What is the impact to expire my server.pem?
Hi Splunk professional,
I would like to know any impacts when the server.pem in SHC are expired.
I have already understood what will happen to expire them in SHC.
I do make sure whether SHC are impossible to connect with indexer when expiring the server.pem, because the 8089 port is not work.
Is that correct?
Anyway, I would like to know another impact and concern.
I appreciate any opinion.
Generally speaking, Splunk will not be adversely affected by an expired certificate, however, it is of course bad security practice.
SSL/TLS certificate management can be quite a daunting process in Splunk, however, this excellent presentation from .conf15 walks you through the process of generating your own certificates for your whole deployment - Its a great guide.
It also shows which services such as CA checking and CN checking are used by each component.
As far as I know if you have
sslVerifyServerCert = false in server.conf then it will not create any problem but KVStore will complain and might not work (I had tested expired server.pem in Splunk 6.3 or 6.4 and it was working fine in my lab in SHC and IDXC and I was not using kvstore)