resolved this issue for myself, I'm probably a different case since this issue was around my odd "proxy" Convert zscaler certificate to .pem openssl x509 -in ZscalerRootCertificate-2048-SHA256.crt -out zscaler.pem -outform PEM Insert .pem into o365 app cacert cat zscaler.pem >> /opt/splunk/etc/apps/splunk_ta_o365/bin/3rdparty/certifi/cacert.pem Ensure ownership chown splunk.splunk * Restart splunk systemctl restart splunk Add tenant This might be useful for anyone else with certificate issues.
... View more