<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP authentication caching in Security</title>
    <link>https://community.splunk.com/t5/Security/LDAP-authentication-caching/m-p/58772#M1956</link>
    <description>&lt;P&gt;Hi;&lt;/P&gt;

&lt;P&gt;Seems like, with LDAP integrated and roles mapped to LDAP groups, Splunk will update its cached list of users and their roles only when a splunkweb session starts--ie, if we add a user to a mapped role, this does not show up in Manage &amp;gt; Access Controls &amp;gt; Users, but after that user logs in, he/she now shows up in that list.&lt;/P&gt;

&lt;P&gt;On the other hand, if we make changes to that user's role, and he/she is currently logged into splunk web, that change will not take effect unless they log out and back in--correct?&lt;/P&gt;

&lt;P&gt;We know we can hit manage &amp;gt; Access Controls &amp;gt; Authentication method &amp;gt; Reload authentication method to reset, but:&lt;/P&gt;

&lt;P&gt;a) is there any setting in authentication.conf or limits.conf to make this happen on a periodic basis?&lt;/P&gt;

&lt;P&gt;b) we see that according to &lt;A href="http://blogs.splunk.com/2009/08/20/reload-4-auth/"&gt;http://blogs.splunk.com/2009/08/20/reload-4-auth/&lt;/A&gt;, we can do this via a cron job, but is this still best practice in 5.0 +?&lt;/P&gt;

&lt;P&gt;thanks,&lt;BR /&gt;
bw&lt;/P&gt;</description>
    <pubDate>Tue, 10 Sep 2013 13:50:31 GMT</pubDate>
    <dc:creator>bobwalden</dc:creator>
    <dc:date>2013-09-10T13:50:31Z</dc:date>
    <item>
      <title>LDAP authentication caching</title>
      <link>https://community.splunk.com/t5/Security/LDAP-authentication-caching/m-p/58772#M1956</link>
      <description>&lt;P&gt;Hi;&lt;/P&gt;

&lt;P&gt;Seems like, with LDAP integrated and roles mapped to LDAP groups, Splunk will update its cached list of users and their roles only when a splunkweb session starts--ie, if we add a user to a mapped role, this does not show up in Manage &amp;gt; Access Controls &amp;gt; Users, but after that user logs in, he/she now shows up in that list.&lt;/P&gt;

&lt;P&gt;On the other hand, if we make changes to that user's role, and he/she is currently logged into splunk web, that change will not take effect unless they log out and back in--correct?&lt;/P&gt;

&lt;P&gt;We know we can hit manage &amp;gt; Access Controls &amp;gt; Authentication method &amp;gt; Reload authentication method to reset, but:&lt;/P&gt;

&lt;P&gt;a) is there any setting in authentication.conf or limits.conf to make this happen on a periodic basis?&lt;/P&gt;

&lt;P&gt;b) we see that according to &lt;A href="http://blogs.splunk.com/2009/08/20/reload-4-auth/"&gt;http://blogs.splunk.com/2009/08/20/reload-4-auth/&lt;/A&gt;, we can do this via a cron job, but is this still best practice in 5.0 +?&lt;/P&gt;

&lt;P&gt;thanks,&lt;BR /&gt;
bw&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2013 13:50:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-authentication-caching/m-p/58772#M1956</guid>
      <dc:creator>bobwalden</dc:creator>
      <dc:date>2013-09-10T13:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication caching</title>
      <link>https://community.splunk.com/t5/Security/LDAP-authentication-caching/m-p/58773#M1957</link>
      <description>&lt;P&gt;We're encountering strange issues with LDAP in version 5 and have implemented our workaround which is scripting of the auth reload command on a regular basis.   &lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2014 18:20:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-authentication-caching/m-p/58773#M1957</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2014-06-17T18:20:25Z</dc:date>
    </item>
  </channel>
</rss>

