Splunk Enterprise

How to configure/tell Splunk which CA is in use so it can trust the certificate?

rob345963
Observer

I am configuring a hostname validation TLS certificate with a self-signed certificate in splunk enterprise 9.0 and it seems to me that it cannot trust the CA

ERROR X509Verify [TelemetryMetricBuffer] - Server X509 certificate (CN=,DC=,DC=,DC=) failed validation; error=19, reason="self signed certificate in certificate chain"

the configuration is the following:

[sslConfig]
# turns on TLS certificate requirements
sslVerifyServerCert = true
# turns on TLS certificate host name validation
sslVerifyServerName = true
serverCert = <path to your server certificate>

Do you know how I can tell splunk which CA I'm using so it can trust the certificate? or how can i configure it?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...