<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: secure splunk web with signed certificate in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322661#M93860</link>
    <description>&lt;P&gt;Are you having the intermediate certificate?!?!&lt;/P&gt;</description>
    <pubDate>Sun, 22 Oct 2017 10:15:30 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2017-10-22T10:15:30Z</dc:date>
    <item>
      <title>secure splunk web with signed certificate</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322656#M93855</link>
      <description>&lt;P&gt;I generate Key &amp;amp; csr files from my splunk machine&lt;BR /&gt;
then got the signed certificate from .pem &amp;amp; root , sub certificates , i put them in on single file in order&lt;/P&gt;

&lt;P&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;
... (certificate for your server)...&lt;BR /&gt;
-----END CERTIFICATE-----&lt;BR /&gt;
-----BEGIN CERTIFICATE-----&lt;BR /&gt;
... (the intermediate certificate)...&lt;BR /&gt;
-----END CERTIFICATE-----&lt;BR /&gt;
-----BEGIN CERTIFICATE-----&lt;BR /&gt;
... (the root certificate for the CA)...&lt;BR /&gt;
-----END CERTIFICATE-----&lt;/P&gt;

&lt;P&gt;also configured  web.conf to be like below&lt;/P&gt;

&lt;P&gt;[settings]&lt;BR /&gt;
enableSplunkWebSSL = true&lt;BR /&gt;
privKeyPath =  C:\Program Files\Splunk\etc\auth\mycerts\mySplunkWebPrivateKey.key&lt;BR /&gt;
serverCert =  C:\Program Files\Splunk\etc\auth\mycerts\mySplunkWebCert.pem&lt;/P&gt;

&lt;P&gt;but after trying to restart splunk service&lt;BR /&gt;
am waiting much time in starting web server process more than 10 min and i have to revert back my configuration to can access splunk GUI again&lt;BR /&gt;
anyone can help ?&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2017 08:28:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322656#M93855</guid>
      <dc:creator>MAShawky</dc:creator>
      <dc:date>2017-10-22T08:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: secure splunk web with signed certificate</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322657#M93856</link>
      <description>&lt;P&gt;when you start Splunk, did it show error or just showing Splunk web starting?&lt;/P&gt;

&lt;P&gt;Ensure, &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;privKeyPath
caCertPath
serverCert
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;are all reflected in  btool output of web.conf&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2017 09:12:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322657#M93856</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2017-10-22T09:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: secure splunk web with signed certificate</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322658#M93857</link>
      <description>&lt;P&gt;which path can i write in CAcert as i have only one .pem file ?&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2017 09:15:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322658#M93857</guid>
      <dc:creator>MAShawky</dc:creator>
      <dc:date>2017-10-22T09:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: secure splunk web with signed certificate</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322659#M93858</link>
      <description>&lt;P&gt;Are you having the intermediate certificate?!?!&lt;/P&gt;

&lt;P&gt;Troubleshoot your Splunk Web authentication&lt;BR /&gt;
If you are unable to verify your certificate configuration, you can use the web_service.log in $SPLUNK_HOME/var/log/splunk to view and troubleshoot any errors that occur upon restart.&lt;/P&gt;

&lt;P&gt;Look for SSL configuration warnings. For example, if you provide an incorrect path to the server certificate declared in serverCert, Splunk Web fails to start and the following error appears:&lt;/P&gt;

&lt;P&gt;2010-12-21 16:25:02,804 ERROR [4d11455df3182e6710] root:442 - [Errno 2] No such file or directory: '/opt/splunk/share/splunk/mycerts/mySplunkWebCertificate.pem'&lt;BR /&gt;
Note: If the private key is provided in privKeyPath is password protected, no error is provided but your browser won't load Splunk Web.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.0/Security/TroubleshootyourSplunkWebauthentication" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.0/Security/TroubleshootyourSplunkWebauthentication&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:22:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322659#M93858</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-09-29T16:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: secure splunk web with signed certificate</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322660#M93859</link>
      <description>&lt;P&gt;no warning in this file related to the certificate &lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2017 09:36:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322660#M93859</guid>
      <dc:creator>MAShawky</dc:creator>
      <dc:date>2017-10-22T09:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: secure splunk web with signed certificate</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322661#M93860</link>
      <description>&lt;P&gt;Are you having the intermediate certificate?!?!&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2017 10:15:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322661#M93860</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-10-22T10:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: secure splunk web with signed certificate</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322662#M93861</link>
      <description>&lt;P&gt;yes I have ca-root &amp;amp; ca-subcertificate &amp;amp; webserver certificate&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2017 10:22:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322662#M93861</guid>
      <dc:creator>MAShawky</dc:creator>
      <dc:date>2017-10-22T10:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: secure splunk web with signed certificate</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322663#M93862</link>
      <description>&lt;P&gt;Can you confirm that you have put all the certificates in your .pem file? &lt;/P&gt;

&lt;P&gt;Also can you check what error are you getting in Splunkd.log when you start your Splunk with this configurations?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 06:01:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/secure-splunk-web-with-signed-certificate/m-p/322663#M93862</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2017-10-23T06:01:47Z</dc:date>
    </item>
  </channel>
</rss>

