<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Smartstore configuration : How to encrypt volume definitions and use bundle deployment? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588028#M8739</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Seriously ?&lt;/P&gt;&lt;P&gt;Wow, that's weird...&lt;/P&gt;&lt;P&gt;Ema&lt;/P&gt;</description>
    <pubDate>Tue, 08 Mar 2022 13:34:01 GMT</pubDate>
    <dc:creator>emallinger</dc:creator>
    <dc:date>2022-03-08T13:34:01Z</dc:date>
    <item>
      <title>Smartstore configuration : How to encrypt volume definitions and use bundle deployment?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/587848#M8733</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I would like to have confirmation of the best secure way to create smartstore volume (with access keys) : how will bundle validation behave if :?&lt;BR /&gt;- I declare volumes (with access_keys) in /opt/splunk/etc/apps/myvolumes/local/indexes.conf ON each indexers&lt;BR /&gt;- I push the indexes definitions (with those volumes) in /opt/splunk/etc/master-apps/myindexes/local/indexes.conf from the Cluster Master&lt;/P&gt;
&lt;P&gt;Protocol would be : maintenance mode, stop every indexers, deploy new conf files via git (and finalize manually for the volume keys not to appear in git), validate bundle on the CM&lt;/P&gt;
&lt;P&gt;=&amp;gt; Will it even work as there is no volume definition on the CM in /opt/splunk/etc/master-apps/myindexes/local/indexes.conf ?&lt;/P&gt;
&lt;P&gt;There is something I do not understand : How am I supposed to secure (encrypt ?) the access keys in the cluster AND use the CM for bundle deployment ?&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Ema&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 04:53:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/587848#M8733</guid>
      <dc:creator>emallinger</dc:creator>
      <dc:date>2022-03-08T04:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Smartstore configuration : How to encrypt volume definitions and use bundle deployment?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588027#M8738</link>
      <description>&lt;P&gt;Unlike pass4SymmKey, S3 access and secret keys are not stored in encrypted form.&amp;nbsp; That means you can deploy they keys from the CM without concern for how they will be saved on the indexers.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 13:26:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588027#M8738</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-03-08T13:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Smartstore configuration : How to encrypt volume definitions and use bundle deployment?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588028#M8739</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Seriously ?&lt;/P&gt;&lt;P&gt;Wow, that's weird...&lt;/P&gt;&lt;P&gt;Ema&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 13:34:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588028#M8739</guid>
      <dc:creator>emallinger</dc:creator>
      <dc:date>2022-03-08T13:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Smartstore configuration : How to encrypt volume definitions and use bundle deployment?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588052#M8740</link>
      <description>&lt;P&gt;Yes, I was serious, because the documentation says nothing about access keys being encrypted (unlike pass4SymmKey).&lt;/P&gt;&lt;P&gt;I took a look at one of my sandboxes, however, and see that &lt;FONT face="courier new,courier"&gt;remote.s3.access_key&lt;/FONT&gt; and &lt;FONT face="courier new,courier"&gt;remote.s3.secret_key&lt;/FONT&gt; are both encrypted.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 15:33:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588052#M8740</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-03-08T15:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: Smartstore configuration : How to encrypt volume definitions and use bundle deployment?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588053#M8741</link>
      <description>&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;Is your sandbox clustered with a cluster master ?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ema&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 15:37:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588053#M8741</guid>
      <dc:creator>emallinger</dc:creator>
      <dc:date>2022-03-08T15:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: Smartstore configuration : How to encrypt volume definitions and use bundle deployment?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588064#M8742</link>
      <description>&lt;P&gt;My sandbox is not clustered, but that should not affect how the keys are stored.&lt;/P&gt;&lt;P&gt;You don't have to put all indexes in SmartStore so test it out with an index you create for that purpose.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 16:10:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588064#M8742</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-03-08T16:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Smartstore configuration : How to encrypt volume definitions and use bundle deployment?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588089#M8743</link>
      <description>&lt;P&gt;Yeah, that I did already : and the access-key transmitted in the bundle are still clear and not encrypted on the Cluster Master AND on all the indexers.&lt;/P&gt;&lt;P&gt;It's not very satisfactory to keep it that way.&lt;/P&gt;&lt;P&gt;Hence me asking for suggestions.&lt;/P&gt;&lt;P&gt;Ema&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 17:08:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Smartstore-configuration-How-to-encrypt-volume-definitions-and/m-p/588089#M8743</guid>
      <dc:creator>emallinger</dc:creator>
      <dc:date>2022-03-08T17:08:33Z</dc:date>
    </item>
  </channel>
</rss>

