Receiving EMS Not Enabled Error when using TLS while forwarding logs to Splunk in RHOCP 4
Issue
- Logs are not forwarding to
Splunk
destination due to SSL/TLS related problems. -
Collector pods are continuously streaming below warning message:
YYYY-MM-DDTHH:MM:SS.XXXX0Z WARN vector::internal_events::http_client: HTTP error. error=error trying to connect: error:1C8000E9:Provider routines:kdf_tls1_prf_derive:ems not enabled:providers/implementations/kdfs/tls1_prf.c:200:, error:0A08010C:SSL routines:tls1_PRF:unsupported:ssl/t1_enc.c:83: error_type="request_failed" stage="processing" internal_log_rate_limit=true
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- Red Hat OpenShift Logging (RHOL)
- 5.8+
- Splunk
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.