Deployment Architecture

Bootstrapping a secure management configuration with company certificates

afx
Contributor

Distributing certificates to forwarders for the indexer configuration works fine in Splunk.
But what about the management communication?
It seems to be a chicken and egg problem.
Can this be done via the deployment mechanism, sending the forwarders appropriate configuration and certificates?
But then as soon as that configuration is active, the deployment server will no longer accept the connections until that is switched as well. Or is there a fallback mechanism to internal certs that allows a smooth transition?
thx
afx

brettwilliams
Path Finder

I've run into this myself...  if a Splunk instance starts, and there is no SSL configuration anywhere, Splunk creates its own in etc/system/local.  Which can't be overridden.  I could conjure up something creative on the Linux forwarders...  but Windows, yeah, right...  not gonna happen.

For the forwarders that I control, this is easy to fix.  But for the forwarders I don't control, I'm just a few mouse clicks away from doom when I'm making changes in Forwarder Management.  If I accidentally pull the 8089 certs, I have to go get many, many people to touch every single forwarder to manually fix it.  Maybe we shouldn't distribute SSL certs for 8089 via deployment server.  But without any other options, at least in my enterprise, I don't see any alternatives.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...