Security

SSL "obsolete key" warning in chrome browser

Lucas_K
Motivator

Has anyone been able to get Splunk Web settings that do not trigger these browser reports?

web.conf

[settings]
enableSplunkWebSSL = 1
cipherSuite = TLSv1.2:!eNULL:!aNULL:!SHA1
supportSSLV3Only = False
sslVersions = tls1.2

I still get this

Obsolete Connection Settings
The connection to this site uses a strong protocol (TLS 1.2), an obsolete key exchange (RSA), and a strong cipher (AES_128_GCM).
0 Karma
1 Solution

Lucas_K
Motivator

Solved. No splunk settings were changed from the above to make this work.

alt text

This warning can be removed by using ellipitcal curve cert keys.

Old blog post with examples here : http://blogs.splunk.com/2014/06/03/generate-elliptical-curve-certkeys-for-splunk/

The down side is that your CA needs to be signing EC certs. If they aren't then you can't use ec keys.

View solution in original post

0 Karma

Lucas_K
Motivator

Solved. No splunk settings were changed from the above to make this work.

alt text

This warning can be removed by using ellipitcal curve cert keys.

Old blog post with examples here : http://blogs.splunk.com/2014/06/03/generate-elliptical-curve-certkeys-for-splunk/

The down side is that your CA needs to be signing EC certs. If they aren't then you can't use ec keys.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...