONG&gt;' -- and everything worked well again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/210895"&gt;@jreuter_splunk&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;sslConfig is case sensitive.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Indeed it is.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 19:00:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-now-getting-quot-SSL-configuration-issue-invalid-CA/m-p/555686#M65882</guid>
      <dc:creator>memarshall63</dc:creator>
      <dc:date>2021-06-14T19:00:56Z</dc:date>
    </item>
  </channel>
</rss>

