<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sslKeysfilePassword not working in a deployed forwarder app in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/sslKeysfilePassword-not-working-in-a-deployed-forwarder-app/m-p/254767#M48941</link>
    <description>&lt;P&gt;I've created some certificates to use with our forwarders to secure forwarded traffic.  I've created an indexer_discovery app which contains outputs, a cert directory containing my certificate etc. but I've hit a snag...&lt;/P&gt;

&lt;P&gt;I also included app/local/server.conf with an [sslConfig] stanza containing the cert location, sslKeysfilePassword etc. but Splunk doesn't seem to read the password from this file.  After a forwarder restart the password remains unencrypted and the forwarder can't decrypt the cert producing lots of errors in splunkd.log.&lt;/P&gt;

&lt;P&gt;The only workaround is to modify /opt/splunkforwarder/etc/system/local/server.conf and add [sslConfig] with the sslKeysfilePassword parameter.  This means when we deploy the indexer discovery app we'll also need to login to each server to change the local server.conf file. &lt;/P&gt;

&lt;P&gt;Please tell me I'm doing it wrong &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jul 2016 14:11:16 GMT</pubDate>
    <dc:creator>stepheneardley</dc:creator>
    <dc:date>2016-07-13T14:11:16Z</dc:date>
    <item>
      <title>sslKeysfilePassword not working in a deployed forwarder app</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sslKeysfilePassword-not-working-in-a-deployed-forwarder-app/m-p/254767#M48941</link>
      <description>&lt;P&gt;I've created some certificates to use with our forwarders to secure forwarded traffic.  I've created an indexer_discovery app which contains outputs, a cert directory containing my certificate etc. but I've hit a snag...&lt;/P&gt;

&lt;P&gt;I also included app/local/server.conf with an [sslConfig] stanza containing the cert location, sslKeysfilePassword etc. but Splunk doesn't seem to read the password from this file.  After a forwarder restart the password remains unencrypted and the forwarder can't decrypt the cert producing lots of errors in splunkd.log.&lt;/P&gt;

&lt;P&gt;The only workaround is to modify /opt/splunkforwarder/etc/system/local/server.conf and add [sslConfig] with the sslKeysfilePassword parameter.  This means when we deploy the indexer discovery app we'll also need to login to each server to change the local server.conf file. &lt;/P&gt;

&lt;P&gt;Please tell me I'm doing it wrong &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 14:11:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sslKeysfilePassword-not-working-in-a-deployed-forwarder-app/m-p/254767#M48941</guid>
      <dc:creator>stepheneardley</dc:creator>
      <dc:date>2016-07-13T14:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: sslKeysfilePassword not working in a deployed forwarder app</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sslKeysfilePassword-not-working-in-a-deployed-forwarder-app/m-p/254768#M48942</link>
      <description>&lt;P&gt;You are indeed doing it wrong &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;The forwarder SSL doesn't use the server.conf file - it uses inputs.conf &amp;amp; outputs.conf.&lt;/P&gt;

&lt;P&gt;First go and read dwaddles SSL guides:&lt;BR /&gt;
&lt;A href="http://www.duanewaddle.com/splunk-conf-2014/"&gt;http://www.duanewaddle.com/splunk-conf-2014/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The relevant splunk documentation is here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/Security/ConfigureSplunkforwardingtousesignedcertificates"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/Security/ConfigureSplunkforwardingtousesignedcertificates&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 15:53:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sslKeysfilePassword-not-working-in-a-deployed-forwarder-app/m-p/254768#M48942</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2016-07-13T15:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: sslKeysfilePassword not working in a deployed forwarder app</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sslKeysfilePassword-not-working-in-a-deployed-forwarder-app/m-p/254769#M48943</link>
      <description>&lt;P&gt;I'm not saying you're wrong but if you are correct then why does SSL forwarding work when I move the sslKeysfilePassword parameter to etc/system/local/server.conf?  I can confirm that it also uses the cert we've pushed down with the app along with the cert location in server.conf within the app context.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 13:48:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sslKeysfilePassword-not-working-in-a-deployed-forwarder-app/m-p/254769#M48943</guid>
      <dc:creator>stepheneardley</dc:creator>
      <dc:date>2016-07-15T13:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: sslKeysfilePassword not working in a deployed forwarder app</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sslKeysfilePassword-not-working-in-a-deployed-forwarder-app/m-p/254770#M48944</link>
      <description>&lt;P&gt;Odd - I don't actually use the SSL forwarding myself, so I couldn't tell you for sure. My guess would be that when you put the parameter in system/local it gets ignored&lt;/P&gt;

&lt;P&gt;On your indexer run &lt;CODE&gt;./bin/splunk cmd btool inputs list&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;If you're using ssl you should have an input stanza  like &lt;CODE&gt;[splunktcp-ssl:9997]&lt;/CODE&gt;. If its &lt;CODE&gt;[splunktcp://9997]&lt;/CODE&gt; then you're not actually using SSL&lt;/P&gt;

&lt;P&gt;The server.conf controls the ssl settings for the splunkd port, 8089 &lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 16:07:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sslKeysfilePassword-not-working-in-a-deployed-forwarder-app/m-p/254770#M48944</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2016-07-15T16:07:44Z</dc:date>
    </item>
  </channel>
</rss>

