Getting Data In

Qualys scan detecting various SSL certificate vulnerabilities: How to resolve these vulnerabilities?

afamuyiwa
Engager

Our Qualys report detected various SSL certificate vulnerabilities for any devices using Splunk universal forwarder via 8090. We have deployment server configured to push configuration to servers running Splunk agent. After doing some research it appears we need to create a certificate on the deployment server and distribute to any server running Splunk agent. I'm curious to know which certificates I need to distribute. I was able to create self-sign certificates on the deployment server. I would like to resolve vulnerabilities detected by Qualys. I found the following documentation that cert authentication is not recommended for deployment and clients. - https://docs.splunk.com/Documentation/Splunk/7.1.0/Security/Securingyourdeploymentserverandclients

Additional information:
http://docs.splunk.com/Documentation/Splunk/7.1.0/Security/Howtoself-signcertificates
http://docs.splunk.com/Documentation/Splunk/7.1.0/Security/HowtoprepareyoursignedcertificatesforSplu...

Qualys Vulnerabilities:
• X.509 Certificate SHA1 Signature Collision Vulnerability

• SSL Certificate - Self-Signed Certificate

• SSL Certificate - Expired

• SSL Certificate - Subject Common Name Does Not Match Server FQDN

• SSL Certificate - Signature Verification Failed Vulnerability

• HTTP Security Header Not Detected

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...