Deployment Architecture

SSL flows within deployed app

pdjhh
Communicator

Hi there.

We have our data ingestion ssl flows distributed to our heavy forwarders within an app. So the certs and outputs.conf are just under app/local and this has worked fine until now. What has happened is we have had a windows HF in the past whereas we've just stood up Linux HFs. The app gets pushed to the new linux HF but the secure connection will not come up.

The errors I'm seeing are these on the indexer side:
ERROR TcpInputProc - Error encountered for connection from src=x.x.x.x:59918. error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol

Searching that error points to lots of things such as tls versions, compression on or off etc but as my config is all within the files in the app then this new forwarder has the same config as the old windows one which talks to the indexer succesfully. Just wondering if there's any secret ssl security within that's preventing this working? I've tried regenerating the sslPassword in case it was that but no go.

Thanks.

0 Karma

pdjhh
Communicator

This problem looks to have been caused by pushing hashed passwords in the apps to the new heavy forwarders. This doesn't work with hashed passwords (effecting app deployment) but you need to work around as per the following article:

http://docs.splunk.com/Documentation/Splunk/6.0.1/Security/Deploysecurepasswordsacrossmultipleserver...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...