<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Forwarder SSL error - &amp;quot;SSL23_GET_CLIENT_HELLO:unknown protocol&amp;quot; in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308162#M58018</link>
    <description>&lt;P&gt;Since this "sslRootCAPath" is deprecated, you don't need it.  I would also be interested in seeing which instructions specified those settings as I don't see it in outputs.conf documentation.&lt;/P&gt;</description>
    <pubDate>Sat, 15 Jul 2017 18:56:43 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2017-07-15T18:56:43Z</dc:date>
    <item>
      <title>Splunk Forwarder SSL error - "SSL23_GET_CLIENT_HELLO:unknown protocol"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308157#M58013</link>
      <description>&lt;P&gt;I'm attempting to setup splunk enterprise in a docker container using the official splunk image. I have been unsuccessful in getting ssl from the forwarders to the indexer configured. As far as I can tell, my certs are fine. I've tried enabling further debugging, but none of the errors seem to point me in the right direction.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;indexer splunkd.log&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    07-15-2017 07:41:52.160 +0000 INFO  TcpInputConfig - IPv4 port 9997 is reserved for splunk 2 splunk (SSL)
    07-15-2017 07:41:52.161 +0000 INFO  TcpInputProc - Creating raw Acceptor for IPv4 port 1514 with Non-SSL
    07-15-2017 07:41:52.161 +0000 INFO  TcpInputProc - Creating fwd data Acceptor for IPv4 port 9997 with SSL
    07-15-2017 07:43:45.404 +0000 ERROR TcpInputProc - Error encountered for connection from src=10.101.21.34:36346. error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol
    07-15-2017 07:43:45.413 +0000 ERROR TcpInputProc - Error encountered for connection from src=10.101.21.34:36348. error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;indexer inputs.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#[default]
#host = splunkenterprise

[splunktcp-ssl:9997]
disabled=0

[SSL]
serverCert = /opt/splunk/etc/auth/splunk.cert.chain.pem
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;indexer inputs.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[general]
serverName = splunkenterprise
pass4SymmKey = $1$liNoIVdm5xPP

[sslConfig]
sslRootCAPath = /opt/splunk/etc/auth/intermediate-chain.cert.pem
sslPassword = $1$wW88fRIgrEHP

[lmpool:auto_generated_pool_download-trial]
description = auto_generated_pool_download-trial
quota = MAX
slaves = *
stack_id = download-trial

[lmpool:auto_generated_pool_forwarder]
description = auto_generated_pool_forwarder
quota = MAX
slaves = *
stack_id = forwarder

[lmpool:auto_generated_pool_free]
description = auto_generated_pool_free
quota = MAX
slaves = *
stack_id = free
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;forwarder outputs.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:group1]
server=splunk.mydomain.net:9997
disabled = 0

[tcpout:splunkssl]
sslRootCAPath = /etc/pki/ca-trust/source/anchors/intermediate-chain.cert.pem
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;forwarder server.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sslConfig]
sslRootCAPath = /etc/pki/ca-trust/source/anchors/intermediate-chain.cert.pem
sslPassword = $1$rCb/2hSpZ34D

[general]
pass4SymmKey = $1$+2qrhlHvLCwD

[lmpool:auto_generated_pool_forwarder]
description = auto_generated_pool_forwarder
quota = MAX
slaves = *
stack_id = forwarder

