I am using my own cert to send events from UF to Indexer. Evens are coming in and everything is working fine. However, when I restart the forwarder I always see the following entry:
SSLCommon - Can't read key file C:\Program Files\SplunkUniversalForwarder\etc\auth\server.pem
HTTPServer - SSL context could not be created - error in cert or password is wrong
HTTPServer - SSL will not be enabled
The traffic between UF and Indexer is being encrypted with my cert and so far nothing wrong is apparent. Is this safe to ignore?