Security

Impact of certificate expiry

rohitvjoshi
Path Finder

Hi all,

We have checked the Splunk certificate on the below 2 locations:
1.$splunk_Home/etc/auth/server.pem
2.$splunk_Home/etc/auth/spunkweb/cert.pem

All the certs are showing enddate this month.

This I saw in all my Indexers,SH,CM,LS,Deployer,DM. Can you please help me to understand the impact due to this?

What is the process I have to follow to renew the cert?

0 Karma

rohitvjoshi
Path Finder

We went through the above scenario, there is no such impact in Splunk processing. It will generate soft waring i.e.-SSL certificates expired on XXX server.
if we check the logs (metrics.logs or mongod.logs we can see the message).

cheers

0 Karma

kmarciniak
Path Finder

We experienced the same results with half of our internal splunk certs expired. That is, all processes keep running, there were no TCP errors in logs, just that one log message Server certificate is now invalid. It expired on Sat xxxx. Traffic also still looks encrypted.

0 Karma

nickhills
Ultra Champion

Certificate expiry is a 'soft fail' in Splunk.

What this means is that expired or invalid certificates generally will not cause your deployment to fail.
You can form your own opinion if this is a good or a bad thing.

However, your question suggests that you are using the default Splunk certificates, and you should be aware that since these are common across many thousands of deployments, the private keys for these certs are widely shared, and should not be considered to provide any element of 'privacy' in your Splunk communications.

Good practice dictates that you should issue&manage your own certificates (internal or commercial) and keep them valid - meaning correct hostnames, valid CA issue chains, and within expiry.

See this excellent slide deck from .conf 15 for a step by step process to manage your own certs
https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPr...

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...