<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sslRootCAPath at server.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/sslRootCAPath-at-server-conf/m-p/359298#M65554</link>
    <description>&lt;P&gt;SSL is already complex one, this poor documentation adds the &lt;STRONG&gt;fuel to the fire&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.4.4/Security/ConfigureSplunkforwardingtousesignedcertificates"&gt;https://docs.splunk.com/Documentation/Splunk/6.4.4/Security/ConfigureSplunkforwardingtousesignedcertificates&lt;/A&gt;&lt;BR /&gt;
this says, we should update server.conf with sslRootCAPath  info, but when splunkd restarts, it says the other way around. &lt;/P&gt;

&lt;P&gt;[root@UF /app/JE0/splunkforwarder/etc/twoCerts]#/app/splunkforwarder/bin/splunk restart&lt;BR /&gt;
Stopping splunkd...&lt;BR /&gt;
Shutting down.  Please wait, as this may take a few minutes.&lt;BR /&gt;
............                                               [  OK  ]&lt;BR /&gt;
Stopping splunk helpers...&lt;BR /&gt;
                                                           [  OK  ]&lt;BR /&gt;
Done.&lt;/P&gt;

&lt;P&gt;Splunk&amp;gt; All batbelt. No tights.&lt;/P&gt;

&lt;P&gt;Checking prerequisites...&lt;BR /&gt;
        Checking mgmt port [8089]: open&lt;BR /&gt;
        Checking conf files for problems...&lt;BR /&gt;
                *&lt;EM&gt;Invalid key in stanza [sslConfig] in /app/splunkforwarder/etc/system/local/server.conf, line 19: sslRootCAPath  (value:  /app/splunkforwarder/etc/twoCerts/cacert.pem). *&lt;/EM&gt;&lt;BR /&gt;
                Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'&lt;BR /&gt;
        Done&lt;BR /&gt;
        Checking default conf files for edits...&lt;BR /&gt;
        Validating installed files against hashes from '/app/splunkforwarder/splunkforwarder-6.3.4-cae2458f4aef-linux-2.6-x86_64-manifest'&lt;BR /&gt;
        All installed files intact.&lt;BR /&gt;
        Done&lt;BR /&gt;
All preliminary checks passed.&lt;/P&gt;

&lt;P&gt;Starting splunk server daemon (splunkd)...&lt;BR /&gt;
Done&lt;BR /&gt;
                                                           [  OK  ]&lt;BR /&gt;
[root@UF /app/splunkforwarder/etc/twoCerts]#&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jun 2017 13:29:50 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2017-06-20T13:29:50Z</dc:date>
    <item>
      <title>sslRootCAPath at server.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sslRootCAPath-at-server-conf/m-p/359298#M65554</link>
      <description>&lt;P&gt;SSL is already complex one, this poor documentation adds the &lt;STRONG&gt;fuel to the fire&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.4.4/Security/ConfigureSplunkforwardingtousesignedcertificates"&gt;https://docs.splunk.com/Documentation/Splunk/6.4.4/Security/ConfigureSplunkforwardingtousesignedcertificates&lt;/A&gt;&lt;BR /&gt;
this says, we should update server.conf with sslRootCAPath  info, but when splunkd restarts, it says the other way around. &lt;/P&gt;

&lt;P&gt;[root@UF /app/JE0/splunkforwarder/etc/twoCerts]#/app/splunkforwarder/bin/splunk restart&lt;BR /&gt;
Stopping splunkd...&lt;BR /&gt;
Shutting down.  Please wait, as this may take a few minutes.&lt;BR /&gt;
............                                               [  OK  ]&lt;BR /&gt;
Stopping splunk helpers...&lt;BR /&gt;
                                                           [  OK  ]&lt;BR /&gt;
Done.&lt;/P&gt;

&lt;P&gt;Splunk&amp;gt; All batbelt. No tights.&lt;/P&gt;

