Security

installing SSL certificates

ssackrider
Explorer

created the have new CA & ssl certs, tweaked /opt/splunk/etc/system/local/web.conf to say
privkeypath = $SPLUNK_HOME/etc/auth/mySplunkPrivateWebKey.pem

splunkd.log still says: Can't read key file /opt/splunk/etc/auth/splunkweb/privkey.pem

and web doesn't start What's pointing to the old file? Not in web.conf anywhere else.

Tags (1)
0 Karma
1 Solution

elliotproebstel
Champion

Is that a direct copy/paste from your web.conf file? If so, the capitalization might be the issue. I believe the variable is supposed to be privKeyPath.

View solution in original post

0 Karma

elliotproebstel
Champion

Is that a direct copy/paste from your web.conf file? If so, the capitalization might be the issue. I believe the variable is supposed to be privKeyPath.

0 Karma

ssackrider
Explorer

Again, my windows background vexes me-- appreciate it

0 Karma

elliotproebstel
Champion

Glad to help!

0 Karma
Get Updates on the Splunk Community!

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...

Almost Too Eventful Assurance: Part 1

Modern IT and Network teams still struggle with too many alerts and isolating issues before they are notified. ...

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...