Getting Data In

How do you do a silent installation of a universal forwarder with own certificates and password?

pichertklaus
Explorer

Hello,

We tried to install the latest universal forwarder silently on our Windows machines using the following command

msiexec /i splunkforwarder-7.1.2-a0c72a66db66-x64-release.msi 
    DEPLOYMENT_SERVER="<deploysrvname>:8089" 
    LAUNCHSPLUNK=0 
    SERVICESTARTTYPE=auto 
    CERTFILE="%CD%\server.pem" 
    CERTPASSWORD=<certpassword> 
    ROOTCACERTFILE="%CD%\cacert.pem" 
    SPLUNKPASSWORD=<splunkpassword> 
    AGREETOLICENSE=yes /quiet

When the service is starting, however, we get the following error in splunkd.log, and it will not connect to DC.

03-28-2019 13:28:07.041 +0100 ERROR SSLCommon - Can't read key file C:\Program Files\SplunkUniversalForwarder\etc\auth\server.pem errno=101077092 error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt.
03-28-2019 13:28:07.041 +0100 ERROR HTTPServer - SSL context could not be created - error in cert or password is wrong
03-28-2019 13:28:07.041 +0100 ERROR HTTPServer - SSL will not be enabled

When I paste the certpassword into etc/system/local/server.conf and restart the service it will come up correctly and connect to DC to receive its apps.

Where is the error?

Regards,
Klaus

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...