<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I use self signed SSL with HEC? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-self-signed-SSL-with-HEC/m-p/613786#M106222</link>
    <description>&lt;P&gt;Similar to some other &lt;A href="https://community.splunk.com/t5/Getting-Data-In/SSL-connection-to-HEC-stops-working-with-self-signed-certificate/m-p/606548#M105376" target="_self"&gt;existing&lt;/A&gt; community posts, I am having issues sending POST requests to the https://.../services/collector/event endpoint of my Splunk enterprise server running on AWS after following Splunk guides on &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Security/Howtoself-signcertificates" target="_blank" rel="noopener"&gt;creating self signed ssl&lt;/A&gt; and using it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using -k in curl to skip insecure verify works, but including --cacert myselfsignedca does not. I've gone further and even added relevant x509 extensions like SANs with no success. The result from curl:&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;* successfully set certificate verify locations:&lt;BR /&gt;* CAfile: ./splunkCA.pem&lt;BR /&gt;CApath: /etc/ssl/certs&lt;BR /&gt;* TLSv1.3 (OUT), TLS handshake, Client hello (1):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Server hello (2):&lt;BR /&gt;* TLSv1.2 (IN), TLS handshake, Certificate (11):&lt;BR /&gt;* TLSv1.2 (OUT), TLS alert, Server hello (2):&lt;BR /&gt;* SSL certificate problem: self signed certificate in certificate chain&lt;BR /&gt;* stopped the pause stream!&lt;BR /&gt;* Closing connection 0&lt;BR /&gt;curl: (60) SSL certificate problem: self signed certificate in certificate chain&lt;BR /&gt;More details here: &lt;A href="https://curl.haxx.se/docs/sslcerts.html" target="_blank" rel="noopener"&gt;https://curl.haxx.se/docs/sslcerts.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;curl failed to verify the legitimacy of the server and therefore could not&lt;BR /&gt;establish a secure connection to it. To learn more about this situation and&lt;BR /&gt;how to fix it, please visit the web page mentioned above.&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help is appreciated!&lt;/P&gt;</description>
    <pubDate>Thu, 06 Oct 2022 23:49:33 GMT</pubDate>
    <dc:creator>andl24</dc:creator>
    <dc:date>2022-10-06T23:49:33Z</dc:date>
    <item>
      <title>How do I use self signed SSL with HEC?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-self-signed-SSL-with-HEC/m-p/613786#M106222</link>
      <description>&lt;P&gt;Similar to some other &lt;A href="https://community.splunk.com/t5/Getting-Data-In/SSL-connection-to-HEC-stops-working-with-self-signed-certificate/m-p/606548#M105376" target="_self"&gt;existing&lt;/A&gt; community posts, I am having issues sending POST requests to the https://.../services/collector/event endpoint of my Splunk enterprise server running on AWS after following Splunk guides on &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Security/Howtoself-signcertificates" target="_blank" rel="noopener"&gt;creating self signed ssl&lt;/A&gt; and using it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using -k in curl to skip insecure verify works, but including --cacert myselfsignedca does not. I've gone further and even added relevant x509 extensions like SANs with no success. The result from curl:&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;* successfully set certificate verify locations:&lt;BR /&gt;* CAfile: ./splunkCA.pem&lt;BR /&gt;CApath: /etc/ssl/certs&lt;BR /&gt;* TLSv1.3 (OUT), TLS handshake, Client hello (1):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Server hello (2):&lt;BR /&gt;* TLSv1.2 (IN), TLS handshake, Certificate (11):&lt;BR /&gt;* TLSv1.2 (OUT), TLS alert, Server hello (2):&lt;BR /&gt;* SSL certificate problem: self signed certificate in certificate chain&lt;BR /&gt;* stopped the pause stream!&lt;BR /&gt;* Closing connection 0&lt;BR /&gt;curl: (60) SSL certificate problem: self signed certificate in certificate chain&lt;BR /&gt;More details here: &lt;A href="https://curl.haxx.se/docs/sslcerts.html" target="_blank" rel="noopener"&gt;https://curl.haxx.se/docs/sslcerts.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;curl failed to verify the legitimacy of the server and therefore could not&lt;BR /&gt;establish a secure connection to it. To learn more about this situation and&lt;BR /&gt;how to fix it, please visit the web page mentioned above.&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help is appreciated!&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 23:49:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-self-signed-SSL-with-HEC/m-p/613786#M106222</guid>
      <dc:creator>andl24</dc:creator>
      <dc:date>2022-10-06T23:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Using self signed SSL with HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-self-signed-SSL-with-HEC/m-p/615798#M106442</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I don't know why, but it seems that quite many TA's etc. which are using HEC is requested valid official CA-signed certs not self signed. This is probably some kind of statement from Splunk side?&lt;/P&gt;&lt;P&gt;If I recall right there (or in slack) was some time ago one post where someone has succeed to use self signed cert with Splunk_TA_aws as adding own CA cert into local CA store on those hosts. Maybe that can help also you.&amp;nbsp;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-AWS-Problem-Does-anyone-know-how-to-disable/m-p/569418" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-AWS-Problem-Does-anyone-know-how-to-disable/m-p/569418&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Anyhow you should/could create a idea into ideas.splunk.com for this. I suppose quite many will vote it ;-?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 10:58:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-self-signed-SSL-with-HEC/m-p/615798#M106442</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-10-04T10:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Using self signed SSL with HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-self-signed-SSL-with-HEC/m-p/616242#M106477</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have the same issue running it locally with Docker, not just on AWS. Are self signed certs with HEC supposed to be supported?&lt;/P&gt;&lt;P&gt;ref:&amp;nbsp;&lt;A href="https://hub.docker.com/r/splunk/splunk" target="_blank"&gt;https://hub.docker.com/r/splunk/splunk&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 23:34:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-self-signed-SSL-with-HEC/m-p/616242#M106477</guid>
      <dc:creator>andl24</dc:creator>
      <dc:date>2022-10-06T23:34:57Z</dc:date>
    </item>
  </channel>
</rss>

