I'm required to scan my Splunk Enterprise environment for compliance reasons. When I'm scanning my search heads and indexers ,I keep getting multiple SSL errors for the management port 8089. I've searched and haven't found a way figure out a method to upload a third party cert to fix this or if this is something that I'll just have to make not isn't fixable. I've included some of the vulnerability issues I've found. Not sure if opening a ticket with support would get me the information I need.
What version of Splunk?
If you 6.3+ you can have splunk use TLV1.2 cipherSuite OR upgrade Splunk to 6.4. Add that in your server.conf and everywhere else (inputs/outputs and web) Hope this helps!
using splunk 6.4.1, you got a link handy and i'll read through that?
i am using 6.4..4 and by scaning we got issue on 8008 port as SHA 1 alert
so how to make 8008 port (vmware DCN port) as secure?
You sure they can't allow exclusions? Generally all servers must be scanned to pass security compliance but even so exceptions are usually made provided justification for enterprise systems
Generally, yes I should be able to exclude if I need to but... more than likely I'll need a reason why I'm leaving this enabled (yay compliance). Thanks for the suggestion though, that may be what has to happen.
SSL Version 2 and 3 Protocol Detected
=> Disable SSLv2 and SSLv3, or specify tls1.2
That's what i was looking for!
Quick question, for 1,2,3 do those fixes apply for stuff on the management port (8089)?
Yes, all of them can apply to the Splunk management port (default is 8089)