Security

Why do I receive a Secure Connection Failed message in Firefox when connecting to a search head which uses a self-signed certificate?

bpaul_splunk
Splunk Employee
Splunk Employee

I am using self-signed certificates to connect to my search heads using SSL. After upgrading to the latest version of Firefox (31+), I now receive the following error message when trying to connect.

Secure Connection Failed

An error occurred during a connection to x.x.x.x:8000. Issuer certificate is invalid. (Error code: sec_error_ca_cert_invalid)

  • The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.
  • Please contact the website owners to inform them of this problem. Alternatively, use the command found in the help menu to report this broken site.

What needs to be done to enable SSL communication to my search heads?

0 Karma

grijhwani
Motivator

Is Firefox not prompting you to allow an exception? You should be able to import and trust the search head's certificate into Firefox's trust store, or at the very least allow a permanent exception for that certificate.

0 Karma

bpaul_splunk
Splunk Employee
Splunk Employee

In this case, there is no option to allow an exception.

0 Karma

bpaul_splunk
Splunk Employee
Splunk Employee

Mozilla added a new certificate verification feature to their Firefox browser (starting with version 31) called PKIX. You will need to disable this feature to use your own self-signed certificate. You may do the following to accomplish this.

  1. Open the Firefox browser.
  2. Type about:config in the search bar and press enter.
  3. If presented with the warning, “This might void your warranty…”, click the “I’ll be careful, I promise!” button.
  4. In the Preference Name column, locate the security.use_mozillapkix_verification option.
  5. Double click on the option to toggle the setting to false

You should now be able to use Mozilla Firefox to access your search head using a self-signed certificate. For more information on Mozilla PKIX, please see their blog posting on the subject.

0 Karma
Get Updates on the Splunk Community!

Digital Resilience Assessment Launch | How prepared are you for disruption?

Disruption is inevitable. The question is – how prepared are you to handle it? In today’s fast-moving digital ...

Buttercup Games: Further Dashboarding Techniques (Part 2)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Index This | What is the next number in the series? 7,645 5,764 4,576…

February 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...