<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deploying SSL between Forwarder and Indexer in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Deploying-SSL-between-Forwarder-and-Indexer/m-p/564802#M24809</link>
    <description>&lt;P&gt;May I suggest using&amp;nbsp;&lt;A href="https://github.com/OpenVPN/easy-rsa" target="_blank"&gt;https://github.com/OpenVPN/easy-rsa&lt;/A&gt;?&lt;/P&gt;&lt;P&gt;The concept is like so:&lt;/P&gt;&lt;P&gt;- you generate a keypair for the client (SUF)&lt;/P&gt;&lt;P&gt;- you generate a keypair for the server (receiver, indexer etc.)&lt;/P&gt;&lt;P&gt;- the client and server each have the same CA cert&lt;/P&gt;&lt;P&gt;So three files on the server and three files on the client in a single file.&lt;/P&gt;&lt;P&gt;This is the simplest setup.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Aug 2021 22:44:25 GMT</pubDate>
    <dc:creator>ephemeric</dc:creator>
    <dc:date>2021-08-25T22:44:25Z</dc:date>
    <item>
      <title>Deploying SSL between Forwarder and Indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deploying-SSL-between-Forwarder-and-Indexer/m-p/564240#M24793</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I wanted to request help with how configuring&amp;nbsp; correctly SSL between Universal -&amp;gt; Indexer.&lt;/P&gt;&lt;P&gt;I tried following this procedure:&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.1/Security/Howtoself-signcertificates" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.1/Security/Howtoself-signcertificates&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;And I ended with two public certificates:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class="li_content"&gt;myServerCertificate.pem&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="li_content"&gt;myServerPrivateKey.key&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="li_content"&gt;myCACertificate.pem&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Afterwards I prepared the certificate in the following order:&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.1/Security/HowtoprepareyoursignedcertificatesforSplunk" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.1/Security/HowtoprepareyoursignedcertificatesforSplunk&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;cat myServerCertificate.pem myServerPrivateKey.key myCACertificate.pem &amp;gt; myNewServerCertificate.pem&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;This resulted with a signed server certificate with a chain of the authority.&lt;BR /&gt;&lt;BR /&gt;I am struggling with understating what exactly goes where and in case I understand it, how do I add one more cert to another server?..&lt;BR /&gt;&lt;BR /&gt;My mind says, Indexer has to have the private key -&amp;gt; (Not sure whether the authorities key, or the server key or the chain).&lt;BR /&gt;&lt;BR /&gt;And what the forwarder needs to have is -&amp;gt; only public key. (Not sure what)&lt;BR /&gt;&lt;BR /&gt;Summary of what I have running the whole commands:&lt;BR /&gt;myCAPrivateKey.key&lt;BR /&gt;myCACertificate.csr&lt;BR /&gt;myCACertificate.pem&lt;BR /&gt;myServerPrivateKey.key&lt;BR /&gt;myServerCertificate.csr&lt;BR /&gt;myServerCertificate.pem&lt;BR /&gt;myNewServerCertificate.pem&lt;BR /&gt;&lt;BR /&gt;Appreciate your help.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Aug 2021 19:46:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deploying-SSL-between-Forwarder-and-Indexer/m-p/564240#M24793</guid>
      <dc:creator>kobibi11</dc:creator>
      <dc:date>2021-08-22T19:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying SSL between Forwarder and Indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deploying-SSL-between-Forwarder-and-Indexer/m-p/564802#M24809</link>
      <description>&lt;P&gt;May I suggest using&amp;nbsp;&lt;A href="https://github.com/OpenVPN/easy-rsa" target="_blank"&gt;https://github.com/OpenVPN/easy-rsa&lt;/A&gt;?&lt;/P&gt;&lt;P&gt;The concept is like so:&lt;/P&gt;&lt;P&gt;- you generate a keypair for the client (SUF)&lt;/P&gt;&lt;P&gt;- you generate a keypair for the server (receiver, indexer etc.)&lt;/P&gt;&lt;P&gt;- the client and server each have the same CA cert&lt;/P&gt;&lt;P&gt;So three files on the server and three files on the client in a single file.&lt;/P&gt;&lt;P&gt;This is the simplest setup.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 22:44:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deploying-SSL-between-Forwarder-and-Indexer/m-p/564802#M24809</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2021-08-25T22:44:25Z</dc:date>
    </item>
  </channel>
</rss>

