Security

When setting up Indexer Discovery feature over SSL, what are the "password" and "sslPassword" options referring to?

jspvkey
Explorer

I was setting up the Indexer Discovery feature over SSL and according to the Splunk documentation, I am supposed to put the below info to Splunk Configuration files.

For Indexer

[SSL]
serverCert = path to server certificate
password = certificate password
rootCA = path to certificate authority list

Does anyone know what the "password" option referring to? Is this the passphrase that we used for creating the certificate??

For Forwarder

sslCertPath = path to  client certificate
sslPassword = CAcert password
sslRootCAPath = path to root certificate authority file

Regarding this, what is the option "sslPassword" referring to? Is it the passphrase used to create the CA certificate? I couldn't find any proper answers in Splunk documentation. Can someone please help me?

Thanks

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi jspvkey,
Yes it's certificate password.
You insert it in clear, at the first restart you'll find it encrypted.
Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jspvkey,
Yes it's certificate password.
You insert it in clear, at the first restart you'll find it encrypted.
Bye.
Giuseppe

0 Karma

jspvkey
Explorer

Thanks for the confirmation.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Yes, the passphrase hash will be inserted in the password field

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...