Splunk Enterprise

Splunk Certificate 8089 Port

edgarsilva01
Path Finder

Hello

I'm trying to install a web certificate for port 8089, I don't know what I'm doing wrong.
There are already 3 scans and the vulnerability continues to appear.

Someone who has already solved it

This is the stanza I have in the web.conf file

[settings]
enableSplunkWebSSL = true
privKeyPath = /opt/splunk/etc/auth/mycerts/certificate.key
serverCert = /opt/splunk/etc/auth/mycerts/certificate.pem
 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
What problem are you trying to solve?
What "vulnerability" are you talking about?
Port 8089 is not "SplunkWeb". It's the Splunk management port used by Splunk instances to talk to each other. Change the security on that post and you could break your Splunk installation.
"SplunkWeb" is port 8000.
---
If this reply helps you, Karma would be appreciated.
0 Karma

edgarsilva01
Path Finder

Hi richgalloway

The problem I have is that a scan was performed to one of the servers where a universal forwarder is installed and a vulnerability in port 8089 of the splunk service was detected.

To solve this problem, a digital certificate was requested, upload it to the deployment server, in a second scan the vulnerability is still active

0 Karma

richgalloway
SplunkTrust
SplunkTrust
You don't say what vulnerability was reported, but perhaps this answer will solve your problem: https://community.splunk.com/t5/Security/Splunk-Enterprise-8089-Vulnerability-Scan-Results-Resolve-t...
It's not enough to put a certificate on the DS - it must be installed on the UF to protect the UF's management port.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...