Splunk Dev

Splunk Web support password-protected private keys or not?

daniel_splunk
Splunk Employee
Splunk Employee

From the latest document,

http://docs.splunk.com/Documentation/Splunk/latest/Security/Self-signcertificatesforSplunkWeb

It stated that

Remove the password from your key. (Splunk Web does not support password-protected private keys.)

However, from the web.conf page (starting from 6.6.0),

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Webconf

It stated that

sslPassword = <password>
* Password protecting the private key specified by 'privKeyPath'.
* Optional. Defaults to unencrypted private key.
* If encrypted private key is used, do not enable client-authentication
  on splunkd server. In [sslConfig] stanza of server.conf,
  'requireClientCert' must be 'false'.

The 2 parameter seem contradict to each others. Any idea why?

Tags (1)
0 Karma

jeremyhagand61
Communicator

It certainly works with passwords in version 9

0 Karma

daniel_splunk
Splunk Employee
Splunk Employee

I would suggest to follow our older version practise not to set password to protect the web private key.

If password-protected private key is really needed in web.conf, don't set requireClientCert to true (default value is false) in server.conf

0 Karma

osmanysr
Engager

The documentation in version 9.0 and up is no longer asking to remove the password from the private key prior generating a CSR file.

Compare this documentation...

https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/Getthird-partycertificatesforSplunkWeb

vs.

This one...

https://docs.splunk.com/Documentation/Splunk/8.2.9/Security/Getthird-partycertificatesforSplunkWeb

That says:

Remove the password from the private key. You must do this because Splunk Web does not support private key passwords.

In my case...

I am using Splunk version 9.0.2 and my private key (.key file) has password. I use it on web conf under sslPassword

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...