&lt;P&gt;Checking prerequisites...&lt;BR /&gt;
        Checking mgmt port [8089]: open&lt;BR /&gt;
        Checking conf files for problems...&lt;BR /&gt;
                *&lt;EM&gt;Invalid key in stanza [sslConfig] in /app/splunkforwarder/etc/system/local/server.conf, line 19: sslRootCAPath  (value:  /app/splunkforwarder/etc/twoCerts/cacert.pem). *&lt;/EM&gt;&lt;BR /&gt;
                Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'&lt;BR /&gt;
        Done&lt;BR /&gt;
        Checking default conf files for edits...&lt;BR /&gt;
        Validating installed files against hashes from '/app/splunkforwarder/splunkforwarder-6.3.4-cae2458f4aef-linux-2.6-x86_64-manifest'&lt;BR /&gt;
        All installed files intact.&lt;BR /&gt;
        Done&lt;BR /&gt;
All preliminary checks passed.&lt;/P&gt;

&lt;P&gt;Starting splunk server daemon (splunkd)...&lt;BR /&gt;
Done&lt;BR /&gt;
                                                           [  OK  ]&lt;BR /&gt;
[root@UF /app/splunkforwarder/etc/twoCerts]#&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 13:29:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sslRootCAPath-at-server-conf/m-p/359298#M65554</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-06-20T13:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: sslRootCAPath at server.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sslRootCAPath-at-server-conf/m-p/359299#M65555</link>
      <description>&lt;P&gt;Hi inventsekar, &lt;/P&gt;

&lt;P&gt;there is a parameter named &lt;CODE&gt;caCertPath&lt;/CODE&gt; which is depreciated in recent splunk versions, but served as the &lt;CODE&gt;sslRootCAPath&lt;/CODE&gt; parameter in past splunk versions.&lt;/P&gt;

&lt;P&gt;You seem to use a splunkforwarder with the version 6.3.4. In this version &lt;CODE&gt;caCertPath&lt;/CODE&gt; should work.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 14:00:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sslRootCAPath-at-server-conf/m-p/359299#M65555</guid>
      <dc:creator>horsefez</dc:creator>
      <dc:date>2017-06-20T14:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: sslRootCAPath at server.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sslRootCAPath-at-server-conf/m-p/359300#M65556</link>
      <description>&lt;P&gt;Thanks Pyro_wood, &lt;BR /&gt;
sslRootCAPath works fine, but on inputs.conf file(not server.conf). &lt;/P&gt;

&lt;P&gt;the document should be updated properly. if "SSL" is not updated properly, how a simple user can read this document and deploy SSL ?!?!?! hope splunk guys will check this and update soon. &lt;BR /&gt;
the wiki.splunk on SSL also got multiple issues. &lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 00:09:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sslRootCAPath-at-server-conf/m-p/359300#M65556</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-06-21T00:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: sslRootCAPath at server.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sslRootCAPath-at-server-conf/m-p/359301#M65557</link>
      <description>&lt;P&gt;Two pitfalls to watch out for:&lt;/P&gt;

&lt;P&gt;2) The 'deprecated' settings don't appear to be really deprecated.  Using v7.0.0, I still have to set caCertFile.  If I try to set sslRootCAPath I get error "setting ignored under Windows".  The Splunk docs for v7.0.0 say caCertFile is deprecated, but in practice it's not.&lt;/P&gt;

&lt;P&gt;2) Splunk's SSL handling is intolerant of extra lines in PEM files.  For example, if you start with a certificate in PFX and export to PEM, you end up with a lot of 'bag attributes' in the output PEM file.  They look like comments in between the actual certificates.  You have to manually strip out those lines so that the PEM file only contains lines that are either BEGIN, END, or Base64 encoded.&lt;/P&gt;

&lt;P&gt;edit: Splunk appears to have fixed the sslRootCAPath problem in  &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.2/ReleaseNotes/Fixedissues"&gt;v7.1.2&lt;/A&gt;:&lt;BR /&gt;
2018-06-15&lt;BR /&gt;
SPL-149190, SPL-141808&lt;BR /&gt;
(Windows Only) Support sslRootCAPath on Windows&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 21:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sslRootCAPath-at-server-conf/m-p/359301#M65557</guid>
      <dc:creator>satyenshah</dc:creator>
      <dc:date>2018-05-10T21:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: sslRootCAPath at server.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sslRootCAPath-at-server-conf/m-p/579908#M102347</link>
      <description>&lt;P&gt;Agreed, this is misleading.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 17:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sslRootCAPath-at-server-conf/m-p/579908#M102347</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2022-01-04T17:55:48Z</dc:date>
    </item>
  </channel>
</rss>

