Security

LDAP authentication to Search Head using Smart Card

joshua_hart1
Path Finder

My computing environment mandates authentication via smart card and has disabled username/password authentication to the domain. Does Splunk allow smart card auth to LDAP when logging into the search head?

0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

Splunk uses AD/LDAP filters and settings to login to the search head. If you want to use Smart Card authentication, you will want to use the proxy sso option. We have SSO enabled to use Windows credentials to login to the searchheads. Should work for smart card as well, as long as you are logged into the workstation with it. Depending on how user access is controlled, you will either need to connect it to AD for users/groups/roles mapping, or do everything by hand.

Note: set permissive SSO to false to force logins via the proxy. Otherwise, you can still login via a direct connection to the search head.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

Splunk uses AD/LDAP filters and settings to login to the search head. If you want to use Smart Card authentication, you will want to use the proxy sso option. We have SSO enabled to use Windows credentials to login to the searchheads. Should work for smart card as well, as long as you are logged into the workstation with it. Depending on how user access is controlled, you will either need to connect it to AD for users/groups/roles mapping, or do everything by hand.

Note: set permissive SSO to false to force logins via the proxy. Otherwise, you can still login via a direct connection to the search head.

lguinn2
Legend

Thanks for the answer! IHAC with a mandate for smart-card authentication (DOD CAC). Their mandate explicitly EXCLUDES a proxy solution.

Since this solution uses a proxy, it doesn't meet the requirements.
Any other ideas?

Thanks!

joshua_hart1
Path Finder

Thanks for the write-up. I'll see how our environment is set up and go from there.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...