Getting Data In

Issue with Self-Signed Certs Windows Splunk Univeral Forwarder to Windows Indexer "PEM routines:PEM_read_bio:no start line."

dwchow
Engager

Hello I get an error when attempting to utilize a self-signed Splunk cert generated from the splunk openssl through the tutorial found here

When after generating the keys I put them in the program files folder under \etc\auth and then my outputs.conf is set appropriately. The forwarder continues to send in clear text and the following error is within splunkd. "ERROR SSLCommon - Can't read key file C:\Program Files\SplunkUniversalForwarder\etc\auth\foocert.pem errno=151441516 error:0906D06C:PEM routines:PEM_read_bio:no start line."

I've investigated the pem file and compared it to others. Since it was windows I looked at them cert in both notepad++ and notepad regular and made adjusted line breaks accordingly even without word wrap as an attempt to resolve. I ensured the top of the file included "-----BEGIN CERTIFICATE-----" exactly 5 dashes each with no extra spacing. as well as the footer "-----END CERTIFICATE-----" the key looks like your average normal key. When examining the file with all non-printables notepad++ reports "CR LF" byte codes at each line. The other PEM files seem to have them too; which I suspect should be fine. I would like to use the same certificate pair made for the indexer as the UF; but the I do not have the private key right after the public key in the same pem file. I doubt that would generate the error but then again I'm unsure. Does the 'splunk open ssl' command use in Windows generate a file that needs to be tweaked before utilization? If so please advise.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...