[lmpool:auto_generated_pool_free]
description = auto_generated_pool_free
quota = MAX
slaves = *
stack_id = free
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;/splunk cmd openssl s_client -connect splunk.mydomain.net:9997&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;New, TLSv1/SSLv3, Cipher is AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: zlib compression
Expansion: zlib compression
No ALPN negotiated
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : AES256-GCM-SHA384
    Session-ID: 443457B09EEBEE91F8B72DE5132E970CCDBD14D96A1BF5BE02FE34ED6EA631D9
    Session-ID-ctx:   
    Master-Key: B1D47C8F8EDD71D957E7BBC78B946B3FCFC4B6FB5B5527C3E16C6ADDE7C1DF7A6B950E8B2DC148EFCA4A70D88BC6035E
    Key-Arg   : None  
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 300 (seconds)
    TLS session ticket:
    0000 - d6 cc 25 7b f8 a9 96 eb-70 16 9c ce 01 99 7f 0e   ..%{....p.......
    0010 - fd 7d 06 ec 4f cc 9f 63-27 00 b4 c2 19 b7 fc c0   .}..O..c'.......
    0020 - e9 c5 0c 9c 2c 21 ed df-28 34 bd 4f 00 68 87 d2   ....,!..(4.O.h..
    0030 - b2 cc bb 2a ff 32 51 26-dc 4f 7d d8 36 94 ea 96   ...*.2Q&amp;amp;.O}.6...
    0040 - 74 d6 16 16 35 1e 3e c9-84 6c f0 c1 4a 3a 8d 7c   t...5.&amp;gt;..l..J:.|
    0050 - 1b 8d 67 bf 77 95 a2 1a-4a 4b df 2e 8a 12 4d fb   ..g.w...JK....M.
    0060 - 05 e5 39 74 28 2a 5a 35-39 70 57 09 f0 5c ac aa   ..9t(*Z59pW..\..
    0070 - 31 82 b1 42 24 8f 80 6e-6b a9 97 c5 31 2d e9 6a   1..B$..nk...1-.j
    0080 - c1 03 25 c0 27 53 90 b0-7d 2e 1a 1a a5 24 73 6c   ..%.'S..}....$sl
    0090 - 89 4e 3d f7 2d f7 dd 1c-ce 0c 65 36 f6 27 55 11   .N=.-.....e6.'U.

    Compression: 1 (zlib compression)
    Start Time: 1500105568
    Timeout   : 300 (sec)
    Verify return code: 19 (self signed certificate in certificate chain)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 15 Jul 2017 08:03:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308157#M58013</guid>
      <dc:creator>mjmayer</dc:creator>
      <dc:date>2017-07-15T08:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder SSL error - "SSL23_GET_CLIENT_HELLO:unknown protocol"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308158#M58014</link>
      <description>&lt;P&gt;Did you recently upgrade to 6.6.x?&lt;/P&gt;

&lt;P&gt;Do you have some older UFs?&lt;/P&gt;

&lt;P&gt;Are you using SSL on the UFs to communicate?&lt;/P&gt;

&lt;P&gt;If so, it sounds like the V2 vs V3 SSL problem that you can find several answers for here.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jul 2017 13:09:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308158#M58014</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-07-15T13:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder SSL error - "SSL23_GET_CLIENT_HELLO:unknown protocol"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308159#M58015</link>
      <description>&lt;P&gt;This is a new install of the indexer and forwarder. In my original configuration I was running 6.5.3 on the indexer and 6.6.0 for the forwarder.&lt;/P&gt;

