Getting Data In

Issue with Self-Signed Certs Windows Splunk Univeral Forwarder to Windows Indexer "PEM routines:PEM_read_bio:no start line."

dwchow
Engager

Hello I get an error when attempting to utilize a self-signed Splunk cert generated from the splunk openssl through the tutorial found here

When after generating the keys I put them in the program files folder under \etc\auth and then my outputs.conf is set appropriately. The forwarder continues to send in clear text and the following error is within splunkd. "ERROR SSLCommon - Can't read key file C:\Program Files\SplunkUniversalForwarder\etc\auth\foocert.pem errno=151441516 error:0906D06C:PEM routines:PEM_read_bio:no start line."

I've investigated the pem file and compared it to others. Since it was windows I looked at them cert in both notepad++ and notepad regular and made adjusted line breaks accordingly even without word wrap as an attempt to resolve. I ensured the top of the file included "-----BEGIN CERTIFICATE-----" exactly 5 dashes each with no extra spacing. as well as the footer "-----END CERTIFICATE-----" the key looks like your average normal key. When examining the file with all non-printables notepad++ reports "CR LF" byte codes at each line. The other PEM files seem to have them too; which I suspect should be fine. I would like to use the same certificate pair made for the indexer as the UF; but the I do not have the private key right after the public key in the same pem file. I doubt that would generate the error but then again I'm unsure. Does the 'splunk open ssl' command use in Windows generate a file that needs to be tweaked before utilization? If so please advise.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...