Security
Highlighted

Upgrading a LWF to a Universal Forwarder 4.1.6 to 4.2.5, we get SSL errors

Path Finder

ERROR TcpOutputProc - Error initializing SSL context - invalid sslCertPath for server xx.xx.xx.x1:9997

ERROR SSLCommon - Can't read key file /opt/splunkforwarder/etc/apps/ku-certs/forwarder.pem errno=101077092 error:06065064:digital envelope routines:EVPDecryptFinalex:bad decrypt.

ERROR TcpOutputProc - Error initializing SSL context - invalid sslCertPath for server xx.xx.xx.x2:9997

ERROR SSLCommon - Can't read key file /opt/splunkforwarder/etc/apps/ku-certs/forwarder.pem errno=101077092 error:06065064:digital envelope routines:EVPDecryptFinalex:bad decrypt.

ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.

Verified certpath, verified outputs.conf. Still unable to connect to indexer.

Tags (1)
Highlighted

Re: Upgrading a LWF to a Universal Forwarder 4.1.6 to 4.2.5, we get SSL errors

Path Finder

After verifying the certpath and the outputs.conf file. I edited the outputs.conf and removed the encrypted SSLPassword. Added the cleartext password in its place and restarted the forwarder. This encrypted the SSLPassword and the forwarder connected with the indexer successfully.

View solution in original post

Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.