Monitoring Splunk

Disabling CBC mode ciphers

lal37
Explorer

Hi Team,

SSLv3.0/TLSv1.0 Protocol Weak CBC Mode vulnerability have been identified on Splunk during internal scan.
The internal PA team asked us to upgrade to TLSv1.1 or TLSv1.2,if not possible to upgrade they asked us to disable CBC mode ciphers.
It could be better if you could guide us to fix the issue.strong text

Regards,
Shiva

Tags (1)

hsesterhenn_spl
Splunk Employee
Splunk Employee

Just an update to make sure people use the current options: (v7.3+)

https://docs.splunk.com/Documentation/Splunk/latest/Security/Ciphersuites

HTH,

Holger

0 Karma

dwaddle
SplunkTrust
SplunkTrust

For Splunkd (port 8089 by default) - the proper setting of cipher suites is in server.conf under the sslConfig stanza, set the cipherSuite option using a valid OpenSSL cipher suite specification. See http://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf

For splunkweb, there are similar settings in web.conf.

lal37
Explorer

Hi dawadle,

I would like to know how we can replace SSL version to TLS version.
I guess by default splunk is using SSL encryption.
Please advice.

Thanks and Regards,
Shiva

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...