All Apps and Add-ons

Disable SSL validation Tenable add-on

splunk_kk
Path Finder

Hi Team,

We are using certificates on our Tenable Security Center and have disabled SSL validation in splunk under tenable add-on. The config we have done is as below:

[tenable_sc_settings]
disable_ssl_certificate_validation = 1

Just wanted to know if it only disables the verification of identity of the server and the encryption still occurs? or is it something more than that?

Thanks!

0 Karma
1 Solution

xpac
SplunkTrust
SplunkTrust

Disabling SSL Certificate validation (in almost any product) usually means, do not:

  • Check if hostname and certificate SAN match
  • Check if the CA that issued the certificate is trusted
  • Check if the certificate has expired or has been revoked

Actually, it means "Do encryption, but don't care at all about who is on the other side - if the other side supports encryption, encrypt it."

View solution in original post

xpac
SplunkTrust
SplunkTrust

Disabling SSL Certificate validation (in almost any product) usually means, do not:

  • Check if hostname and certificate SAN match
  • Check if the CA that issued the certificate is trusted
  • Check if the certificate has expired or has been revoked

Actually, it means "Do encryption, but don't care at all about who is on the other side - if the other side supports encryption, encrypt it."

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...