Security

Feature Request: Splunk Certificate Management GUI

dwchow
Engager

While there is ample documentation on certificate generation and application to both Splunk Web, Indexers, and Forwarders-- we often find that securing post-default deployment scenarios during PS engagements are no fun. We haven't had good luck with just 'pushing' certificates and having Universal Forwarders properly utilize them (at least in Windows environments). Utilizing the Deployment Server and pushing your own app and config packages still have clear text in many scenarios.

We would like to see a feature added for complete Web GUI of Splunk Certificate Management including:
Components: universal forwarders, indexers, and Splunk web server
Action/abilities for administrator user from within WebUI:
Import and use 3rd party signed CA certificates, and their respective keys (including mutual authentication client certs required)
Automated abilities Generate, replace/renew, and deploy certificates to all connecting forwarders (Windows and Linux)
Warning messages when certificates will expire
Enable a 'quick start' deployment default options of either using 3rd party signed certs or using self signed certs during installation for secure NOT JUST universal forwarder agent check in/control status messages but the actual data being forwarded from them. This also includes automatic proper TLS use ready for receiver

richgalloway
SplunkTrust
SplunkTrust

@dwchow Consider submitting this feature request at https://ideas.splunk.com/

---
If this reply helps you, Karma would be appreciated.
0 Karma

acharlieh
Influencer

This doesn't read like you have a question, but I'll give you an answer... If you have a need for such a feature you should submit a P4 (Enhancement Request) ticket on your support entitlement, and/or talk to your account / partner teams about it. In order for anything to have a chance of being worked on by the development teams, it needs to get to Splunk's JIRA queues. While some employees may troll Splunk Answers, you have a better chance of getting it into their JIRA to be prioritized if it's logged through proper channels.

See also: https://answers.splunk.com/answers/4844/how-can-i-submit-an-enhancement-request.html

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...