Splunk Enterprise

SSLCommon - Received fatal SSL3 alert in splunkd.log

Dias
Explorer

Hi, 

I just noticed an alert "TCP or SSL config issue" in Splunk Admins app, then i followed to the splunkd.log and then noticed there SSLCommon - Received fatal SSL3 alert 

07-08-2021 04:45:08.309 +0600 ERROR X509Verify - Server X509 certificate (CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US) failed validation; error=20, reason="unable to get local issuer certificate"
07-08-2021 04:45:08.312 +0600 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='error', alert_description='unknown CA'.
07-08-2021 04:45:08.837 +0600 ERROR X509Verify - Server X509 certificate (CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US) failed validation; error=20, reason="unable to get local issuer certificate"
07-08-2021 04:45:08.837 +0600 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='error', alert_description='unknown CA'.

 How i understand this alert came with an error that doesn't accept certificate. I use Splunk's build in certificate, and dont know why this error shows up. Could this error be due to server overload or lack of resources? Because in other environments with the same settings  this error doesn't show up. 

Tags (1)
0 Karma

scoughlin1
Path Finder

Did you ever get this issue resolved? I have the same problem but have not found a solution.

0 Karma

Dias
Explorer

Hi, I haven't found a solution to this question yet

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...