<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic After upgrading to Splunk 6.6.0, why am I receiving warning messages such as &amp;quot;WARN  SSLCommon - Received fatal SSL3 alert&amp;quot;? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372459#M13661</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I upgraded a Search Head to 6.6.0, and am getting the following messages continuously...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;5-10-2017 13:12:10.558 -0400 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client hello C', alert_description='handshake failure'.
05-10-2017 13:12:10.558 -0400 WARN  HttpListener - Socket error from 127.0.0.1 while idling: error:1408A10B:SSL routines:ssl3_get_client_hello:wrong version number
05-10-2017 13:12:13.181 -0400 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client hello C', alert_description='handshake failure'.
05-10-2017 13:12:13.181 -0400 WARN  HttpListener - Socket error from 127.0.0.1 while idling: error:1408A10B:SSL routines:ssl3_get_client_hello:wrong version number
05-10-2017 13:12:15.624 -0400 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client hello C', alert_description='handshake failure'.
05-10-2017 13:12:15.624 -0400 WARN  HttpListener - Socket error from 127.0.0.1 while idling: error:1408A10B:SSL routines:ssl3_get_client_hello:wrong version number
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 10 May 2017 17:15:22 GMT</pubDate>
    <dc:creator>a212830</dc:creator>
    <dc:date>2017-05-10T17:15:22Z</dc:date>
    <item>
      <title>After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372459#M13661</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I upgraded a Search Head to 6.6.0, and am getting the following messages continuously...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;5-10-2017 13:12:10.558 -0400 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client hello C', alert_description='handshake failure'.
05-10-2017 13:12:10.558 -0400 WARN  HttpListener - Socket error from 127.0.0.1 while idling: error:1408A10B:SSL routines:ssl3_get_client_hello:wrong version number
05-10-2017 13:12:13.181 -0400 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client hello C', alert_description='handshake failure'.
05-10-2017 13:12:13.181 -0400 WARN  HttpListener - Socket error from 127.0.0.1 while idling: error:1408A10B:SSL routines:ssl3_get_client_hello:wrong version number
05-10-2017 13:12:15.624 -0400 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client hello C', alert_description='handshake failure'.
05-10-2017 13:12:15.624 -0400 WARN  HttpListener - Socket error from 127.0.0.1 while idling: error:1408A10B:SSL routines:ssl3_get_client_hello:wrong version number
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 10 May 2017 17:15:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372459#M13661</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2017-05-10T17:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372460#M13662</link>
      <description>&lt;P&gt;Its a bug ... Roll back to previous version and see&lt;/P&gt;

&lt;P&gt;Everything works as normal&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 18:37:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372460#M13662</guid>
      <dc:creator>naidusadanala</dc:creator>
      <dc:date>2017-05-10T18:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372461#M13663</link>
      <description>&lt;P&gt;Do you see any communication failures or just these warnings? &lt;/P&gt;

&lt;P&gt;Include any SSL related conf from your server.conf or web.conf (probably good to use btool here). Since it was an upgrade, there's always a chance there was a leftover ssl config from a prior release that conflicts with modern security requirements for SSL.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 12:07:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372461#M13663</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-05-11T12:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372462#M13664</link>
      <description>&lt;P&gt;Looks like there's some known issues related to SSL and upgrades.&lt;/P&gt;

&lt;P&gt;Do any of these items seem like the cause? &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/ReleaseNotes/Knownissues"&gt;http://docs.splunk.com/Documentation/Splunk/latest/ReleaseNotes/Knownissues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 12:09:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372462#M13664</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-05-11T12:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372463#M13665</link>
      <description>&lt;P&gt;any updates on this? Im experiencing the same issue now.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 03:23:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372463#M13665</guid>
      <dc:creator>KPamatian</dc:creator>
      <dc:date>2017-06-29T03:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372464#M13666</link>
      <description>&lt;P&gt;I'm also experiencing this after upgrade from 6.5.1 to 6.6.1. Had to rollback to previous version and all worked.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2017 15:17:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372464#M13666</guid>
      <dc:creator>ehorwood</dc:creator>
      <dc:date>2017-07-03T15:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372465#M13667</link>
      <description>&lt;P&gt;Are you using older universal forwarders pre 6.2.x and sending traffic to a splunk tcp SSL port on the indexer? &lt;/P&gt;

&lt;P&gt;In particular the older 6.0/6.1 series releases:&lt;BR /&gt;
6.0.0 to 6.0.6 forwarders&lt;BR /&gt;
6.1.0 to 6.1.4 forwarders&lt;/P&gt;

&lt;P&gt;If so you can make the changes described in the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/ReleaseNotes/Knownissues"&gt;known issues&lt;/A&gt; for 6.6.2 or upgrade your forwarders to a new version.&lt;/P&gt;

