<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SHClustering SSLv3 Errors in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/SHClustering-SSLv3-Errors/m-p/450747#M24139</link>
    <description>&lt;P&gt;This alert is returned if a record is received with an incorrect MAC.  This alert also MUST be returned if an alert is sent because a TLSCiphertext decrypted in an invalid way: either it wasn't an even multiple of the block length, or its padding values, when checked, weren't correct.&lt;/P&gt;

&lt;P&gt;Possible causes: &lt;BR /&gt;
SNAT isn't enabled &lt;BR /&gt;
F5 is unloading ssl and rebaking with F5's cert&lt;BR /&gt;
Wrong ciphers in use on both ends&lt;/P&gt;

&lt;P&gt;Check server.conf [ssl] &amp;amp; [shclustering] stanzas on each search head.&lt;/P&gt;

&lt;P&gt;Also you mentioned one search head is captain.  Are you running static captain?  If so that's only supported for when you're recovering a failed cluster.&lt;/P&gt;</description>
    <pubDate>Wed, 14 Aug 2019 21:22:30 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2019-08-14T21:22:30Z</dc:date>
    <item>
      <title>SHClustering SSLv3 Errors</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SHClustering-SSLv3-Errors/m-p/450744#M24136</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;

&lt;P&gt;Been troubleshooting my distributed searching for the last two days. My environment:&lt;/P&gt;

&lt;P&gt;Primary facility:&lt;BR /&gt;
Cluster Master&lt;BR /&gt;
deployment server&lt;BR /&gt;
2 Search Heads&lt;BR /&gt;
2 indexers&lt;/P&gt;

&lt;P&gt;Secondary:&lt;BR /&gt;
2 Search Heads ( captain is here for testing)&lt;BR /&gt;
2 indexers&lt;/P&gt;

&lt;P&gt;the 2 search headers in Primary can't reach the captain and splunkd.log is showing the following:&lt;/P&gt;

&lt;P&gt;WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='SSL negotiation finished successfully', alert_description='bad record mac'.&lt;BR /&gt;
08-14-2019 18:04:48.986 +0000 ERROR HttpClientRequest - HTTP client error=error:140943FC:SSL routines:ssl3_read_bytes:sslv3 alert bad record mac while accessing server=https://:8089 for request=https://:8089/services/shcluster/captain/members.&lt;/P&gt;

&lt;P&gt;On the cluster master i'm seeing the following:&lt;BR /&gt;
(obfuscating the IPs)&lt;BR /&gt;
Bundle Replication: Problem replicating config (bundle) to search peer ' secondary indexer 1 ', Unknown write error&lt;BR /&gt;
Bundle Replication: Problem replicating config (bundle) to search peer ' secondary indexer 2 ', Unknown write error&lt;/P&gt;

&lt;P&gt;so it seems to me that what ever Master ( search or clustermaster) in either site, can't talk to devices in the other site. &lt;/P&gt;

&lt;P&gt;few thoughts:&lt;BR /&gt;
There is a F5 in between&lt;BR /&gt;
other is it's going over a WAN and latency is effecting it.&lt;/P&gt;

&lt;P&gt;Anyone have ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:46:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SHClustering-SSLv3-Errors/m-p/450744#M24136</guid>
      <dc:creator>ekenne06</dc:creator>
      <dc:date>2020-09-30T01:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: SHClustering SSLv3 Errors</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SHClustering-SSLv3-Errors/m-p/450745#M24137</link>
      <description>&lt;P&gt;You have an F5 between sites?  Why?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 19:13:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SHClustering-SSLv3-Errors/m-p/450745#M24137</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-08-14T19:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: SHClustering SSLv3 Errors</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SHClustering-SSLv3-Errors/m-p/450746#M24138</link>
      <description>&lt;P&gt;this is because this is two separate subnets. We use the F5 as a gateway to route the traffic&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 19:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SHClustering-SSLv3-Errors/m-p/450746#M24138</guid>
      <dc:creator>ekenne06</dc:creator>
      <dc:date>2019-08-14T19:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: SHClustering SSLv3 Errors</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/SHClustering-SSLv3-Errors/m-p/450747#M24139</link>
      <description>&lt;P&gt;This alert is returned if a record is received with an incorrect MAC.  This alert also MUST be returned if an alert is sent because a TLSCiphertext decrypted in an invalid way: either it wasn't an even multiple of the block length, or its padding values, when checked, weren't correct.&lt;/P&gt;

&lt;P&gt;Possible causes: &lt;BR /&gt;
SNAT isn't enabled &lt;BR /&gt;
F5 is unloading ssl and rebaking with F5's cert&lt;BR /&gt;
Wrong ciphers in use on both ends&lt;/P&gt;

&lt;P&gt;Check server.conf [ssl] &amp;amp; [shclustering] stanzas on each search head.&lt;/P&gt;

&lt;P&gt;Also you mentioned one search head is captain.  Are you running static captain?  If so that's only supported for when you're recovering a failed cluster.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 21:22:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/SHClustering-SSLv3-Errors/m-p/450747#M24139</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-08-14T21:22:30Z</dc:date>
    </item>
  </channel>
</rss>

