<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I am looking for clarification on SSL compression settings in relation to security. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/I-am-looking-for-clarification-on-SSL-compression-settings-in/m-p/126154#M25969</link>
    <description>&lt;P&gt;I am also running into this concern with our use of Splunk in a Federal environment and CRIME vulnerabilities showing up. I read the same answer you linked, but there have been major changes since then. I haven't seen any official word on mitigating that risk. Even with SSL in general, even without browsers, the traffic can still be hijacked. &lt;/P&gt;</description>
    <pubDate>Wed, 30 Aug 2017 15:42:36 GMT</pubDate>
    <dc:creator>PhilipDudley</dc:creator>
    <dc:date>2017-08-30T15:42:36Z</dc:date>
    <item>
      <title>I am looking for clarification on SSL compression settings in relation to security.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-am-looking-for-clarification-on-SSL-compression-settings-in/m-p/126153#M25968</link>
      <description>&lt;P&gt;Security scans of my forwarders are alerting on "TLS CRIME". I have read the &lt;A href="http://answers.splunk.com/answers/65218/splunk-shows-vulnerable-to-cve-2012-4929-in-my-nessus-vulnerability-scan-what-is-going-on.html"&gt;Splunk Answer&lt;/A&gt; regarding this but I am a little bit unsatisfied with the answer. Basically they describe this as being a browser vulnerability, but everything I read seems to indicate that the remediation actions are to disable the use of SSL encryption. So I am unclear if SSL encryption is fundamentally flawed and is vulnerable regardless of whether it is web browser traffic.&lt;/P&gt;

&lt;P&gt;Splunk Answer: &lt;A href="http://answers.splunk.com/answers/65218/splunk-shows-vulnerable-to-cve-2012-4929-in-my-nessus-vulnerability-scan-what-is-going-on.html"&gt;http://answers.splunk.com/answers/65218/splunk-shows-vulnerable-to-cve-2012-4929-in-my-nessus-vulnerability-scan-what-is-going-on.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I have been told by multiple people at this point that SSL encryption in Splunk is best left enabled for performance reasons, so I want to leave it enabled, but I would like to have a better understanding of which SSL settings in server.conf do what exactly. Which setting actually controls the encryption of the logs being forwarded? I've been told to shut-off port 8089 on the forwarders, will that disable the ability to use a deployment manager? Is there a way I can keep compression on the log traffic and disable it on 8089 in a way that will not show up as a false positive on security scans?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2015 22:56:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-am-looking-for-clarification-on-SSL-compression-settings-in/m-p/126153#M25968</guid>
      <dc:creator>fd26645</dc:creator>
      <dc:date>2015-04-02T22:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: I am looking for clarification on SSL compression settings in relation to security.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-am-looking-for-clarification-on-SSL-compression-settings-in/m-p/126154#M25969</link>
      <description>&lt;P&gt;I am also running into this concern with our use of Splunk in a Federal environment and CRIME vulnerabilities showing up. I read the same answer you linked, but there have been major changes since then. I haven't seen any official word on mitigating that risk. Even with SSL in general, even without browsers, the traffic can still be hijacked. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 15:42:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-am-looking-for-clarification-on-SSL-compression-settings-in/m-p/126154#M25969</guid>
      <dc:creator>PhilipDudley</dc:creator>
      <dc:date>2017-08-30T15:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: I am looking for clarification on SSL compression settings in relation to security.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-am-looking-for-clarification-on-SSL-compression-settings-in/m-p/126155#M25970</link>
      <description>&lt;P&gt;In the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf&lt;/A&gt; , I would set the following options to false&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;useSSLCompression = false&lt;/LI&gt;
&lt;LI&gt;allowSslCompression = false&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;There'll be a few different stanzas depending on what you're disabling it on, but disabling Compression for each setting explicitly would probably help negate this since the options seem to change regularly. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 15:50:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-am-looking-for-clarification-on-SSL-compression-settings-in/m-p/126155#M25970</guid>
      <dc:creator>PhilipDudley</dc:creator>
      <dc:date>2017-08-30T15:50:10Z</dc:date>
    </item>
  </channel>
</rss>