&lt;P&gt;You did get me thinking. I was running indexer 6.5.3 and a 6.6.0 forwarder. I did bring the forwarder down to version 6.5.3, but I'm seeing the same errors.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jul 2017 15:09:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308159#M58015</guid>
      <dc:creator>mjmayer</dc:creator>
      <dc:date>2017-07-15T15:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder SSL error - "SSL23_GET_CLIENT_HELLO:unknown protocol"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308160#M58016</link>
      <description>&lt;P&gt;the server and ssl settings should be in the same tcpout stanza.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:group1]
server=splunk.mydomain.net:9997
clientCert = /etc/pki/ca-trust/source/anchors/intermediate-chain.cert.pem
sslPassword= clientCertPasswordIfApplicable
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 15 Jul 2017 16:17:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308160#M58016</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-07-15T16:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder SSL error - "SSL23_GET_CLIENT_HELLO:unknown protocol"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308161#M58017</link>
      <description>&lt;P&gt;Switching the outputs stanza as you advised to&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    [tcpout:group1]
    server=splunk.mydomain.net:9997
    disabled = 0
    sslRootCAPath = /etc/pki/ca-trust/source/anchors/intermediate-chain.cert.pem
    clientCert = /opt/splunkforwarder/etc/auth/splunk.mydomain.net.cert.pair.pem
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;worked. The client is now logging &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;7-15-2017 18:39:55.889 +0000 INFO  TcpOutputProc - Connected to idx=10.101.21.34:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The indexer is logging&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;07-15-2017 18:34:59.115 +0000 DEBUG TcpInputConfig - connection_host=ip for 10.101.21.34
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It does seem odd that the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.3/Security/ConfigureSplunkforwardingtousesignedcertificates"&gt;instructions&lt;/A&gt; show that it us supposed to be configured differently&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:group1]
server=10.1.1.197:9997
disabled = 0

[tcpout:splunkssl]
useClientSSLCompression = &amp;lt;true&amp;gt; Disabling tls compression can cause bandwidth issues.
sslPassword = The password for the CAcert
sslCommonNameToCheck = (Optional) &amp;lt;commonName1&amp;gt;, &amp;lt;commonName2&amp;gt;, ... sslVerifyServerCert must be enabled to use common name checking. Defaults to no common name checking. 
sslAltNameToCheck = (Optional) &amp;lt;alternateName1&amp;gt;, &amp;lt;alternateName2&amp;gt;, ... sslVerifyServerCert must be enabled to use common name checking. Defaults to no common name checking. 
sslVerifyServerCert =  Defaults to false. If true, you must make sure that the server you are connecting to can be authenticated to. When enabled, the common name and the alternate name of the server are checked.
cipherSuite = (Optional) Splunk uses any specified cipher string for the input processors. If not set, Splunk uses the default cipher string provided by OpenSSL.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 15 Jul 2017 18:50:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308161#M58017</guid>
      <dc:creator>mjmayer</dc:creator>
      <dc:date>2017-07-15T18:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder SSL error - "SSL23_GET_CLIENT_HELLO:unknown protocol"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308162#M58018</link>
      <description>&lt;P&gt;Since this "sslRootCAPath" is deprecated, you don't need it.  I would also be interested in seeing which instructions specified those settings as I don't see it in outputs.conf documentation.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jul 2017 18:56:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308162#M58018</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-07-15T18:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder SSL error - "SSL23_GET_CLIENT_HELLO:unknown protocol"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308163#M58019</link>
      <description>&lt;P&gt;If you can share a link,&lt;BR /&gt;
I can ask the author to revise.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jul 2017 18:57:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308163#M58019</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-07-15T18:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder SSL error - "SSL23_GET_CLIENT_HELLO:unknown protocol"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308164#M58020</link>
      <description>&lt;P&gt;Leave a &lt;CODE&gt;Comment&lt;/CODE&gt; at the bottom of the docs page telling them that the information is outdated/incorrect.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jul 2017 20:10:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308164#M58020</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-07-15T20:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder SSL error - "SSL23_GET_CLIENT_HELLO:unknown protocol"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308165#M58021</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.3/Security/ConfigureSplunkforwardingtousesignedcertificates"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.3/Security/ConfigureSplunkforwardingtousesignedcertificates&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jul 2017 14:33:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308165#M58021</guid>
      <dc:creator>mjmayer</dc:creator>
      <dc:date>2017-07-16T14:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder SSL error - "SSL23_GET_CLIENT_HELLO:unknown protocol"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308166#M58022</link>
      <description>&lt;P&gt;I submitted feedback.  Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jul 2017 15:26:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-SSL-error-quot-SSL23-GET-CLIENT-HELLO-unknown/m-p/308166#M58022</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-07-16T15:26:07Z</dc:date>
    </item>
  </channel>
</rss>

