Security

roleMap got updated to etc/system/local/authentication.conf during restart or reload auth

daniel_splunk
Splunk Employee
Splunk Employee

I've an app called auth_conf which is used to define authentication.conf.

For example,
etc/apps/auth_conf/local/authentication.conf
[roleMap_LDAP_Authentication_IT]
admin = a001,a002
power = p001

However, sometimes, the roleMap is copied to etc/system/local/authentication.conf and the content like this.
etc/system/local/authentication.conf
[roleMap_LDAP_Authentication_IT]
admin = a001
power = p001

Remarks: I'm not using LDAP group, users are configured individually.

Tags (2)
1 Solution

daniel_splunk
Splunk Employee
Splunk Employee

When you restart splunkd or run 'splunk reload auth', splunk will check each of the users from authentication.conf against LDAP server.

If all of the user exist in the server, then, it would leave it as is.

However, if there are some users which are missing from the LDAP server, it will remove that user from the roleMap and then the new copy will be written to etc/system/local/authentication.conf

From the log, you will see somthing like this.

03-10-2015 13:52:46.360 +0800 WARN  AuthenticationManagerLDAP - strategy="ldap_user" The group="a002" was not found on the LDAP server, removing it from the role map

View solution in original post

daniel_splunk
Splunk Employee
Splunk Employee

When you restart splunkd or run 'splunk reload auth', splunk will check each of the users from authentication.conf against LDAP server.

If all of the user exist in the server, then, it would leave it as is.

However, if there are some users which are missing from the LDAP server, it will remove that user from the roleMap and then the new copy will be written to etc/system/local/authentication.conf

From the log, you will see somthing like this.

03-10-2015 13:52:46.360 +0800 WARN  AuthenticationManagerLDAP - strategy="ldap_user" The group="a002" was not found on the LDAP server, removing it from the role map

daniel_splunk
Splunk Employee
Splunk Employee

This behavior will be changed from 6.2.3 tentatively. A warning message will be logged instead.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...