created the have new CA & ssl certs, tweaked /opt/splunk/etc/system/local/web.conf to say
privkeypath = $SPLUNK_HOME/etc/auth/mySplunkPrivateWebKey.pem
splunkd.log still says: Can't read key file /opt/splunk/etc/auth/splunkweb/privkey.pem
and web doesn't start What's pointing to the old file? Not in web.conf anywhere else.
Is that a direct copy/paste from your web.conf file? If so, the capitalization might be the issue. I believe the variable is supposed to be privKeyPath
.
Is that a direct copy/paste from your web.conf file? If so, the capitalization might be the issue. I believe the variable is supposed to be privKeyPath
.
Again, my windows background vexes me-- appreciate it
Glad to help!