<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Errors in log after enabling requireClientCert in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Errors-in-log-after-enabling-requireClientCert/m-p/636902#M15906</link>
    <description>&lt;P&gt;In order to satisfy the "Upgrade readiness app" in 9.0.2 it seems we must set "requireClientCert = true" in our server.conf under the [sslConfig] stanza. However, when I do this I begin to see a lot of errors in splunkd.log of the following nature:&lt;/P&gt;&lt;P&gt;03-31-2023 10:53:36.274 -0400 ERROR ExecProcessor [1996726 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py" Enter PEM pass phrase:&lt;/P&gt;&lt;P&gt;Presumably this is because the key has a passphrase set on it, but we do have "sslPassword" set, so&amp;nbsp; I'm not sure what's causing the issue. Our complete sslConfig stanza looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[sslConfig]&lt;BR /&gt;enableSplunkdSSL = true&lt;BR /&gt;sslRootCAPath = /opt/splunk/etc/auth/certs/ca.pem&lt;BR /&gt;serverCert = /opt/splunk/etc/auth/certs/combined.pem&lt;BR /&gt;sslPassword = &amp;lt;REDACTED&amp;gt;&lt;BR /&gt;sslVerifyServerCert = true&lt;BR /&gt;verifyServerCert = true&lt;BR /&gt;requireClientCert = true&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I haven't been able to find this issue mentioned anywhere. Any help would be appreciated. TIA&lt;/P&gt;</description>
    <pubDate>Fri, 31 Mar 2023 15:09:46 GMT</pubDate>
    <dc:creator>Brian_O</dc:creator>
    <dc:date>2023-03-31T15:09:46Z</dc:date>
    <item>
      <title>Errors in log after enabling requireClientCert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Errors-in-log-after-enabling-requireClientCert/m-p/636902#M15906</link>
      <description>&lt;P&gt;In order to satisfy the "Upgrade readiness app" in 9.0.2 it seems we must set "requireClientCert = true" in our server.conf under the [sslConfig] stanza. However, when I do this I begin to see a lot of errors in splunkd.log of the following nature:&lt;/P&gt;&lt;P&gt;03-31-2023 10:53:36.274 -0400 ERROR ExecProcessor [1996726 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py" Enter PEM pass phrase:&lt;/P&gt;&lt;P&gt;Presumably this is because the key has a passphrase set on it, but we do have "sslPassword" set, so&amp;nbsp; I'm not sure what's causing the issue. Our complete sslConfig stanza looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[sslConfig]&lt;BR /&gt;enableSplunkdSSL = true&lt;BR /&gt;sslRootCAPath = /opt/splunk/etc/auth/certs/ca.pem&lt;BR /&gt;serverCert = /opt/splunk/etc/auth/certs/combined.pem&lt;BR /&gt;sslPassword = &amp;lt;REDACTED&amp;gt;&lt;BR /&gt;sslVerifyServerCert = true&lt;BR /&gt;verifyServerCert = true&lt;BR /&gt;requireClientCert = true&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I haven't been able to find this issue mentioned anywhere. Any help would be appreciated. TIA&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 15:09:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Errors-in-log-after-enabling-requireClientCert/m-p/636902#M15906</guid>
      <dc:creator>Brian_O</dc:creator>
      <dc:date>2023-03-31T15:09:46Z</dc:date>
    </item>
  </channel>
</rss>

