<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Universal Forwarder, 8089 management port SSL certificate expired in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-8089-management-port-SSL-certificate/m-p/162539#M33003</link>
    <description>&lt;P&gt;I downvoted this post because no solution - not an answer&lt;/P&gt;</description>
    <pubDate>Fri, 31 Mar 2017 14:21:45 GMT</pubDate>
    <dc:creator>nurtdi</dc:creator>
    <dc:date>2017-03-31T14:21:45Z</dc:date>
    <item>
      <title>Splunk Universal Forwarder, 8089 management port SSL certificate expired</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-8089-management-port-SSL-certificate/m-p/162536#M33000</link>
      <description>&lt;P&gt;As the Splunk Universal Forwarder installed &lt;STRONG&gt;3 yrs ago&lt;/STRONG&gt; (1,094 days) &amp;amp; it doesn't upgraded. &lt;/P&gt;

&lt;P&gt;The &lt;STRONG&gt;SSL certificate&lt;/STRONG&gt; used in &lt;STRONG&gt;8089 management&lt;/STRONG&gt; port will be expired &amp;amp; be changelled by auditors.&lt;/P&gt;

&lt;P&gt;According to the &lt;STRONG&gt;nrpeter's&lt;/STRONG&gt; comment in below URL, the &lt;STRONG&gt;server.pem&lt;/STRONG&gt; (used for the SSL certification) located in &lt;STRONG&gt;/opt/splunkforwarder/etc/auth&lt;/STRONG&gt; will be recreated while it's missing when &lt;STRONG&gt;Splunkd start&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/33308/splunk-fowarder-ssl-error-error-tcpoutputproc.html"&gt;http://answers.splunk.com/answers/33308/splunk-fowarder-ssl-error-error-tcpoutputproc.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;As a result, except to upgrade the Splunk Universal Forwarder to latest version, we could remove the &lt;STRONG&gt;server.pem&lt;/STRONG&gt; and &lt;STRONG&gt;restart&lt;/STRONG&gt; the Splunk UF.&lt;/P&gt;

&lt;P&gt;And we could use below command to check the renewed certification information. Hope this help.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;command&lt;/STRONG&gt;:&lt;BR /&gt;
&lt;EM&gt;/usr/bin/openssl s_client -connect localhost:8089&lt;/EM&gt;&lt;BR /&gt;
OR &lt;BR /&gt;
&lt;EM&gt;/usr/bin/openssl s_client -connect 127.0.0.1:8089&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;And the results could be checked by below online services.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Decode SSL certificate Online&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="https://www.trustico.com/ssltools/decode/certificate-pem/decode-certificate.php"&gt;https://www.trustico.com/ssltools/decode/certificate-pem/decode-certificate.php&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2015 09:27:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-8089-management-port-SSL-certificate/m-p/162536#M33000</guid>
      <dc:creator>rossikwan</dc:creator>
      <dc:date>2015-03-03T09:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder, 8089 management port SSL certificate expired</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-8089-management-port-SSL-certificate/m-p/162537#M33001</link>
      <description>&lt;P&gt;self solved&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2015 09:28:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-8089-management-port-SSL-certificate/m-p/162537#M33001</guid>
      <dc:creator>rossikwan</dc:creator>
      <dc:date>2015-03-03T09:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder, 8089 management port SSL certificate expired</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-8089-management-port-SSL-certificate/m-p/162538#M33002</link>
      <description>&lt;P&gt;I downvoted this post because no solution given.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 03:17:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-8089-management-port-SSL-certificate/m-p/162538#M33002</guid>
      <dc:creator>bdavistsp</dc:creator>
      <dc:date>2016-10-07T03:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder, 8089 management port SSL certificate expired</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-8089-management-port-SSL-certificate/m-p/162539#M33003</link>
      <description>&lt;P&gt;I downvoted this post because no solution - not an answer&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 14:21:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-8089-management-port-SSL-certificate/m-p/162539#M33003</guid>
      <dc:creator>nurtdi</dc:creator>
      <dc:date>2017-03-31T14:21:45Z</dc:date>
    </item>
  </channel>
</rss>

