Each indexer needs a certificate installed & configured, yes. But that certificate can have multiple SANs for each of your indexers. That way there is only one certificate to renew when the time comes. But for your indexers to accept SSL connections from another Splunk instance (Server or forwarder) it needs a certificate as well. Luckily the forwarder can utilize any certificate you obtained for your Splunk servers. It doesn't have to be the indexer's certificate but that one is readily available I assume?
... View more