<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How are passwords encrypted in Splunk? in Security</title>
    <link>https://community.splunk.com/t5/Security/How-are-passwords-encrypted-in-Splunk/m-p/75318#M2518</link>
    <description>&lt;P&gt;There is no way for the root user to reverse the passwords. However, someone with access to &lt;CODE&gt;$SPLUNK_HOME/etc/passwd&lt;/CODE&gt; could edit the file with a text editor, removing users altogether. If all users are removed (usually by renaming the &lt;CODE&gt;passwd&lt;/CODE&gt; file) then the default Splunk login becomes whatever was specified in &lt;CODE&gt;user-seed.conf&lt;/CODE&gt;. This is usually user: &lt;EM&gt;admin&lt;/EM&gt; and password: &lt;EM&gt;changeme&lt;/EM&gt;.&lt;/P&gt;

&lt;P&gt;I believe that the actual encryption is based on the Unix crypt(3) routine, which is a one-way hash function based upon a modified DES algorithm. But I could be wrong...&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jan 2013 03:04:11 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2013-01-02T03:04:11Z</dc:date>
    <item>
      <title>How are passwords encrypted in Splunk?</title>
      <link>https://community.splunk.com/t5/Security/How-are-passwords-encrypted-in-Splunk/m-p/75317#M2517</link>
      <description>&lt;P&gt;What method is used to protect and encrypt passwords in Splunk. For example the "Users" passwords (when Local type of accounts are used).&lt;/P&gt;

&lt;P&gt;Is there a way for a root user of the Splunk server to reverse the passwords to plain text?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jan 2013 01:48:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-are-passwords-encrypted-in-Splunk/m-p/75317#M2517</guid>
      <dc:creator>alexander_lucas</dc:creator>
      <dc:date>2013-01-02T01:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: How are passwords encrypted in Splunk?</title>
      <link>https://community.splunk.com/t5/Security/How-are-passwords-encrypted-in-Splunk/m-p/75318#M2518</link>
      <description>&lt;P&gt;There is no way for the root user to reverse the passwords. However, someone with access to &lt;CODE&gt;$SPLUNK_HOME/etc/passwd&lt;/CODE&gt; could edit the file with a text editor, removing users altogether. If all users are removed (usually by renaming the &lt;CODE&gt;passwd&lt;/CODE&gt; file) then the default Splunk login becomes whatever was specified in &lt;CODE&gt;user-seed.conf&lt;/CODE&gt;. This is usually user: &lt;EM&gt;admin&lt;/EM&gt; and password: &lt;EM&gt;changeme&lt;/EM&gt;.&lt;/P&gt;

&lt;P&gt;I believe that the actual encryption is based on the Unix crypt(3) routine, which is a one-way hash function based upon a modified DES algorithm. But I could be wrong...&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jan 2013 03:04:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-are-passwords-encrypted-in-Splunk/m-p/75318#M2518</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-01-02T03:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: How are passwords encrypted in Splunk?</title>
      <link>https://community.splunk.com/t5/Security/How-are-passwords-encrypted-in-Splunk/m-p/75319#M2519</link>
      <description>&lt;P&gt;You can see the information on the algorithms used in etc/passwd in etc/system/README/authentication.conf.spec and etc/system/default/authentication.conf&lt;/P&gt;

&lt;P&gt;At the time of this answer, (5.0.x), Splunk was using MD5 with a large number of rounds.  Currently we are using SHA512.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2015 22:27:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-are-passwords-encrypted-in-Splunk/m-p/75319#M2519</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2015-03-03T22:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: How are passwords encrypted in Splunk?</title>
      <link>https://community.splunk.com/t5/Security/How-are-passwords-encrypted-in-Splunk/m-p/541397#M12109</link>
      <description>&lt;P&gt;Is Splunk still using the same encryption today or has it changed in spunk 7.x?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 17:49:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-are-passwords-encrypted-in-Splunk/m-p/541397#M12109</guid>
      <dc:creator>pbarbuto</dc:creator>
      <dc:date>2021-02-25T17:49:11Z</dc:date>
    </item>
  </channel>
</rss>

