Security

Impact of certificate expiry

rohitvjoshi
Path Finder

Hi all,

We have checked the Splunk certificate on the below 2 locations:
1.$splunk_Home/etc/auth/server.pem
2.$splunk_Home/etc/auth/spunkweb/cert.pem

All the certs are showing enddate this month.

This I saw in all my Indexers,SH,CM,LS,Deployer,DM. Can you please help me to understand the impact due to this?

What is the process I have to follow to renew the cert?

0 Karma

rohitvjoshi
Path Finder

We went through the above scenario, there is no such impact in Splunk processing. It will generate soft waring i.e.-SSL certificates expired on XXX server.
if we check the logs (metrics.logs or mongod.logs we can see the message).

cheers

0 Karma

kmarciniak
Path Finder

We experienced the same results with half of our internal splunk certs expired. That is, all processes keep running, there were no TCP errors in logs, just that one log message Server certificate is now invalid. It expired on Sat xxxx. Traffic also still looks encrypted.

0 Karma

nickhills
Ultra Champion

Certificate expiry is a 'soft fail' in Splunk.

What this means is that expired or invalid certificates generally will not cause your deployment to fail.
You can form your own opinion if this is a good or a bad thing.

However, your question suggests that you are using the default Splunk certificates, and you should be aware that since these are common across many thousands of deployments, the private keys for these certs are widely shared, and should not be considered to provide any element of 'privacy' in your Splunk communications.

Good practice dictates that you should issue&manage your own certificates (internal or commercial) and keep them valid - meaning correct hostnames, valid CA issue chains, and within expiry.

See this excellent slide deck from .conf 15 for a step by step process to manage your own certs
https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPr...

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...