Splunk Enterprise Security

How to point a non-SSL indexer cluster to a SSL enabled license master?

ptcrusher
Explorer

We're working on the setup of a new Splunk installation.
As an intermediate step during the migration work we would like to point the old Indexer Cluster to the new License Master.

The problem we're facing is that, in the old installation we're not using SSL for port 8089 communications and in the new installation we are.
To sum up, SSL is not configured in the client (the old Indexer Cluster) but is enabled in new License Master.

After setting the master_uri in [license] stanza to https://newlm.com:8089 (in /opt/splunk/etc/system/local/server.conf) the following messages started to popup:

Failed to contact license master: reason='Unable to connect to license master=https://newlm.com:8089 Error connecting: SSL not configured on client

As a side note openssl output looks clean:

>openssl s_client -connect newlm.com:8089 -CAfile /opt/splunk/etc/auth/cacert.pem Verify return code: 0 (ok)

Anyway to set up this mixed environment?
Could we possibly use SSL just for the communication with the License Master?
Could these calls be "proxied" by a License Slave?
What is the minimum setup to support this kind of communication? It would be the bummer if we have to set up the entire old installation for SSL just to contact the License Master!

Thanks in advance.

Labels (3)
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...