Splunk Dev

Splunk Web support password-protected private keys or not?

daniel_splunk
Splunk Employee
Splunk Employee

From the latest document,

http://docs.splunk.com/Documentation/Splunk/latest/Security/Self-signcertificatesforSplunkWeb

It stated that

Remove the password from your key. (Splunk Web does not support password-protected private keys.)

However, from the web.conf page (starting from 6.6.0),

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Webconf

It stated that

sslPassword = <password>
* Password protecting the private key specified by 'privKeyPath'.
* Optional. Defaults to unencrypted private key.
* If encrypted private key is used, do not enable client-authentication
  on splunkd server. In [sslConfig] stanza of server.conf,
  'requireClientCert' must be 'false'.

The 2 parameter seem contradict to each others. Any idea why?

Tags (1)
0 Karma

jeremyhagand61
Communicator

It certainly works with passwords in version 9

0 Karma

daniel_splunk
Splunk Employee
Splunk Employee

I would suggest to follow our older version practise not to set password to protect the web private key.

If password-protected private key is really needed in web.conf, don't set requireClientCert to true (default value is false) in server.conf

0 Karma

osmanysr
Engager

The documentation in version 9.0 and up is no longer asking to remove the password from the private key prior generating a CSR file.

Compare this documentation...

https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/Getthird-partycertificatesforSplunkWeb

vs.

This one...

https://docs.splunk.com/Documentation/Splunk/8.2.9/Security/Getthird-partycertificatesforSplunkWeb

That says:

Remove the password from the private key. You must do this because Splunk Web does not support private key passwords.

In my case...

I am using Splunk version 9.0.2 and my private key (.key file) has password. I use it on web conf under sslPassword

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...