<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I change the Common Name (CN) = SplunkServerDefaultCert to the hostname? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-change-the-Common-Name-CN-SplunkServerDefaultCert-to/m-p/166301#M47363</link>
    <description>&lt;P&gt;Hello Admins,&lt;/P&gt;

&lt;P&gt;Can you help us on how to use the self-signed certs, so that i think we could see this issue in depth,&lt;BR /&gt;
I believe the problem occurs with the default Installation package which has the default certs, (i am not sure).&lt;/P&gt;

&lt;P&gt;Any help in providing the installation guide for the  linux setup with certs would certainly help me to start with this..&lt;/P&gt;

&lt;P&gt;Thank you in advance.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Venu&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2015 06:40:44 GMT</pubDate>
    <dc:creator>SandzVG</dc:creator>
    <dc:date>2015-04-28T06:40:44Z</dc:date>
    <item>
      <title>How do I change the Common Name (CN) = SplunkServerDefaultCert to the hostname?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-change-the-Common-Name-CN-SplunkServerDefaultCert-to/m-p/166300#M47362</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Splunk cert shows up in our vulnerability report, &lt;/P&gt;

&lt;P&gt;The Subject Common Name (CN) found in the X.509 cert doesn't seem to match scan target xx.xx.xx.xx (IP)&lt;/P&gt;

&lt;P&gt;More details &lt;BR /&gt;
Subject CN SplunkServerDefaultCert doesnt match the node name XX.XX.XX.XX (IP)&lt;BR /&gt;
Subject CN SplunkServerDefaultCert doesnt match the DNS name &lt;BR /&gt;
Subject CN SplunkServerDefaultCert could not be resolved to an IP address via DNS Lookup.&lt;/P&gt;

&lt;P&gt;I'm new to splunk, so requesting admins here on how I could change the CN = SplunkServerDefaultCert to the hostname?&lt;/P&gt;

&lt;P&gt;Any help is highly appreciated.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Venu&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2015 05:14:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-change-the-Common-Name-CN-SplunkServerDefaultCert-to/m-p/166300#M47362</guid>
      <dc:creator>SandzVG</dc:creator>
      <dc:date>2015-04-27T05:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change the Common Name (CN) = SplunkServerDefaultCert to the hostname?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-change-the-Common-Name-CN-SplunkServerDefaultCert-to/m-p/166301#M47363</link>
      <description>&lt;P&gt;Hello Admins,&lt;/P&gt;

&lt;P&gt;Can you help us on how to use the self-signed certs, so that i think we could see this issue in depth,&lt;BR /&gt;
I believe the problem occurs with the default Installation package which has the default certs, (i am not sure).&lt;/P&gt;

&lt;P&gt;Any help in providing the installation guide for the  linux setup with certs would certainly help me to start with this..&lt;/P&gt;

&lt;P&gt;Thank you in advance.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Venu&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 06:40:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-change-the-Common-Name-CN-SplunkServerDefaultCert-to/m-p/166301#M47363</guid>
      <dc:creator>SandzVG</dc:creator>
      <dc:date>2015-04-28T06:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change the Common Name (CN) = SplunkServerDefaultCert to the hostname?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-change-the-Common-Name-CN-SplunkServerDefaultCert-to/m-p/166302#M47364</link>
      <description>&lt;P&gt;Hello Admins,&lt;/P&gt;

&lt;P&gt;Could you please provide a way to raise a support case with you guys for investigation. I think this is getting no where.&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2015 05:43:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-change-the-Common-Name-CN-SplunkServerDefaultCert-to/m-p/166302#M47364</guid>
      <dc:creator>SandzVG</dc:creator>
      <dc:date>2015-05-05T05:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change the Common Name (CN) = SplunkServerDefaultCert to the hostname?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-change-the-Common-Name-CN-SplunkServerDefaultCert-to/m-p/166303#M47365</link>
      <description>&lt;P&gt;Ok, then.. after parsing all the .pem files, i found this &lt;/P&gt;

&lt;P&gt;the &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder\etc\auth\server.pem
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;contains the Subject: CN=SplunkServerDefaultCert, O=SplunkUser&lt;/P&gt;

&lt;P&gt;Now i need to re-generate keeping intact the other certs that ship along... any ideas?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Venu&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2015 11:28:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-change-the-Common-Name-CN-SplunkServerDefaultCert-to/m-p/166303#M47365</guid>
      <dc:creator>SandzVG</dc:creator>
      <dc:date>2015-05-05T11:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change the Common Name (CN) = SplunkServerDefaultCert to the hostname?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-change-the-Common-Name-CN-SplunkServerDefaultCert-to/m-p/166304#M47366</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;

&lt;P&gt;Regenrate self-signed certs if your comp has no CA present , follow the below procedure..&lt;/P&gt;

&lt;P&gt;Please take a backup of &lt;CODE&gt;c:\Program Files\SplunkUniversalForwarder\etc\auth&lt;/CODE&gt; Folder in Windows.&lt;BR /&gt;
Below commands should be executed from the path &lt;CODE&gt;c:\Program Files\SplunkUniversalForwarder\etc\auth&lt;/CODE&gt; &lt;BR /&gt;
When prompted to enter the details in the CERT. during creation.&lt;/P&gt;

&lt;P&gt;C=US&lt;BR /&gt;
ST=SF&lt;BR /&gt;
L=WD&lt;BR /&gt;
O=Splunk&lt;BR /&gt;
OU=SPLUNK&lt;BR /&gt;
CN=&amp;lt;FQDN of the server&amp;gt; # this is the critical value that has to be the hostname on which the cert is being generated,rest can be anything.&lt;BR /&gt;
Password : changeme2&lt;BR /&gt;
emailAddress=&amp;lt;user&amp;gt;@&amp;lt;comp&amp;gt;.com&lt;/P&gt;

&lt;P&gt;Generate a New CA key and Cert&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;            openssl ecparam -out ca-key.pem -genkey -name prime256v1
            openssl req -x509 -new -key ca-key.pem -out ca-cert.pem
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Next we generate a CSR to sign the CERT/KEYs&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;            openssl ecparam -out server-key.pem -genkey -name prime256v1 -noout
            openssl req -new -key server-key.pem -out server-csr.pem
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Finally using our CSR we generate a Cert. Here we use the CA we previously generated &lt;/P&gt;

&lt;H1&gt;10 years&lt;/H1&gt;

&lt;PRE&gt;&lt;CODE&gt;            openssl x509 -req -days 3650 -in server-csr.pem -CA ca-cert.pem -CAkey ca-key.pem -set_serial 01 -out server-cert.pem
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Convert cert and key to PEM format&lt;/P&gt;

&lt;H1&gt;Using Cygwin Bash Shell&lt;/H1&gt;

&lt;PRE&gt;&lt;CODE&gt;            cat server-cert.pem server-key.pem &amp;amp;gt; server.pem
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Renamed the below certs as per the call from outputs.conf in splunk.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;            ca-cert.pem to cacert.pem
            ca-key.pem to ca.key
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Restart the SplunkForwarder and verify the splunkd.log for any CA related errors. If no errors we are good.&lt;/P&gt;

&lt;P&gt;NOTE: These are self-signed certs with CN = (hostname FQDN)&lt;/P&gt;

&lt;P&gt;i think this is the long story short, good luck&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Venu&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 09:11:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-change-the-Common-Name-CN-SplunkServerDefaultCert-to/m-p/166304#M47366</guid>
      <dc:creator>SandzVG</dc:creator>
      <dc:date>2015-05-13T09:11:57Z</dc:date>
    </item>
  </channel>
</rss>

