Security

When setting up Indexer Discovery feature over SSL, what are the "password" and "sslPassword" options referring to?

jspvkey
Explorer

I was setting up the Indexer Discovery feature over SSL and according to the Splunk documentation, I am supposed to put the below info to Splunk Configuration files.

For Indexer

[SSL]
serverCert = path to server certificate
password = certificate password
rootCA = path to certificate authority list

Does anyone know what the "password" option referring to? Is this the passphrase that we used for creating the certificate??

For Forwarder

sslCertPath = path to  client certificate
sslPassword = CAcert password
sslRootCAPath = path to root certificate authority file

Regarding this, what is the option "sslPassword" referring to? Is it the passphrase used to create the CA certificate? I couldn't find any proper answers in Splunk documentation. Can someone please help me?

Thanks

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi jspvkey,
Yes it's certificate password.
You insert it in clear, at the first restart you'll find it encrypted.
Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jspvkey,
Yes it's certificate password.
You insert it in clear, at the first restart you'll find it encrypted.
Bye.
Giuseppe

0 Karma

jspvkey
Explorer

Thanks for the confirmation.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Yes, the passphrase hash will be inserted in the password field

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...