<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Universal Forwarder hosts - How do I replace self-signed SSL cert with one from LetsEncrypt on Debian &amp;amp; Ubuntu? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-hosts-How-do-I-replace-self-signed-SSL-cert/m-p/622738#M12136</link>
    <description>&lt;P&gt;Tenable.io is alerting on all my splunk universal forwarder client hosts (Debian &amp;amp; Ubuntu)&lt;/P&gt;&lt;P&gt;It is seeing port 8089 on these hosts (probably the management port??) and throwing this error:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;The following certificate was found at the top of the certificate&lt;BR /&gt;chain sent by the remote host, but is self-signed and was not&lt;BR /&gt;found in the list of known certificate authorities :&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;|-Subject : C=US/ST=CA/L=San Francisco/O=Splunk/CN=SplunkCommonCA/E=support@splunk.com&lt;/P&gt;&lt;P&gt;I dont need to encypt splunk commuications from universal forwarder to splunk server, I just want Tenable to see a signed cert on this port so it doesnt complain. Where is this file and can I replace it with my fullchain.pem from Letsencrypt that is already elsewhere on this host?&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Nov 2022 20:40:43 GMT</pubDate>
    <dc:creator>mbw</dc:creator>
    <dc:date>2022-11-30T20:40:43Z</dc:date>
    <item>
      <title>Universal Forwarder hosts - How do I replace self-signed SSL cert with one from LetsEncrypt on Debian &amp; Ubuntu?</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-hosts-How-do-I-replace-self-signed-SSL-cert/m-p/622738#M12136</link>
      <description>&lt;P&gt;Tenable.io is alerting on all my splunk universal forwarder client hosts (Debian &amp;amp; Ubuntu)&lt;/P&gt;&lt;P&gt;It is seeing port 8089 on these hosts (probably the management port??) and throwing this error:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;The following certificate was found at the top of the certificate&lt;BR /&gt;chain sent by the remote host, but is self-signed and was not&lt;BR /&gt;found in the list of known certificate authorities :&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;|-Subject : C=US/ST=CA/L=San Francisco/O=Splunk/CN=SplunkCommonCA/E=support@splunk.com&lt;/P&gt;&lt;P&gt;I dont need to encypt splunk commuications from universal forwarder to splunk server, I just want Tenable to see a signed cert on this port so it doesnt complain. Where is this file and can I replace it with my fullchain.pem from Letsencrypt that is already elsewhere on this host?&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 20:40:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-hosts-How-do-I-replace-self-signed-SSL-cert/m-p/622738#M12136</guid>
      <dc:creator>mbw</dc:creator>
      <dc:date>2022-11-30T20:40:43Z</dc:date>
    </item>
  </channel>
</rss>

