Splunk Enterprise

SSL enabled between deployment server and deployment client (UF)

krusovice
Path Finder

In my environment, I've setup the SSL communication and authentication between Deployment Server and its deployment client. It is working fine.

The trouble came when nearly 1 year - the renewal of the SSL is needed, meaning the server.pem and cacert.pem in UF require to be updated with renewed SSL. 

For the first year, we have used DS to push the SSL cert over to UF. Question is - is there any way to push the second year's SSL cert (server.pem and cacert.pem) over to UF using Deployment servers while the first year SSL still valid?

Or is there any best practice how to renew the cert in UF (deployment client) in yearly basis?

 

Thanks.

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

the best way to renew those is dependent on your way to use those. If you have use individual certificate in every node then you definitely need some tool which will manage that. But as the normal way to do this with splunk is to use one (or only few) cert for all UFs then it's much easier. Depending on place where you have put your cert files on UF you need a separate deployment tool (e.g. ansible, any MS based for windows) to renew those or use DS to add that on separate TA/SA on clients and then restart those.

r. Ismo

View solution in original post

0 Karma

SinghK
Builder

Ow, are you saying that you pushed a common ssl cert to all UF's?

0 Karma

krusovice
Path Finder

Yes, in our environment, there is cacert.pem and server.pem sit in the UF that require to annually renewed.

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

the best way to renew those is dependent on your way to use those. If you have use individual certificate in every node then you definitely need some tool which will manage that. But as the normal way to do this with splunk is to use one (or only few) cert for all UFs then it's much easier. Depending on place where you have put your cert files on UF you need a separate deployment tool (e.g. ansible, any MS based for windows) to renew those or use DS to add that on separate TA/SA on clients and then restart those.

r. Ismo

0 Karma

tinatan
Engager

Thank you for the reply, we are using one cert applied to all UFs.

Tags (1)
0 Karma

SinghK
Builder

my understanding was ssl cert was very unique with priv key and everything unless csr  and key is not generated on server it will not work.

i am very interested in the topic lets ask isoutamo or anyone else who can help.

 

@isoutamo 

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...