Hello Team,
We are planning to upgrade Splunk Enterprise v6.5.1 to v7.1.2. I understand that we need to upgrade or make changes to SSL/TLS config as per http://docs.splunk.com/Documentation/Forwarder/7.1.2/Forwarder/Compatibilitybetweenforwardersandindexers
Current UF Version Deployed and connecting to Heavy Forwarders.
6.2.6
6.3.0
6.3.7
6.4.3
6.5.1
6.5.2
I am confused as in link it says to change the cipher suite on forwarder but when clicked on Known issue list it is not clear where to make the changes.
From Known issue:
SPL-141964 - For splunktcp-ssl - we are not using it
SPL-141961 - This seems to be applicable but it states "Upgrade your older instances to the latest maintenance releases or on your 6.6.x Splunk instances. Add the following stanza to server.conf:"
[sslConfig]
sslVersions = *,-ssl2
sslVersionsForClient = *,-ssl2
cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH
Can you advise what changes need to be done? I believe it is SPL-141961 but where this change need to be done IDX/HF/UF?
↧