Security

How will changing my SSL versions affect my system

a212830
Champion

We were recently flagged for supporting SSLv2, and we want to change our systems to only support TLS. We run Splunk 6.5.4 on Linux, and the majority of our forwarders are version 6.3.11 and above, with a couple of 6.2 forwarders.

My thought was the since the forwarders are not configured to use a specific version of SSL, I should be able to change the indexers to only use TLS, and the forwarder will still be able to determine the change and communicate. Is that accurate? Or will they all need to be restarted? Or, do I need to coordinate this in great detail?

Tags (2)
0 Karma

sloshburch
Ultra Champion

So, you'll want to sanity check against http://docs.splunk.com/Documentation/Splunk/latest/Security/AboutsecuringyourSplunkconfigurationwith... but regardless of what you see in the docs, you def want to test this before rolling it out to make sure that your understanding of the docs match up what the behavior they intended to document.

0 Karma

a212830
Champion

Anyone?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...