Security

Can I force forwarders to use TLS 1.2 by disabling SSL3?

MrMcGeough
Explorer

I need to disable SSL3 and enable TLS 1.2 across all of Splunk Enterprise. SSL3 is being disabled entirely in my organization.

If I just add "sslVersions = -tls1.1, tls1.2, -sslv2, -sslv3" to the inputs.conf, server.conf (under [sslConfig] ) and web.conf on the Indexer, would this not force all forwarders to use TLS 1.2 (or not connect at all if TLS 1.2 is not enabled on the forwarder)?

I have read a number of questions on this, and I'm not entirely clear how I can be certain that I am using TLS 1.2 exclusively across all Splunk servers.

Tags (1)
0 Karma

MrMcGeough
Explorer

I followed that guide to force TLS. As I said above, "I'm not entirely clear how I can be certain that I am using TLS 1.2 exclusively across all Splunk servers."

When they shut down SSL3, I don't want to find out that somehow Splunk was still using it for 'x' to communicate.

0 Karma

ddrillic
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...