Security
Highlighted

Deploy SSL app to UF and when UF restart, will it connect to deployment server?

Champion

Hi, SSL certificate renewal from Splunk default to self signed SSL.
I would like to create an app with SSL certificate and deploy that app to UF's.

  1. Once the app gets deployed, can I control when the UF should restart or after an app deployment the UF restarts automatically?
  2. After restart, the UF will have the new SSL certificate. But the deployment server is still having the old SSL certificate. Meaning, after SSL app deployment, how the UF can communicate with the deployment server?
  3. Can I deploy SSL certificate app to heavy forwarder and UF together at the same time? I mean, let's assume indexers got manually configured/renewed with self signed SSL certificate. Then, heavy forwarder and UF can be renewed together at the same time?

Please suggest.. thanks.

Tags (2)
0 Karma
Highlighted

Re: Deploy SSL app to UF and when UF restart, will it connect to deployment server?

Champion

Hi Splunk Gurus.. any suggestions please

0 Karma
Highlighted

Re: Deploy SSL app to UF and when UF restart, will it connect to deployment server?

Champion

How about the next step?
· Disable the deployment client remotely.
· Update the SSL of the deployment server.
· Enable deployment client remotely.
· (Restart the client remotely.)

You can also run it all at once using a script.

CLI Commands
http://docs.splunk.com/Documentation/Splunk/7.0.0/Admin/CLIadmincommands
Restart
https://answers.splunk.com/answers/92094/restart-splunkd-remotely.html

0 Karma
Highlighted

Re: Deploy SSL app to UF and when UF restart, will it connect to deployment server?

Champion

thanks for the reply HiroshiSatoh.. let me check this and update you back..

0 Karma
Highlighted

Re: Deploy SSL app to UF and when UF restart, will it connect to deployment server?

Champion

Hi ... 2 questions..
1. Do we need to run this remote start/stop commands manually for all UF's? If we have thousands of UFs, then manual task will become a big task.
We can take list of UF and then run thru a shell script, but, is there any other simple methods Splunk providing for this task?

  1. During SSL app deployment to clients, the client's which are down, will not receive the SSL app. And as we renew the deployment server with SSL certificate app, when these down UF will become up, this will look for deployment server with old SSL, but we already renewed it. how to deal with this situation please.

Thanks again..

0 Karma
Highlighted

Re: Deploy SSL app to UF and when UF restart, will it connect to deployment server?

Champion

Hi.. any suggestions please

0 Karma