Security

How do I renew an expired Splunk Certificate?

khusain_splunk
Splunk Employee
Splunk Employee

We have a distributed Splunk environment and the certificate for Splunk API in port tcp/8089 on the search head has expired.

How do I renew the Splunk Certificates?

0 Karma
1 Solution

khusain_splunk
Splunk Employee
Splunk Employee

First check if really Certs expired:

Windows:

C:\Program Files\splunk\bin> openssl x509 -enddate -noout -in "C:\Program Files\splunk\etc\auth\server.pem

Linux:
openssl x509 -enddate -noout -in /opt/splunk/etc/auth/server.pem

If it has been expired then rename /opt/splunk/etc/auth/server.pem to server.pem.back and restart splunkd.

./splunk restart

This will regenerate the server.pem file and renewed the certs.

View solution in original post

swellerrific
Explorer

Howdy! Quick follow-up on this. My apologies, still learning here. This is the first expiration since we stood up our environment.

In a distributed environment, do I do this on all my Splunk instances individually or can I do this on the deployment server and it pushes it out? 

Thank you in advance! 🙂 

0 Karma

harsmarvania57
Ultra Champion
0 Karma

khusain_splunk
Splunk Employee
Splunk Employee

First check if really Certs expired:

Windows:

C:\Program Files\splunk\bin> openssl x509 -enddate -noout -in "C:\Program Files\splunk\etc\auth\server.pem

Linux:
openssl x509 -enddate -noout -in /opt/splunk/etc/auth/server.pem

If it has been expired then rename /opt/splunk/etc/auth/server.pem to server.pem.back and restart splunkd.

./splunk restart

This will regenerate the server.pem file and renewed the certs.

yannK
Splunk Employee
Splunk Employee

If your splunk server.pem expired, then your mongo/kvstore cert copy probably expired too.

 

Check in $SPLUNK_HOME/var/lib/splunk/kvstore/mongo/splunk.key
if needed, you can move it aside, and restart splunk. A new one will be created based on the splunkd one.

 

see https://answers.splunk.com/answers/699766/can-you-help-me-with-the-following-mongod-kvstore.html

0 Karma

splunkreal
Motivator

This should be documented 🙂

* If this helps, please upvote or accept solution if it solved *

Faarooq
Loves-to-Learn

Does anyone know if there are any options to obtain certs for more than one year? 

0 Karma

splunkreal
Motivator

This generates for 3 years normally.

* If this helps, please upvote or accept solution if it solved *
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...