Security

Upgrading a LWF to a Universal Forwarder 4.1.6 to 4.2.5, we get SSL errors

sgarvin55
Splunk Employee
Splunk Employee

ERROR TcpOutputProc - Error initializing SSL context - invalid sslCertPath for server xx.xx.xx.x1:9997

ERROR SSLCommon - Can't read key file /opt/splunkforwarder/etc/apps/ku-certs/forwarder.pem errno=101077092 error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt.

ERROR TcpOutputProc - Error initializing SSL context - invalid sslCertPath for server xx.xx.xx.x2:9997

ERROR SSLCommon - Can't read key file /opt/splunkforwarder/etc/apps/ku-certs/forwarder.pem errno=101077092 error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt.

ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.

Verified certpath, verified outputs.conf. Still unable to connect to indexer.

Tags (1)
1 Solution

sgarvin55
Splunk Employee
Splunk Employee

After verifying the certpath and the outputs.conf file. I edited the outputs.conf and removed the encrypted SSLPassword. Added the cleartext password in its place and restarted the forwarder. This encrypted the SSLPassword and the forwarder connected with the indexer successfully.

View solution in original post

sgarvin55
Splunk Employee
Splunk Employee

After verifying the certpath and the outputs.conf file. I edited the outputs.conf and removed the encrypted SSLPassword. Added the cleartext password in its place and restarted the forwarder. This encrypted the SSLPassword and the forwarder connected with the indexer successfully.

Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...