<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: deploy server.conf via deployment server and point individual ssl certs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/deploy-server-conf-via-deployment-server-and-point-individual/m-p/324552#M60401</link>
    <description>&lt;P&gt;Hi garethatiag &lt;/P&gt;

&lt;P&gt;I do not understand&lt;/P&gt;

&lt;P&gt;I am trying to push the individual pem files for my clients on the deployment server to the client servers. plus edit the indivdual client server's server.conf to point to the respective cert.&lt;/P&gt;

&lt;P&gt;do i edit the put these files in the deployment server's splunk_home\etc\deployment-apps\myserverconfigindexgroup\server1.pem to push the pem certificate for server1.pem down to server1? &lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2017 12:34:23 GMT</pubDate>
    <dc:creator>leonaheidern</dc:creator>
    <dc:date>2017-10-24T12:34:23Z</dc:date>
    <item>
      <title>deploy server.conf via deployment server and point individual ssl certs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/deploy-server-conf-via-deployment-server-and-point-individual/m-p/324550#M60399</link>
      <description>&lt;P&gt;hi all&lt;/P&gt;

&lt;P&gt;I am a splunk noob.&lt;/P&gt;

&lt;P&gt;I have created individual server.pem files that are sha256 compliant from my windows ca&lt;/P&gt;

&lt;P&gt;my deployment server and clients are mostly windows&lt;/P&gt;

&lt;P&gt;the clients ( servers with universalforwarder installed) were individually installed.&lt;/P&gt;

&lt;P&gt;my environment is using 6.5.3&lt;/P&gt;

&lt;P&gt;i am trying to push a hardened server.conf with the sslconfig pointing to each individual servers pem file from the deployment server. &lt;/P&gt;

&lt;P&gt;Is there any way i can do that&lt;/P&gt;

&lt;P&gt;e.g. in the deploymentserver\etc\deployment-apps\appname\local\server.confs&lt;/P&gt;

&lt;P&gt;can i put the server.conf file this way?&lt;/P&gt;

&lt;P&gt;[general]&lt;BR /&gt;
servername= server1&lt;/P&gt;

&lt;P&gt;[sslconfig]&lt;BR /&gt;
allowsslcompression=false&lt;BR /&gt;
sslversions = tls1.1, tls1.2&lt;BR /&gt;
requireclientcert=false&lt;BR /&gt;
enablesplunkdssl=true&lt;BR /&gt;
sslkey files=server1.pem&lt;BR /&gt;
sslkeysfilepassword=password&lt;BR /&gt;
caPath=$splunk_home\etc\auth&lt;BR /&gt;
sslPassword=password&lt;/P&gt;

&lt;P&gt;[general]&lt;BR /&gt;
servername= server2&lt;/P&gt;

&lt;P&gt;[sslconfig]&lt;BR /&gt;
allowsslcompression=false&lt;BR /&gt;
sslversions = tls1.1, tls1.2&lt;BR /&gt;
requireclientcert=false&lt;BR /&gt;
enablesplunkdssl=true&lt;BR /&gt;
sslkey files=server2.pem&lt;BR /&gt;
sslkeysfilepassword=password&lt;BR /&gt;
caPath=$splunk_home\etc\auth&lt;BR /&gt;
sslPassword=password&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 05:42:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/deploy-server-conf-via-deployment-server-and-point-individual/m-p/324550#M60399</guid>
      <dc:creator>leonaheidern</dc:creator>
      <dc:date>2017-10-24T05:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: deploy server.conf via deployment server and point individual ssl certs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/deploy-server-conf-via-deployment-server-and-point-individual/m-p/324551#M60400</link>
      <description>&lt;P&gt;The documentation for &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Security/AboutsecuringyourSplunkconfigurationwithSSL"&gt;securing Splunk with SSL&lt;/A&gt; in particular the section about securing the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Security/Securingyourdeploymentserverandclients"&gt;deployment server and clients&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You do not need to override all the configuration, only the relevant parts that you are changing as per the documentation...&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 10:39:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/deploy-server-conf-via-deployment-server-and-point-individual/m-p/324551#M60400</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-10-24T10:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: deploy server.conf via deployment server and point individual ssl certs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/deploy-server-conf-via-deployment-server-and-point-individual/m-p/324552#M60401</link>
      <description>&lt;P&gt;Hi garethatiag &lt;/P&gt;

&lt;P&gt;I do not understand&lt;/P&gt;

&lt;P&gt;I am trying to push the individual pem files for my clients on the deployment server to the client servers. plus edit the indivdual client server's server.conf to point to the respective cert.&lt;/P&gt;

&lt;P&gt;do i edit the put these files in the deployment server's splunk_home\etc\deployment-apps\myserverconfigindexgroup\server1.pem to push the pem certificate for server1.pem down to server1? &lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 12:34:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/deploy-server-conf-via-deployment-server-and-point-individual/m-p/324552#M60401</guid>
      <dc:creator>leonaheidern</dc:creator>
      <dc:date>2017-10-24T12:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: deploy server.conf via deployment server and point individual ssl certs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/deploy-server-conf-via-deployment-server-and-point-individual/m-p/324553#M60402</link>
      <description>&lt;P&gt;If your happy with all your clients using a common SSL file then pushing from the deployment server is going to be an easy way to do this...&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 01:12:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/deploy-server-conf-via-deployment-server-and-point-individual/m-p/324553#M60402</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-10-30T01:12:48Z</dc:date>
    </item>
  </channel>
</rss>

