Security

Splunk not taking updated certificate (SSL)

nawazns5038
Builder

Hi,

The search head cluster uses our own certificates which are going to expire soon. So in order to update the certificates I have pushed the certs through the deployer and updated the SSL Password in server.conf and outputs.conf and the search heads restarted and everything is working fine without errors . But the certificates have not been updated. UI still shows the old certificate and I have checked the expiry through CLI as well. It shows the old certificate. The new certificates have been pushed in the backend.

What could be the reason ?? Anything that I have missed ?

I have double checked using btool , and the certs are pointing towards the right direction .

One thing I observed is that $SPLUNK_HOME is not set on the splunk-launch.conf file . Is that a problem ??

0 Karma

johnansett
Communicator

Hello!  Did you get this working? I am having the same issue - the privKeyPath and serverCert show up correctly when I run btool, but it still seems to be using the old self signed certs.....

0 Karma

MoniM
Communicator

Hi @nawazns5038 ,

Have you gone through the below settings in web.conf ?

https://docs.splunk.com/Documentation/Splunk/7.2.3/Security/SecureSplunkWebusingasignedcertificate#C...

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...