Monitoring Splunk

Disabling CBC mode ciphers

lal37
Explorer

Hi Team,

SSLv3.0/TLSv1.0 Protocol Weak CBC Mode vulnerability have been identified on Splunk during internal scan.
The internal PA team asked us to upgrade to TLSv1.1 or TLSv1.2,if not possible to upgrade they asked us to disable CBC mode ciphers.
It could be better if you could guide us to fix the issue.strong text

Regards,
Shiva

Tags (1)

hsesterhenn_spl
Splunk Employee
Splunk Employee

Just an update to make sure people use the current options: (v7.3+)

https://docs.splunk.com/Documentation/Splunk/latest/Security/Ciphersuites

HTH,

Holger

0 Karma

dwaddle
SplunkTrust
SplunkTrust

For Splunkd (port 8089 by default) - the proper setting of cipher suites is in server.conf under the sslConfig stanza, set the cipherSuite option using a valid OpenSSL cipher suite specification. See http://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf

For splunkweb, there are similar settings in web.conf.

lal37
Explorer

Hi dawadle,

I would like to know how we can replace SSL version to TLS version.
I guess by default splunk is using SSL encryption.
Please advice.

Thanks and Regards,
Shiva

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...