<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL enabled between deployment server and deployment client (UF) in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/743326#M22024</link>
    <description>&lt;P&gt;did you wind up getting a good solution in place for pushing new certs from the deployment server?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Apr 2025 21:56:54 GMT</pubDate>
    <dc:creator>msquicc</dc:creator>
    <dc:date>2025-04-02T21:56:54Z</dc:date>
    <item>
      <title>SSL enabled between deployment server and deployment client (UF)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/581825#M11234</link>
      <description>&lt;P&gt;In my environment, I've setup the SSL communication and authentication between Deployment Server and its deployment client. It is working fine.&lt;/P&gt;&lt;P&gt;The trouble came when nearly 1 year - the renewal of the SSL is needed, meaning the server.pem and cacert.pem in UF require to be updated with renewed SSL.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the first year, we have used DS to push the SSL cert over to UF. Question is - is there any way to push the second year's SSL cert (server.pem and cacert.pem) over to UF using Deployment servers while the first year SSL still valid?&lt;/P&gt;&lt;P&gt;Or is there any best practice how to renew the cert in UF (deployment client) in yearly basis?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 06:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/581825#M11234</guid>
      <dc:creator>krusovice</dc:creator>
      <dc:date>2022-01-20T06:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL enabled between deployment server and deployment client (UF)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/581828#M11235</link>
      <description>&lt;P&gt;Ow, are you saying that you pushed a common ssl cert to all UF's?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 06:33:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/581828#M11235</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-20T06:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: SSL enabled between deployment server and deployment client (UF)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/581840#M11239</link>
      <description>&lt;P&gt;Yes, in our environment, there is cacert.pem and server.pem sit in the UF that require to annually renewed.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 07:02:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/581840#M11239</guid>
      <dc:creator>krusovice</dc:creator>
      <dc:date>2022-01-20T07:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: SSL enabled between deployment server and deployment client (UF)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/581842#M11240</link>
      <description>&lt;P&gt;my understanding was ssl cert was very unique with priv key and everything unless csr&amp;nbsp; and key is not generated on server it will not work.&lt;/P&gt;&lt;P&gt;i am very interested in the topic lets ask isoutamo or anyone else who can help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 07:10:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/581842#M11240</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-20T07:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: SSL enabled between deployment server and deployment client (UF)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/581847#M11241</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;the best way to renew those is dependent on your way to use those. If you have use individual certificate in every node then you definitely need some tool which will manage that. But as the normal way to do this with splunk is to use one (or only few) cert for all UFs then it's much easier. Depending on place where you have put your cert files on UF you need a separate deployment tool (e.g. ansible, any MS based for windows) to renew those or use DS to add that on separate TA/SA on clients and then restart those.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://hurricanelabs.com/splunk-tutorials/splunk-certificates-master-guide/" target="_blank"&gt;https://hurricanelabs.com/splunk-tutorials/splunk-certificates-master-guide/&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.duanewaddle.com/splunk-conf-2014/" target="_blank"&gt;https://www.duanewaddle.com/splunk-conf-2014/&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://wiki.splunk.com/images/f/fb/SplunkTrustApril-SSLipperySlopeRevisited.pdf" target="_blank"&gt;https://wiki.splunk.com/images/f/fb/SplunkTrustApril-SSLipperySlopeRevisited.pdf&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.aplura.com/assets/pdf/securing-splunk-cheatsheet.pdf" target="_blank"&gt;https://www.aplura.com/assets/pdf/securing-splunk-cheatsheet.pdf&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 20 Jan 2022 07:53:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/581847#M11241</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-20T07:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: SSL enabled between deployment server and deployment client (UF)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/581959#M11253</link>
      <description>&lt;P&gt;Thank you for the reply, we are using one cert applied to all UFs.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 07:08:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/581959#M11253</guid>
      <dc:creator>tinatan</dc:creator>
      <dc:date>2022-01-21T07:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: SSL enabled between deployment server and deployment client (UF)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/743326#M22024</link>
      <description>&lt;P&gt;did you wind up getting a good solution in place for pushing new certs from the deployment server?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 21:56:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/743326#M22024</guid>
      <dc:creator>msquicc</dc:creator>
      <dc:date>2025-04-02T21:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSL enabled between deployment server and deployment client (UF)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/743329#M22025</link>
      <description>You should create an own app which contains all those needed certs. If you have Splunk Cloud in use you can copy the idea from its Universal Forwarder app.&lt;BR /&gt;Of course it needs that you have added your own private CA.pem into Splunk's CA certs file if you have this in use.</description>
      <pubDate>Wed, 02 Apr 2025 22:02:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/743329#M22025</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-04-02T22:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSL enabled between deployment server and deployment client (UF)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/743332#M22027</link>
      <description>&lt;P&gt;thanks, yea, I was planning on giving that a shot, but mostly interested in how to replace those certs on the UFs before they expire.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;ansible / MS tools could be a backup, but I'd really like to implement and have it fully controlled from the deployment server.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;&lt;BR /&gt;so, just thinking through it, updating the cert(s) in this app would push out the updated certs to the UFs, but then all of the UFs would fail to phone home until I update the certs on the deployment server?&amp;nbsp; then I'd have to hope that everything works from a fully broken state?&amp;nbsp; just seems risky.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;open to suggestions, and maybe I'm over thinking some of it.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;wondering if anyone's accomplished this in a safe practical way?&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/95330"&gt;@krusovice&lt;/a&gt;, what did you wind up doing?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 22:19:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SSL-enabled-between-deployment-server-and-deployment-client-UF/m-p/743332#M22027</guid>
      <dc:creator>msquicc</dc:creator>
      <dc:date>2025-04-02T22:19:23Z</dc:date>
    </item>
  </channel>
</rss>

