Security

Can Splunk or an app notify a user and provide a reset option if LDAP password expires and their account is locked after failed logins?

cdstealer
Contributor

Hi,

My company's LDAP authentication is set to expire all user passwords every 30 days to meet PCI-DSS requirements. However, splunk does not return any errors when this happens, so the end user repeatedly tries to login which then locks their account. I'm unsure if there is anything within splunk or if an app exists that will notify the user of the login error and offer the option to them to reset their password. I've had a search around, but can see nothing. Has anyone here come across this?

Thanks in advance.
Steve

Tags (3)
0 Karma
1 Solution

grijhwani
Motivator

Splunk only makes a query to validate the user/password. All it knows is that it cannot match the credentials. It knows nothing about why, merely that it fails. At work we used to suffer the exact same issue, for the exact same reason, save that in most cases because we authenticated against the Active Directory LDAP and most users were Windoze users they would be aware of their credential expiry by other more informative means before ever encountering it in Splunk.

View solution in original post

grijhwani
Motivator

Splunk only makes a query to validate the user/password. All it knows is that it cannot match the credentials. It knows nothing about why, merely that it fails. At work we used to suffer the exact same issue, for the exact same reason, save that in most cases because we authenticated against the Active Directory LDAP and most users were Windoze users they would be aware of their credential expiry by other more informative means before ever encountering it in Splunk.

MuS
SplunkTrust
SplunkTrust

You could do it a bit less awkward if you setup / use a SSO http://docs.splunk.com/Documentation/Splunk/6.1.3/Security/HowSplunkSSOworks for your Splunk server

0 Karma

cdstealer
Contributor

Many thanks for the info. That does make things rather awkward. 😞 Ah well.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...