<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error when enabling TLS for email. in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Error-when-enabling-TLS-for-email/m-p/566203#M12985</link>
    <description>&lt;P&gt;We recently updated our Splunk infrastructure to 8.1 and before we upgraded, the enable TLS option was checked on the mail server settings. The alert_actions.conf has not changed at all. Now for emails being sent, we receive the following error in the python.log:&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;sendemail:456&lt;/SPAN&gt; &lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN&gt;SSL:&lt;/SPAN&gt; &lt;SPAN&gt;SSLV3_ALERT_HANDSHAKE_FAILURE&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN&gt;sslv3&lt;/SPAN&gt; &lt;SPAN&gt;alert&lt;/SPAN&gt; &lt;SPAN&gt;handshake&lt;/SPAN&gt; &lt;SPAN&gt;failure&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN&gt;_ssl.c:742&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN&gt;while&lt;/SPAN&gt; &lt;SPAN&gt;sending&lt;/SPAN&gt; &lt;SPAN&gt;mail&lt;/SPAN&gt; &lt;SPAN&gt;to:&lt;/SPAN&gt;&amp;nbsp;&amp;lt;EMAIL_ADDRESS&amp;gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;If I manually add use_tls = 1 in that conf file, there are no errors, but if enabled on the web UI, it errors with the above.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I am not sure what else to check here as nothing has changed except for the upgrading of the Splunk version on the servers. Has anyone else experienced this?&lt;/DIV&gt;</description>
    <pubDate>Tue, 07 Sep 2021 19:17:31 GMT</pubDate>
    <dc:creator>hutsellmA</dc:creator>
    <dc:date>2021-09-07T19:17:31Z</dc:date>
    <item>
      <title>Error when enabling TLS for email.</title>
      <link>https://community.splunk.com/t5/Alerting/Error-when-enabling-TLS-for-email/m-p/566203#M12985</link>
      <description>&lt;P&gt;We recently updated our Splunk infrastructure to 8.1 and before we upgraded, the enable TLS option was checked on the mail server settings. The alert_actions.conf has not changed at all. Now for emails being sent, we receive the following error in the python.log:&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;sendemail:456&lt;/SPAN&gt; &lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN&gt;SSL:&lt;/SPAN&gt; &lt;SPAN&gt;SSLV3_ALERT_HANDSHAKE_FAILURE&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN&gt;sslv3&lt;/SPAN&gt; &lt;SPAN&gt;alert&lt;/SPAN&gt; &lt;SPAN&gt;handshake&lt;/SPAN&gt; &lt;SPAN&gt;failure&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN&gt;_ssl.c:742&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN&gt;while&lt;/SPAN&gt; &lt;SPAN&gt;sending&lt;/SPAN&gt; &lt;SPAN&gt;mail&lt;/SPAN&gt; &lt;SPAN&gt;to:&lt;/SPAN&gt;&amp;nbsp;&amp;lt;EMAIL_ADDRESS&amp;gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;If I manually add use_tls = 1 in that conf file, there are no errors, but if enabled on the web UI, it errors with the above.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I am not sure what else to check here as nothing has changed except for the upgrading of the Splunk version on the servers. Has anyone else experienced this?&lt;/DIV&gt;</description>
      <pubDate>Tue, 07 Sep 2021 19:17:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Error-when-enabling-TLS-for-email/m-p/566203#M12985</guid>
      <dc:creator>hutsellmA</dc:creator>
      <dc:date>2021-09-07T19:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Error when enabling TLS for email.</title>
      <link>https://community.splunk.com/t5/Alerting/Error-when-enabling-TLS-for-email/m-p/566221#M12987</link>
      <description>&lt;P&gt;Hi. Did you see this Splunk answers?&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Enterprise/Sendmail-sslv3-alert-handshake-failure/m-p/297554" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Enterprise/Sendmail-sslv3-alert-handshake-failure/m-p/297554&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Sounds like a possible cipher suite issue.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 22:14:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Error-when-enabling-TLS-for-email/m-p/566221#M12987</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2021-09-07T22:14:19Z</dc:date>
    </item>
  </channel>
</rss>

