<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1106) in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/696070#M80960</link>
    <description>&lt;P&gt;On-prem&lt;/P&gt;</description>
    <pubDate>Tue, 13 Aug 2024 00:11:11 GMT</pubDate>
    <dc:creator>clemes</dc:creator>
    <dc:date>2024-08-13T00:11:11Z</dc:date>
    <item>
      <title>[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1106)</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/695791#M80947</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Can anyone help me in getting this error resolved ?&lt;/P&gt;&lt;P&gt;2024-08-09 10:50:00,282 DEBUG pid=8956 tid=MainThread file=connectionpool.py:_new_conn:1007 | Starting new HTTPS connection (5): cisco-managed-ap-northeast-2.s3.ap-northeast-2.amazonaws.com:443&lt;BR /&gt;2024-08-09 10:50:00,312 DEBUG pid=8956 tid=MainThread file=endpoint.py:_do_get_response:205 | Exception received when sending HTTP request.&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "/splb001/splunk_fw_teams/etc/apps/TA-cisco-cloud-security-umbrella-addon/bin/ta_cisco_cloud_security_umbrella_addon/aob_py3/urllib3/connectionpool.py", line 710, in urlopen&lt;BR /&gt;chunked=chunked,&lt;BR /&gt;File "/splb001/splunk_fw_teams/etc/apps/TA-cisco-cloud-security-umbrella-addon/bin/ta_cisco_cloud_security_umbrella_addon/aob_py3/urllib3/connectionpool.py", line 386, in _make_request&lt;BR /&gt;self._validate_conn(conn)&lt;BR /&gt;File "/splb001/splunk_fw_teams/etc/apps/TA-cisco-cloud-security-umbrella-addon/bin/ta_cisco_cloud_security_umbrella_addon/aob_py3/urllib3/connectionpool.py", line 1042, in _validate_conn&lt;BR /&gt;conn.connect()&lt;BR /&gt;File "/splb001/splunk_fw_teams/etc/apps/TA-cisco-cloud-security-umbrella-addon/bin/ta_cisco_cloud_security_umbrella_addon/aob_py3/urllib3/connection.py", line 429, in connect&lt;BR /&gt;tls_in_tls=tls_in_tls,&lt;BR /&gt;File "/splb001/splunk_fw_teams/etc/apps/TA-cisco-cloud-security-umbrella-addon/bin/ta_cisco_cloud_security_umbrella_addon/aob_py3/urllib3/util/ssl_.py", line 450, in ssl_wrap_socket&lt;BR /&gt;sock, context, tls_in_tls, server_hostname=server_hostname&lt;BR /&gt;File "/splb001/splunk_fw_teams/etc/apps/TA-cisco-cloud-security-umbrella-addon/bin/ta_cisco_cloud_security_umbrella_addon/aob_py3/urllib3/util/ssl_.py", line 493, in _ssl_wrap_socket_impl&lt;BR /&gt;return ssl_context.wrap_socket(sock, server_hostname=server_hostname)&lt;BR /&gt;File "/splb001/splunk_fw_teams/lib/python3.7/ssl.py", line 423, in wrap_socket&lt;BR /&gt;session=session&lt;BR /&gt;File "/splb001/splunk_fw_teams/lib/python3.7/ssl.py", line 870, in _create&lt;BR /&gt;self.do_handshake()&lt;BR /&gt;File "/splb001/splunk_fw_teams/lib/python3.7/ssl.py", line 1139, in do_handshake&lt;BR /&gt;self._sslobj.do_handshake()&lt;BR /&gt;ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1106)&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 05:39:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/695791#M80947</guid>
      <dc:creator>clemes</dc:creator>
      <dc:date>2024-08-09T05:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1106)</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/695829#M80948</link>
      <description>&lt;P&gt;Are you trying to set it up in Cloud or on-prem? (the section of Answers where you posted it suggests Cloud but it's better to be sure).&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 12:45:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/695829#M80948</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-09T12:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1106)</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/696070#M80960</link>
      <description>&lt;P&gt;On-prem&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 00:11:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/696070#M80960</guid>
      <dc:creator>clemes</dc:creator>
      <dc:date>2024-08-13T00:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1106)</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/696292#M80964</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;This indicates that the SSL certificate is either missing from the certificate store or has expired in the add-on. Additionally, if the server is configured to use a self-signed or third-party certificate, it may not be included in the certificate store used by the add-on.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 14 Aug 2024 17:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/696292#M80964</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2024-08-14T17:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1106)</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/696295#M80965</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for the response&lt;/P&gt;&lt;P&gt;I had taken captues, there's only 2 lines followed by an ACK and a FIN, ACK:&lt;/P&gt;&lt;P&gt;TLSv1.2 Client Hello&lt;BR /&gt;TLSv1.2 Server Hello, Certificate, Server Key Exchange, Server Hello Done&lt;BR /&gt;TCP [ACK]&lt;BR /&gt;TCP [FIN, ACK]&lt;/P&gt;&lt;P&gt;I understood the issue is with Client certificate. Can you kindly help me answer the below:&lt;BR /&gt;Where do I find the certificates that is used by TA-cisco-cloud-security-umbrella-addon in Splunk ? What is the path/location of the certificate store used by the TA-cisco-cloud-security-umbrella-addon ?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 17:23:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/696295#M80965</guid>
      <dc:creator>clemes</dc:creator>
      <dc:date>2024-08-14T17:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1106)</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/696356#M80967</link>
      <description>&lt;P&gt;No. It's not about the client certificate. I understand that the FIN/ACK packet comes from your end of the connection. And the message clearly indicates that it's the server's certificate which is not trusted.&lt;/P&gt;&lt;P&gt;I asked about on-prev vs. cloud earlier because the additional question with an on-prem installation is whether you are using any TLS-inspection tools in your network. Either as an explicit proxy or as pass-through appliance. Anyway, first thing I'd try would be to simply openssl s_client to that Cisco service and make sure what the cert looks like before you start looking for local trusted cert store.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 08:09:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/696356#M80967</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-15T08:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1106)</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/697932#M81037</link>
      <description>&lt;P&gt;Can you try to add SSL CA Chain to below location and see if it works?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;1) /opt/splunk/lib/python3.7/site-packages/certifi

And

2) /etc/apps/&amp;lt;Add-on_folder&amp;gt;/lib/certify&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 06:39:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SSL-CERTIFICATE-VERIFY-FAILED-certificate-verify-failed-unable/m-p/697932#M81037</guid>
      <dc:creator>Meett</dc:creator>
      <dc:date>2024-09-02T06:39:24Z</dc:date>
    </item>
  </channel>
</rss>

