Splunk Enterprise Security

Splunk not taking updated certificate server.pem

clacroixdurant
Explorer

We noticed this morning that all the certificates for our Splunk servers are expired since a week (discovered whilst investigating why KVStore stopped this weekend). 

I followed recommendation from other community ask by renaming server.pem to server.pem.old and restarting the Splunk service to create a new one. 

It correctly creates  a new server.pem with a valid expiration date, however it still displays the old cerficate in my browser. 

I already checked with btool, and it seems fine (pointing to server.pem). I also already checked web.conf and tried to manually indicate the file path but it's still not working...


Am I missing something? 

Labels (3)
Tags (2)
0 Karma
1 Solution

clacroixdurant
Explorer

Well, I finally found what was missing. 

 

There's another certificate for the web interface in /opt/splunk/etc/auth/splunkweb

I did the same as the other certificate (rename it to .old and restart the service) and it automatically recreated a new updated certificate. 

View solution in original post

0 Karma

clacroixdurant
Explorer

Well, I finally found what was missing. 

 

There's another certificate for the web interface in /opt/splunk/etc/auth/splunkweb

I did the same as the other certificate (rename it to .old and restart the service) and it automatically recreated a new updated certificate. 

0 Karma
Get Updates on the Splunk Community!

Changes to Splunk Instructor-Led Training Completion Criteria

We’re excited to share an update to our instructor-led training program that enhances the learning experience ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

❄️ Welcome the new year with our January lineup of Community Office Hours, Tech Talks, and Webinars! 🎉 ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...