<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Puppet'ising configuration files but stuck on password hashes. in Security</title>
    <link>https://community.splunk.com/t5/Security/Puppet-ising-configuration-files-but-stuck-on-password-hashes/m-p/129407#M14545</link>
    <description>&lt;P&gt;i'm having this same issue.  anyone from splunk know?&lt;/P&gt;</description>
    <pubDate>Thu, 13 Apr 2017 15:23:13 GMT</pubDate>
    <dc:creator>tragiccode</dc:creator>
    <dc:date>2017-04-13T15:23:13Z</dc:date>
    <item>
      <title>Puppet'ising configuration files but stuck on password hashes.</title>
      <link>https://community.splunk.com/t5/Security/Puppet-ising-configuration-files-but-stuck-on-password-hashes/m-p/129406#M14544</link>
      <description>&lt;P&gt;I am trying to have Puppet automate the deployment of Splunk in my environment(s), however I do not know the password hashing algorithm Splunk uses (as of Splunk Enterprise v6.2.2) to dynamically add hashes directly to configuration files.&lt;/P&gt;

&lt;P&gt;Does anyone know the algorithm?&lt;/P&gt;

&lt;P&gt;I've tried using openssl and guessing the hash, e.g. SHA1/256/512, MD5, but the output is not the same since the strings are alphanumeric whereas the hashes in the Splunk configuration files are a mix of alpha and non-alphanumeric characters.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2015 11:44:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Puppet-ising-configuration-files-but-stuck-on-password-hashes/m-p/129406#M14544</guid>
      <dc:creator>hamiltonb</dc:creator>
      <dc:date>2015-05-28T11:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Puppet'ising configuration files but stuck on password hashes.</title>
      <link>https://community.splunk.com/t5/Security/Puppet-ising-configuration-files-but-stuck-on-password-hashes/m-p/129407#M14545</link>
      <description>&lt;P&gt;i'm having this same issue.  anyone from splunk know?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2017 15:23:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Puppet-ising-configuration-files-but-stuck-on-password-hashes/m-p/129407#M14545</guid>
      <dc:creator>tragiccode</dc:creator>
      <dc:date>2017-04-13T15:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Puppet'ising configuration files but stuck on password hashes.</title>
      <link>https://community.splunk.com/t5/Security/Puppet-ising-configuration-files-but-stuck-on-password-hashes/m-p/129408#M14546</link>
      <description>&lt;P&gt;One of the method to resolve the issue is to get the password hashed the same way on each instance.&lt;BR /&gt;
To achieve this, you need to unify your splunk.secret key (in $SPLUNK_HOME/etc/auth/splunk.secret. )&lt;/P&gt;

&lt;P&gt;Then when you prepare your config on a separate server that has the same splunk.secret , you restart splunk to apply them, and get the password encrypted in the local folders. Then you can push this pre-hashed  file that all the other servers will be able to read.&lt;/P&gt;

&lt;P&gt;see &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Security/Deploysecurepasswordsacrossmultipleservers" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Security/Deploysecurepasswordsacrossmultipleservers&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Preferably before you start splunk the first time.&lt;BR /&gt;
Or if you do change it afterward, you will have to clear some files to have them being rehashed. &lt;BR /&gt;
in $SPLUNK_HOME/etc/passwd $SPLUNK_HOME/etc/system/local/server.conf &lt;BR /&gt;
and optionally authentication.conf, outputs.conf, inputs.conf, and other special apps passwords fields.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:40:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Puppet-ising-configuration-files-but-stuck-on-password-hashes/m-p/129408#M14546</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2020-09-29T13:40:22Z</dc:date>
    </item>
  </channel>
</rss>

