All Apps and Add-ons

Why am I receiving "SL: CERTIFICATE_VERIFY_FAILED" errors after configuring the "Splunk_TA_nessus" add-on?

jmaple
Communicator

I have configured the SSL certificate according to instructions of the TA.

  • Copy the URL of Security Center and paste it to the Firefox browser.
  • Click View Page Info > Security > View Certificate > Details > Export as PEM file.
  • Copy the content of the PEM file into $SPLUNK_HOME/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/httplib2/cacerts.txt and then save.

I've attempted to append the additional certificate information to the existing file as well as remove all contents except my extracted cert and the result is the same. How am I supposed to add this certificate in accordance with these instructions?

http://docs.splunk.com/Documentation/AddOns/released/Nessus/ConfigureModularInput2#Check_the_warning...

0 Karma
1 Solution

jmaple
Communicator

After doing another export of the certificate, I change my "X.509 Certificate" option to be "X.509 Certificate with chain" as we have a cert chain in our environment and the problem looks to have resolved. Now I just have to figure out if the lack of data is representative of no data coming from Nessus or another issue.

alt text

View solution in original post

jmaple
Communicator

After doing another export of the certificate, I change my "X.509 Certificate" option to be "X.509 Certificate with chain" as we have a cert chain in our environment and the problem looks to have resolved. Now I just have to figure out if the lack of data is representative of no data coming from Nessus or another issue.

alt text

nagendra0911
New Member

did you remove previous certificate in conf file?
in my case i added both and error is still present

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...