Hi,
I just noticed an alert "TCP or SSL config issue" in Splunk Admins app, then i followed to the splunkd.log and then noticed there SSLCommon - Received fatal SSL3 alert
07-08-2021 04:45:08.309 +0600 ERROR X509Verify - Server X509 certificate (CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US) failed validation; error=20, reason="unable to get local issuer certificate"
07-08-2021 04:45:08.312 +0600 WARN SSLCommon - Received fatal SSL3 alert. ssl_state='error', alert_description='unknown CA'.
07-08-2021 04:45:08.837 +0600 ERROR X509Verify - Server X509 certificate (CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US) failed validation; error=20, reason="unable to get local issuer certificate"
07-08-2021 04:45:08.837 +0600 WARN SSLCommon - Received fatal SSL3 alert. ssl_state='error', alert_description='unknown CA'.
How i understand this alert came with an error that doesn't accept certificate. I use Splunk's build in certificate, and dont know why this error shows up. Could this error be due to server overload or lack of resources? Because in other environments with the same settings this error doesn't show up.
Did you ever get this issue resolved? I have the same problem but have not found a solution.
Hi, I haven't found a solution to this question yet
Hi
this sounds like there is not valid CA cert on your installation.
You should check that CA cert is on place and it's valid.
r. Ismo