All Apps and Add-ons

Cisco IronPort - Splunk Integration (SCP Issue)

socespap
Explorer

Hi,

I am trying to integrate a Cisco ESA into splunk and I realized that I have constraints regarding to privileges related to the user that I am using. In this brief test I have been using 'root' but doesn't work properly

type=USER_AUTH msg=audit(1548086500.719:6438): pid=31410 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=10.150.0.11 terminal=ssh res=failed'

SSH folder was configures as 700 privileges, and authorized_keys file as 644.

Any idea about this issue?

Sincerely,

Vitor Leitao

Tags (1)
0 Karma

hcanivel_splunk
Splunk Employee
Splunk Employee

First of all, you should never be using root to SSH/SCP anything, especially if it's publicly facing infrastructure.
Secondly, can you even verify if SSH for root user is enabled? By default, your sshd should have that disabled.
Thirdly, what are your debug logs for both client and server? I would presume testing against root user is disabled for SSH access, but would like to see the actual reason for failure.

0 Karma

socespap
Explorer

Just to add the following log

Mon Jan 21 16:00:04 2019 Info: Appliance:xxxx, Interaction mode: SSH Client, User: *****, Dest IP: X.X.X.X:22, Event: SCP failed. Reason - Permission denied (publickey,password). lost connection
eventtype = cisco-security-events eventtype = err0r error host = XXXX source = /opt/splunk/etc/apps/Splunk_TA_cisco-esa/local/authentication.@20190121T160003.s sourcetype = cisco:esa:authentication

0 Karma

spodda01da
Path Finder

Hi socespap, Did you get it configured, I am too looking to configure via SCP but facing some challenges. Please do let me know how did you fix it.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...