<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ES Glass Table not loading after activating requireClientCert in sslConfig (SSLError) in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ES-Glass-Table-not-loading-after-activating-requireClientCert-in/m-p/513511#M9120</link>
    <description>&lt;P&gt;Hi, did you manage to solve this issue? I am getting the same issue in another app.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Aug 2020 07:32:59 GMT</pubDate>
    <dc:creator>swati_singh</dc:creator>
    <dc:date>2020-08-11T07:32:59Z</dc:date>
    <item>
      <title>ES Glass Table not loading after activating requireClientCert in sslConfig (SSLError)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ES-Glass-Table-not-loading-after-activating-requireClientCert-in/m-p/491898#M8396</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have a problem with Splunk ES Glass Tables not loading when setting the requireClientCert=true in sslConfig. Of course I have the complete SSL setup working fine with sslVersions=tls1.2 using certificates singed by own CA.&lt;/P&gt;

&lt;P&gt;When trying to access the Glass Tables from ES menu, I get the following error message:&lt;/P&gt;

&lt;P&gt;HTTPSConnectionPool(host='127.0.0.1', port=8089): Max retries exceeded with url: /servicesNS/nobody/SplunkEnterpriseSecuritySuite/storage/collections/config/SplunkEnterpriseSecuritySuite_glasstables (Caused by SSLError(SSLError(1, u'[SSL: SSLV3_ALERT_HANDSHAKE_FAILURE] sslv3 alert handshake failure (_ssl.c:742)'),))&lt;/P&gt;

&lt;P&gt;p.s note: I have tried to add ssl3 to allowed list in sslVersions just to check if this is the problem but I end up with KVStore failure. However, this is not how I want to solve it.&lt;/P&gt;

&lt;P&gt;Thank you for your interactivity and responses in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:19:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ES-Glass-Table-not-loading-after-activating-requireClientCert-in/m-p/491898#M8396</guid>
      <dc:creator>tsmadi</dc:creator>
      <dc:date>2020-09-30T05:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: ES Glass Table not loading after activating requireClientCert in sslConfig (SSLError)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ES-Glass-Table-not-loading-after-activating-requireClientCert-in/m-p/513511#M9120</link>
      <description>&lt;P&gt;Hi, did you manage to solve this issue? I am getting the same issue in another app.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 07:32:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ES-Glass-Table-not-loading-after-activating-requireClientCert-in/m-p/513511#M9120</guid>
      <dc:creator>swati_singh</dc:creator>
      <dc:date>2020-08-11T07:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: ES Glass Table not loading after activating requireClientCert in sslConfig (SSLError)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ES-Glass-Table-not-loading-after-activating-requireClientCert-in/m-p/542686#M9762</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes, I did solve it.&lt;/P&gt;&lt;P&gt;After Splunk support failing to solve it, I had to act on my own.&lt;/P&gt;&lt;P&gt;I solved it and Splunk support asked me to show them the solution and after they saw it, they were supposed to modify it and register a bug on my name but unfortunately they didn't.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are still having this problem let me know and I will post the solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Mar 2021 12:36:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ES-Glass-Table-not-loading-after-activating-requireClientCert-in/m-p/542686#M9762</guid>
      <dc:creator>tsmadi</dc:creator>
      <dc:date>2021-03-06T12:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: ES Glass Table not loading after activating requireClientCert in sslConfig (SSLError)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ES-Glass-Table-not-loading-after-activating-requireClientCert-in/m-p/542910#M9771</link>
      <description>&lt;P&gt;Yes.&amp;nbsp; I am having an issue.&amp;nbsp; Please post the solution.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 20:52:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ES-Glass-Table-not-loading-after-activating-requireClientCert-in/m-p/542910#M9771</guid>
      <dc:creator>youngso</dc:creator>
      <dc:date>2021-03-08T20:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: ES Glass Table not loading after activating requireClientCert in sslConfig (SSLError)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ES-Glass-Table-not-loading-after-activating-requireClientCert-in/m-p/543180#M9772</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for taking so long to reply,&amp;nbsp; but Splunk support should have taken care of this issue long time ago!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As promised, the solution for this issue is to enable the client authentication to use the SSL certificates provided for inter-server communication (Splunk components within the server) because the server is forced to authenticate all communications when&amp;nbsp; &lt;SPAN&gt;requireClientCert=true&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;To enable this go to&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite/lib/SplunkEnterpriseSecuritySuite_app_common/solnlib/packages/requests/sessions.py&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Edit the file and modify the following Python tuple:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;self.cert = ("Path to CA", "Path to certificate")&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Save the file and restart splunk. The glass Tables should work now with no problem. However, you might need to troubleshoot other inter-Splunk communications based on your environment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/32102"&gt;@youngso&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/197166"&gt;@swati_singh&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Let me know how it goes!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 15:15:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ES-Glass-Table-not-loading-after-activating-requireClientCert-in/m-p/543180#M9772</guid>
      <dc:creator>tsmadi</dc:creator>
      <dc:date>2021-03-11T15:15:38Z</dc:date>
    </item>
  </channel>
</rss>

