My Question is :
1:As we are changing the web.conf file in deployer , it will applicable for all 3 SH, so we have to create self-signed certs in all 3 SH ?
1. what is our approach for Splunkweb certs in case of Clustered enviornmant .
The best approach to create cert in Splunk is mentioned below :
1. Go to $SPLUNK_HOME\etc\auth\splunkweb
2. Rename cert.pem to cert.pem_backup
3. Restart the splunk using command ./splunk restart
4. After restart you will be able to see a new cert.pem file.
5. Check the expiry date of Certificate now using command: $SPLUNK_HOME\bin\openssl x509 -enddate -noout -in $SPLUNK_HOME/etc/auth/splunkweb/cert.pem
6. The expiry date will be extended.
Do this one by one for all the SH servers if you want to update it for all the SH, but it is not required till the time they are coming near expiry date.
Thanks for your answer, this approach is worked for cert.pem but to renew the certificates in under splunkweb , we have to create the self-signed certificates(SplunkWebPrivateKey & SplunkWebCertificate.pem) and change the certificate path in web.conf.
Configure Splunk Web to use the key and certificate files:
-In $SPLUNK_HOME/etc/system/local/web.conf, make the following changes to the [settings] stanza:
enableSplunkWebSSL = true