Security

Certificate generation failed : Splunkd port communication will not work

dkeck
Influencer

Hi,

On start up I am getting this error:

The certificate generation script did not generate the certificate file: /opt/splunk/etc/auth/<folder>/*.pem. Splunkd port communication will not work. SSL certificate generation failed

I try to change the server.pem and rootCA. So in server.conf I just changed the caCertFile, caPath and sslKeyfile to point to the new certificates. (I know these are deprecated but It didn´t work with the new once either).

Is anyone familiar with this, and can tell me what the cause is?

Thank you

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

Start over completely and do it like this (it is quite complicated and VERY easy to trash your system):

Who: George Starcher and Duane Waddle, Defense Point Security
What: Avoid the SSLippery SSLope of Default SSL
Recording: https://splunk.webex.com/splunk/lsr.php?RCID=da90ccae281af46da9e4a3b46c076a0b
Slides: Media:SplunkTrustApril-SSLipperySlopeRevisited.pdf

View solution in original post

woodcock
Esteemed Legend

Start over completely and do it like this (it is quite complicated and VERY easy to trash your system):

Who: George Starcher and Duane Waddle, Defense Point Security
What: Avoid the SSLippery SSLope of Default SSL
Recording: https://splunk.webex.com/splunk/lsr.php?RCID=da90ccae281af46da9e4a3b46c076a0b
Slides: Media:SplunkTrustApril-SSLipperySlopeRevisited.pdf

dkeck
Influencer

No one? 🙂

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...