Hello Splunkers!!
I have a VM server with two IP addresses: one NAT IP and one public IP. I have installed an SSL certificate for Splunk on the VM, and Splunk is accessible over HTTPS after the important chain certificates on the store are shown as secured.
When I access Splunk using the VM’s public IP, HTTPS is working; however, the browser still shows the connection as not secure.
Could you please clarify whether I also need to install the SSL certificate on my local system, or if any additional configuration is required on the Splunk server to ensure the HTTPS connection is trusted and shows as secure when accessed through the public IP?
I'm not quite sure what you mean that your server has "NAT IP". I suppose you mean that it can be reached by means of connecting to IP A which is by some router NAT-ed to IP B which is your server's address.
Generally speaking, in order for the TLS connection to be considered properly validated, the cert presented by the server must:
- come from the certification chain originating at CA trusted by the client
- the whole chain must not break any constraints and must not contain expired certs (I'm not 100% sure of validity of non-expired certs which had been issued by CAs which already expired)
- the subject you're connecting to (either host name or IP, depending on what you are using to initiate the session) must match the data in the certificate presented by the server (either the subject field or one of the Subject Alternative Name (SAN) values)
So if you have your server configured at 192.168.101.101 to which your internal DNS points from splunk.local hostname and your certificate is issued for splunk.local hostname only (or for both the hostname and 192.168.101.101 IP although it's a common practice to _not_ issue certs for IPs) it will _not_ be valid for any other name or IP. So if some part of your company would try to connect to your Splunk at 172.16.101.101, the cert will not match properly. If they use a name of splunk.external.local, it won't match either obviously.
As far as I remember, while you can bind different certificates to specific inputs (although TLS settings on inputs have their share of problems), I don't recall binding separately (with different certificates) with webui instances. So you must either make sure that all your users connect using the same name(s) which are resolved by DNS to IPs apropriate for the client's environment (which can be tricky) or you must add all "endpoints" (names and IPs) as SANs to your certificate (which is very ugly and possibly leaking information especially if you're mixing private and public names and IPs; whatever private and public means in your case)