Getting Data In

Qualys scan detecting various SSL certificate vulnerabilities: How to resolve these vulnerabilities?

afamuyiwa
Engager

Our Qualys report detected various SSL certificate vulnerabilities for any devices using Splunk universal forwarder via 8090. We have deployment server configured to push configuration to servers running Splunk agent. After doing some research it appears we need to create a certificate on the deployment server and distribute to any server running Splunk agent. I'm curious to know which certificates I need to distribute. I was able to create self-sign certificates on the deployment server. I would like to resolve vulnerabilities detected by Qualys. I found the following documentation that cert authentication is not recommended for deployment and clients. - https://docs.splunk.com/Documentation/Splunk/7.1.0/Security/Securingyourdeploymentserverandclients

Additional information:
http://docs.splunk.com/Documentation/Splunk/7.1.0/Security/Howtoself-signcertificates
http://docs.splunk.com/Documentation/Splunk/7.1.0/Security/HowtoprepareyoursignedcertificatesforSplu...

Qualys Vulnerabilities:
• X.509 Certificate SHA1 Signature Collision Vulnerability

• SSL Certificate - Self-Signed Certificate

• SSL Certificate - Expired

• SSL Certificate - Subject Common Name Does Not Match Server FQDN

• SSL Certificate - Signature Verification Failed Vulnerability

• HTTP Security Header Not Detected

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...