<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add On for Encore - pkcs12 issue in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464412#M57087</link>
    <description>&lt;P&gt;Digging even further I am seeing the following errors on my heavy forwarder when I attempt to start the splencore process :&lt;/P&gt;

&lt;P&gt;139742838814376:error:060A60A3:digital envelope routines:FIPS_CIPHERINIT:diabled for fips:fips_enc.c:142:&lt;BR /&gt;
139742838814376:error:06074078: digital envelope routines:EVP_PBE_CipherInit:keygen failure:evp_pbe.c:197:&lt;BR /&gt;
139742838814376:error:23077073:PKCS12 routines:PKCS12_pbe_crypt:pkcs12 algo ciperinit error:p12_decr.c:87:&lt;/P&gt;

&lt;P&gt;Each time I attempt to start the eStreamer process it tries to process the pkcs file. Then I get the errors I listed above (this issue is detailed in splunk answers : &lt;A href="https://answers.splunk.com/answers/667021/splunk-estreamer-encore-client-doesnt-start.html#comment-667366" target="_blank"&gt;https://answers.splunk.com/answers/667021/splunk-estreamer-encore-client-doesnt-start.html#comment-667366&lt;/A&gt;). &lt;/P&gt;

&lt;P&gt;Yet the thread doesn't have a definitive answer. It suggests an issue with the server version of Python. I'll keep digging, but if anyone has an answer I'd appreciate any help.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 03:01:29 GMT</pubDate>
    <dc:creator>mjhebert</dc:creator>
    <dc:date>2020-09-30T03:01:29Z</dc:date>
    <item>
      <title>Splunk Add On for Encore - pkcs12 issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464409#M57084</link>
      <description>&lt;P&gt;Installed and configured Cisco Estreamer Encore add on for Splunk (3.5.8) both on the Firepower FMC and on my Splunk heavy forwarder (Splunk v 7.2.7). I can get estreamer-status and estreamer-logs to come into Splunk but not estreamer-data (the most important piece). After I configure eStreamer add on I keep getting the following error : "EncoreException : unable to read password from console." If a look a little deeper I find "Unable to process pkcs12 file".&lt;/P&gt;

&lt;P&gt;I have deleted and remade the FMC certificate 6 or 7 times. I have given it a password, and not given it a password. The result is the same. Does anyone have a similar problem or better yet a good solution for this?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 14:41:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464409#M57084</guid>
      <dc:creator>mjhebert</dc:creator>
      <dc:date>2019-10-22T14:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add On for Encore - pkcs12 issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464410#M57085</link>
      <description>&lt;P&gt;You definitely need to give it a password.&lt;/P&gt;

&lt;P&gt;Where on the heavy forwarder are you copying the certificate?  What directory path?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 17:21:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464410#M57085</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2019-11-06T17:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add On for Encore - pkcs12 issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464411#M57086</link>
      <description>&lt;P&gt;Path to certificate : [SPLUNK HOME]/etc/apps/TA-eStreamer/bin/encore &lt;/P&gt;

&lt;P&gt;File has been renamed to "client.pkcs12"&lt;/P&gt;

&lt;P&gt;Currently, the cert has a password, but the error persists. &lt;/P&gt;

&lt;P&gt;Thanks for any help you can give.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 23:35:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464411#M57086</guid>
      <dc:creator>mjhebert</dc:creator>
      <dc:date>2019-11-06T23:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add On for Encore - pkcs12 issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464412#M57087</link>
      <description>&lt;P&gt;Digging even further I am seeing the following errors on my heavy forwarder when I attempt to start the splencore process :&lt;/P&gt;

&lt;P&gt;139742838814376:error:060A60A3:digital envelope routines:FIPS_CIPHERINIT:diabled for fips:fips_enc.c:142:&lt;BR /&gt;
139742838814376:error:06074078: digital envelope routines:EVP_PBE_CipherInit:keygen failure:evp_pbe.c:197:&lt;BR /&gt;
139742838814376:error:23077073:PKCS12 routines:PKCS12_pbe_crypt:pkcs12 algo ciperinit error:p12_decr.c:87:&lt;/P&gt;

&lt;P&gt;Each time I attempt to start the eStreamer process it tries to process the pkcs file. Then I get the errors I listed above (this issue is detailed in splunk answers : &lt;A href="https://answers.splunk.com/answers/667021/splunk-estreamer-encore-client-doesnt-start.html#comment-667366" target="_blank"&gt;https://answers.splunk.com/answers/667021/splunk-estreamer-encore-client-doesnt-start.html#comment-667366&lt;/A&gt;). &lt;/P&gt;

&lt;P&gt;Yet the thread doesn't have a definitive answer. It suggests an issue with the server version of Python. I'll keep digging, but if anyone has an answer I'd appreciate any help.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:01:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464412#M57087</guid>
      <dc:creator>mjhebert</dc:creator>
      <dc:date>2020-09-30T03:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add On for Encore - pkcs12 issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464413#M57088</link>
      <description>&lt;P&gt;Hey @mjhebert,&lt;BR /&gt;
Were you able to get this up and running? I'm experiencing the same issue and have not come across a solution yet.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 15:07:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464413#M57088</guid>
      <dc:creator>sn00p_d0ge</dc:creator>
      <dc:date>2019-12-30T15:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add On for Encore - pkcs12 issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464414#M57089</link>
      <description>&lt;P&gt;I'm running into the same issue. Were you able to resolve this?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 18:11:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464414#M57089</guid>
      <dc:creator>595147</dc:creator>
      <dc:date>2020-02-03T18:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add On for Encore - pkcs12 issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464415#M57090</link>
      <description>&lt;P&gt;I was able to solve it on my box. We had FIPS enabled which was causing the issue when it tried to create the key pair. &lt;/P&gt;

&lt;P&gt;Troubleshooting Steps:&lt;BR /&gt;
the error "EncoreException : unable to read password from console." is the error that the script throws but it's not the actual error. &lt;/P&gt;

&lt;P&gt;The error comes from crypto.py in the estreamer folder.  we ran just the select function that throws the error. &lt;/P&gt;

&lt;P&gt;run the script in the directory with client.pkcs12 cert&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;import OpenSSL.crypto

with open( "client.pkcs12", 'rb' ) as pkcs12File:
            data = pkcs12File.read()

        try:
            pkcs12 = OpenSSL.crypto.load_pkcs12( data, password )
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will give you the actual error, which is how we found out FIPS was the issue.&lt;/P&gt;

&lt;P&gt;Work Around:&lt;BR /&gt;
We loaded the app into a test environment (that had no FMC), and copied the client file to it and performed the the set up through the GUI. Once it created the keypairs, we just copied those to our actual instance and the connection was made. &lt;/P&gt;

&lt;P&gt;I hope this helps.  &lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 21:57:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-for-Encore-pkcs12-issue/m-p/464415#M57090</guid>
      <dc:creator>595147</dc:creator>
      <dc:date>2020-02-06T21:57:48Z</dc:date>
    </item>
  </channel>
</rss>

