Getting Data In

Qualys scan detecting various SSL certificate vulnerabilities: How to resolve these vulnerabilities?

afamuyiwa
Engager

Our Qualys report detected various SSL certificate vulnerabilities for any devices using Splunk universal forwarder via 8090. We have deployment server configured to push configuration to servers running Splunk agent. After doing some research it appears we need to create a certificate on the deployment server and distribute to any server running Splunk agent. I'm curious to know which certificates I need to distribute. I was able to create self-sign certificates on the deployment server. I would like to resolve vulnerabilities detected by Qualys. I found the following documentation that cert authentication is not recommended for deployment and clients. - https://docs.splunk.com/Documentation/Splunk/7.1.0/Security/Securingyourdeploymentserverandclients

Additional information:
http://docs.splunk.com/Documentation/Splunk/7.1.0/Security/Howtoself-signcertificates
http://docs.splunk.com/Documentation/Splunk/7.1.0/Security/HowtoprepareyoursignedcertificatesforSplu...

Qualys Vulnerabilities:
• X.509 Certificate SHA1 Signature Collision Vulnerability

• SSL Certificate - Self-Signed Certificate

• SSL Certificate - Expired

• SSL Certificate - Subject Common Name Does Not Match Server FQDN

• SSL Certificate - Signature Verification Failed Vulnerability

• HTTP Security Header Not Detected

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...