Deployment Architecture

What is the impact to expire my server.pem?

Shuhei052492
Path Finder

What is the impact to expire my server.pem?

Hi Splunk professional,

I would like to know any impacts when the server.pem in SHC are expired.

I have already understood what will happen to expire them in SHC.

  • impossible to use 8089
  • impossible to use kvstore
  • not to work replication between SH
  • not to work lookup and inputlookup command

I do make sure whether SHC are impossible to connect with indexer when expiring the server.pem, because the 8089 port is not work.
Is that correct?

Anyway, I would like to know another impact and concern.

I appreciate any opinion.

Regards,

0 Karma

realsplunk
Motivator

May Splunk not work anymore however if the ROOT CA expires?

Thanks.

 

0 Karma

nickhills
Ultra Champion

Generally speaking, Splunk will not be adversely affected by an expired certificate, however, it is of course bad security practice.

SSL/TLS certificate management can be quite a daunting process in Splunk, however, this excellent presentation from .conf15 walks you through the process of generating your own certificates for your whole deployment - Its a great guide.

It also shows which services such as CA checking and CN checking are used by each component.

https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPr...

If my comment helps, please give it a thumbs up!

harsmarvania57
SplunkTrust
SplunkTrust

Hi,

As far as I know if you have sslVerifyServerCert = false in server.conf then it will not create any problem but KVStore will complain and might not work (I had tested expired server.pem in Splunk 6.3 or 6.4 and it was working fine in my lab in SHC and IDXC and I was not using kvstore)

0 Karma

damann
Communicator

When your SSL certificates expire your components (SH, IDX, Forwarder, etc...) will stop talking to each other.

0 Karma

nickhills
Ultra Champion

This is not correct in most cases. Splunk is very tolerant of expired certificates. It is certainly not the default failure mode

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...