Installation

Why am I getting Invalid key in stanza [sslConfig] in server.conf for slVersionsForClient?

rholm01
Explorer

[sslConfig]
sslVersions = *,-ssl2
slVersionsForClient = *,-ssl2

Per the documentation
* The syntax is the same as the 'sslVersions' setting above.

Those entries are identical, so I don't understand why I am getting an error for one and not both.

Tags (1)
0 Karma

ragedsparrow
Contributor

So, from the spec file:

sslVersions = <versions_list>
* Comma-separated list of SSL versions to support for incoming connections.
* The versions available are "ssl3", "tls1.0", "tls1.1", and "tls1.2".
* The special version "*" selects all supported versions.  
  The version "tls"
  selects all versions tls1.0 or newer.
* If a version is prefixed with "-" it is removed from the list.
* SSLv2 is always disabled; "-ssl2" is accepted in the version list 
  but does nothing.
* When configured in FIPS mode, "ssl3" is always disabled regardless
  of this configuration.
* Default: The default can vary. See the 'sslVersions' setting in 
  the $SPLUNK_HOME/etc/system/default/server.conf file for the 
  curent default.

If you are trying to restrict ssl2, there is no reason to modify the sslVersion or sslVersionsForClient settings. However. Where I think your syntax is wrong is that you have a preceding comma, but nothing in front of it:

[sslConfig]
sslVersions = ,-ssl2
slVersionsForClient = ,-ssl2

I tested the following and had no issue:

[sslConfig]
sslVersions = -ssl2
sslVersionsForClient = -ssl2

It also appears there may be a typo in yours as well; You had slVersionsForClient instead of sslVersionsForClient

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...