Security

How will changing my SSL versions affect my system

a212830
Champion

We were recently flagged for supporting SSLv2, and we want to change our systems to only support TLS. We run Splunk 6.5.4 on Linux, and the majority of our forwarders are version 6.3.11 and above, with a couple of 6.2 forwarders.

My thought was the since the forwarders are not configured to use a specific version of SSL, I should be able to change the indexers to only use TLS, and the forwarder will still be able to determine the change and communicate. Is that accurate? Or will they all need to be restarted? Or, do I need to coordinate this in great detail?

Tags (2)
0 Karma

sloshburch
Splunk Employee
Splunk Employee

So, you'll want to sanity check against http://docs.splunk.com/Documentation/Splunk/latest/Security/AboutsecuringyourSplunkconfigurationwith... but regardless of what you see in the docs, you def want to test this before rolling it out to make sure that your understanding of the docs match up what the behavior they intended to document.

0 Karma

a212830
Champion

Anyone?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...