Splunk Enterprise

SSL certificate

LogUx
Motivator

Hello Splunkers!!

I have a VM server with two IP addresses: one NAT IP and one public IP. I have installed an SSL certificate for Splunk on the VM, and Splunk is accessible over HTTPS after the important chain certificates on the store are shown as secured.

When I access Splunk using the VM’s public IP, HTTPS is working; however, the browser still shows the connection as not secure.

Could you please clarify whether I also need to install the SSL certificate on my local system, or if any additional configuration is required on the Splunk server to ensure the HTTPS connection is trusted and shows as secure when accessed through the public IP?

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I'm not quite sure what you mean that your server has "NAT IP". I suppose you mean that it can be reached by means of connecting to IP A which is by some router NAT-ed to IP B which is your server's address.

Generally speaking, in order for the TLS connection to be considered properly validated, the cert presented by the server must:

- come from the certification chain originating at CA trusted by the client

- the whole chain must not break any constraints and must not contain expired certs (I'm not 100% sure of validity of non-expired certs which had been issued by CAs which already expired)

- the subject you're connecting to (either host name or IP, depending on what you are using to initiate the session) must match the data in the certificate presented by the server (either the subject field or one of the Subject Alternative Name (SAN) values)

So if you have your server configured at 192.168.101.101 to which your internal DNS points from splunk.local hostname and your certificate is issued for splunk.local hostname only (or for both the hostname and 192.168.101.101 IP although it's a common practice to _not_ issue certs for IPs) it will _not_ be valid for any other name or IP. So if some part of your company would try to connect to your Splunk at 172.16.101.101, the cert will not match properly. If they use a name of splunk.external.local, it won't match either obviously.

As far as I remember, while you can bind different certificates to specific inputs (although TLS settings on inputs have their share of problems), I don't recall binding separately (with different certificates) with webui instances. So you must either make sure that all your users connect using the same name(s) which are resolved by DNS to IPs apropriate for the client's environment (which can be tricky) or you must add all "endpoints" (names and IPs) as SANs to your certificate (which is very ugly and possibly leaking information especially if you're mixing private and public names and IPs; whatever private and public means in your case)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...