Monitoring Splunk

Disabling CBC mode ciphers

lal37
Explorer

Hi Team,

SSLv3.0/TLSv1.0 Protocol Weak CBC Mode vulnerability have been identified on Splunk during internal scan.
The internal PA team asked us to upgrade to TLSv1.1 or TLSv1.2,if not possible to upgrade they asked us to disable CBC mode ciphers.
It could be better if you could guide us to fix the issue.strong text

Regards,
Shiva

Tags (1)

hsesterhenn_spl
Splunk Employee
Splunk Employee

Just an update to make sure people use the current options: (v7.3+)

https://docs.splunk.com/Documentation/Splunk/latest/Security/Ciphersuites

HTH,

Holger

0 Karma

dwaddle
SplunkTrust
SplunkTrust

For Splunkd (port 8089 by default) - the proper setting of cipher suites is in server.conf under the sslConfig stanza, set the cipherSuite option using a valid OpenSSL cipher suite specification. See http://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf

For splunkweb, there are similar settings in web.conf.

lal37
Explorer

Hi dawadle,

I would like to know how we can replace SSL version to TLS version.
I guess by default splunk is using SSL encryption.
Please advice.

Thanks and Regards,
Shiva

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...