<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: authentication.conf multiple authType values in Security</title>
    <link>https://community.splunk.com/t5/Security/authentication-conf-multiple-authType-values/m-p/53765#M1786</link>
    <description>&lt;P&gt;I ended up writing a script to do both. This actually turned out somewhat beneficial as I built the script to authenticate against PAM instead of LDAP. We use &lt;CODE&gt;sssd&lt;/CODE&gt; for authentication, so this gives the benefit that if LDAP goes down, splunk will use the offline caching mechanism of sssd for authentication and users will still be able to log in.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Sep 2013 14:01:09 GMT</pubDate>
    <dc:creator>phemmer</dc:creator>
    <dc:date>2013-09-06T14:01:09Z</dc:date>
    <item>
      <title>authentication.conf multiple authType values</title>
      <link>https://community.splunk.com/t5/Security/authentication-conf-multiple-authType-values/m-p/53763#M1784</link>
      <description>&lt;P&gt;I am wanting to set up multiple authentication types, both LDAP and scripted. I would thus need to somehow set multiple &lt;CODE&gt;authType&lt;/CODE&gt; values in the authentication.conf. However from reading the documentation on &lt;CODE&gt;authentication.conf&lt;/CODE&gt;, it does not indicate that this can be done. I just wanted to know if this is not possible, or if it's just not documented well.&lt;/P&gt;

&lt;P&gt;Basically I want to use both LDAP and scripted authentication. LDAP will be used for normal users, but we have some system processes which use splunk, and I want them to be authenticated by a script. The hope is that splunk will first try to authenticate off one source, and if that fails, try the next one.&lt;/P&gt;

&lt;P&gt;Worst case scenario I could move the LDAP authentication into the script so that it could then do both, but that's just ugly and I'm hoping to avoid it.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2013 17:42:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/authentication-conf-multiple-authType-values/m-p/53763#M1784</guid>
      <dc:creator>phemmer</dc:creator>
      <dc:date>2013-09-03T17:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: authentication.conf multiple authType values</title>
      <link>https://community.splunk.com/t5/Security/authentication-conf-multiple-authType-values/m-p/53764#M1785</link>
      <description>&lt;P&gt;I came to the same conclusion as you: it doesn't appear to be possible.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2013 03:00:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/authentication-conf-multiple-authType-values/m-p/53764#M1785</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2013-09-04T03:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: authentication.conf multiple authType values</title>
      <link>https://community.splunk.com/t5/Security/authentication-conf-multiple-authType-values/m-p/53765#M1786</link>
      <description>&lt;P&gt;I ended up writing a script to do both. This actually turned out somewhat beneficial as I built the script to authenticate against PAM instead of LDAP. We use &lt;CODE&gt;sssd&lt;/CODE&gt; for authentication, so this gives the benefit that if LDAP goes down, splunk will use the offline caching mechanism of sssd for authentication and users will still be able to log in.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2013 14:01:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/authentication-conf-multiple-authType-values/m-p/53765#M1786</guid>
      <dc:creator>phemmer</dc:creator>
      <dc:date>2013-09-06T14:01:09Z</dc:date>
    </item>
  </channel>
</rss>