&lt;P&gt;I suspect that your seeing older forwarders attempting to use an SSL/TLS cipher suite that is no longer supported by a modern version of the Splunk enterprise server.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2017 08:25:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372465#M13667</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-07-04T08:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372466#M13668</link>
      <description>&lt;P&gt;Changes to the cipher suites between versions of splunk mean that OOTB the two versions of splunk will not have a common cipher to share the documentation advises providing a common cipher the two versions can agree on.&lt;/P&gt;

&lt;P&gt;SSL/TLS are protocols - NOT ciphers. In particular, TLS is an evolution of SSL.&lt;/P&gt;

&lt;P&gt;The relevant change is in $SPLUNK_HOM/etc/system/default/server.conf, and is the change to cipherSuite. In 6.4.1 this is set to&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and in 6.6.1 this is set to&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDH-ECDSA-AES256-GCM-SHA384:ECDH-ECDSA-AES128-GCM-SHA256:ECDH-ECDSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256:AES128-SHA256
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;TLSv1+HIGH (and corresponding for TLSv1.2) means all ciphers compatible with TLSv1 of HIGH strength. There is some overlap here with the ciphers compatible with SSL3.0. However, none of the SSL3.0 ciphers appear in the 6.6.1 list.&lt;/P&gt;

&lt;P&gt;To see this more clearly, take a Linux system with openssl installed (almost any Linux system will do!).&lt;/P&gt;

&lt;P&gt;Run:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;openssl ciphers SSLv3+HIGH
openssl ciphers TLSv1+HIGH
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note that these give you the same results. However, they all end with SHA. In the explicit list you provide in 6.6.1 they all end with SHA, so it's easy to see that there's no overlap with SSLv3+HIGH and the new list in 6.6.1 - leading to the behaviour observed. Any system (such as Splunk 6.1) which only supports TLS1.0 and below (including SSL3) won't be able to communicate with a Splunk 6.6.1 server with default config only suitable for TLS1.2.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 06:47:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372466#M13668</guid>
      <dc:creator>nclancy_splunk</dc:creator>
      <dc:date>2017-07-24T06:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372467#M13669</link>
      <description>&lt;P&gt;thank you nclancy, this was a fantastic help.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 14:29:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372467#M13669</guid>
      <dc:creator>mbrunetto</dc:creator>
      <dc:date>2018-02-02T14:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372468#M13670</link>
      <description>&lt;P&gt;@a212830 - Would you accept this answer if it helped?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 13:11:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372468#M13670</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2018-02-06T13:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372469#M13671</link>
      <description>&lt;P&gt;I've battled this issue so many times - nclancy, your comment was very helpful, however - I still had some issues.&lt;/P&gt;

&lt;P&gt;At first, I opted to add the following to &lt;STRONG&gt;$SPLUNK_HOME/etc/system/local/inputs.conf&lt;/STRONG&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[applicationsManagement]
cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I believe there's a bug, because after a Splunk restart, the btool debug didn't report the change:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$ ./splunk btool inputs list --debug | grep cipher
/opt/splunkforwarder/etc/system/default/inputs.conf                        cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I ended up editing &lt;STRONG&gt;$SPLUNK_HOME/etc/system/default/inputs.conf&lt;/STRONG&gt; and it did the trick. No more SSLv3 errors!&lt;/P&gt;

&lt;P&gt;If you're at Splunk and can replicate this issue, I'm happy to provide a diag so we can address this bug.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 19:10:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372469#M13671</guid>
      <dc:creator>andrewjhill</dc:creator>
      <dc:date>2018-12-20T19:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372470#M13672</link>
      <description>&lt;P&gt;I think your specific issue is actually that you should have edited the stanza &lt;CODE&gt;[SSL]&lt;/CODE&gt;, not &lt;CODE&gt;[applicationsManagement]&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;Since your changes to default will be reverted upon upgrade, I highly recommend you try adding the stanza in &lt;CODE&gt;local&lt;/CODE&gt; again but as:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[SSL]
cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 02 Jan 2019 22:03:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372470#M13672</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-01-02T22:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading to Splunk 6.6.0, why am I receiving warning messages such as "WARN  SSLCommon - Received fatal SSL3 alert"?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372471#M13673</link>
      <description>&lt;P&gt;adding &lt;CODE&gt;cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH&lt;/CODE&gt; parameter under &lt;CODE&gt;[sslConfig]&lt;/CODE&gt; in server.conf did the trick for us. &lt;/P&gt;

&lt;P&gt;We had HTTP event collector servers stopped sending data once upgraded from v6.5 to v7.1.6. &lt;/P&gt;

&lt;P&gt;put this in server.conf &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[sslConfig]
cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 30 May 2019 09:01:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/After-upgrading-to-Splunk-6-6-0-why-am-I-receiving-warning/m-p/372471#M13673</guid>
      <dc:creator>abhib89</dc:creator>
      <dc:date>2019-05-30T09:01:32Z</dc:date>
    </item>
  </channel>
</rss>

