Monitoring Splunk

Disabling CBC mode ciphers

lal37
Explorer

Hi Team,

SSLv3.0/TLSv1.0 Protocol Weak CBC Mode vulnerability have been identified on Splunk during internal scan.
The internal PA team asked us to upgrade to TLSv1.1 or TLSv1.2,if not possible to upgrade they asked us to disable CBC mode ciphers.
It could be better if you could guide us to fix the issue.strong text

Regards,
Shiva

Tags (1)

hsesterhenn_spl
Splunk Employee
Splunk Employee

Just an update to make sure people use the current options: (v7.3+)

https://docs.splunk.com/Documentation/Splunk/latest/Security/Ciphersuites

HTH,

Holger

0 Karma

dwaddle
SplunkTrust
SplunkTrust

For Splunkd (port 8089 by default) - the proper setting of cipher suites is in server.conf under the sslConfig stanza, set the cipherSuite option using a valid OpenSSL cipher suite specification. See http://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf

For splunkweb, there are similar settings in web.conf.

lal37
Explorer

Hi dawadle,

I would like to know how we can replace SSL version to TLS version.
I guess by default splunk is using SSL encryption.
Please advice.

Thanks and Regards,
Shiva

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...