<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: logging in with local admin while SSO is enabled. in Security</title>
    <link>https://community.splunk.com/t5/Security/logging-in-with-local-admin-while-SSO-is-enabled/m-p/81869#M2731</link>
    <description>&lt;P&gt;You can login with the local admin user. You need to set SSOMode = permissive.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;Permissive: Requests to Splunk Web that originate from an untrusted IP address &lt;BR /&gt;
     are redirected to a login page where they can log into Splunk without using SSO.&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2013 14:09:43 GMT</pubDate>
    <dc:creator>alacercogitatus</dc:creator>
    <dc:date>2013-07-02T14:09:43Z</dc:date>
    <item>
      <title>logging in with local admin while SSO is enabled.</title>
      <link>https://community.splunk.com/t5/Security/logging-in-with-local-admin-while-SSO-is-enabled/m-p/81866#M2728</link>
      <description>&lt;P&gt;We have splunk instance enabled with SSO using CA siteminder. The user authorization is using splunk user config. All users configured with splunk are able to authenticate and authorize correctly. Keeping SSO enabled, is there anyway we can login to splunk using the local admin account of splunk? &lt;/P&gt;

&lt;P&gt;We are accessing splunk via the proxy URL and direct URL of splunk would give SSO error.&lt;/P&gt;

&lt;P&gt;this is the web.conf and server.conf configuration&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;web.conf&lt;BR /&gt;
[settings]&lt;BR /&gt;
\#SSO&lt;BR /&gt;
SSOMode = strict&lt;BR /&gt;
trustedIP = 10.93.171.10&lt;BR /&gt;
remoteUser = Corpid&lt;BR /&gt;
\#tools.proxy.on = true&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;server.conf&lt;BR /&gt;
[general]&lt;BR /&gt;
trustedIP=127.0.0.1&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 11:33:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/logging-in-with-local-admin-while-SSO-is-enabled/m-p/81866#M2728</guid>
      <dc:creator>anoopambli</dc:creator>
      <dc:date>2013-07-02T11:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: logging in with local admin while SSO is enabled.</title>
      <link>https://community.splunk.com/t5/Security/logging-in-with-local-admin-while-SSO-is-enabled/m-p/81867#M2729</link>
      <description>&lt;P&gt;I guess it's not possible. You can assign one user, admin privilege. the local admin can access through splunk web default port. As LDAP will not find any name "admin" in your groups i suppose it's not possible.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 11:49:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/logging-in-with-local-admin-while-SSO-is-enabled/m-p/81867#M2729</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2013-07-02T11:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: logging in with local admin while SSO is enabled.</title>
      <link>https://community.splunk.com/t5/Security/logging-in-with-local-admin-while-SSO-is-enabled/m-p/81868#M2730</link>
      <description>&lt;P&gt;So that means once you have SSO enabled, you cant use the local account as that is not bound with any domain user account for authentication. The option left is to assign admin roles to one of the domain user who can authenticate. Is that correct?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 12:06:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/logging-in-with-local-admin-while-SSO-is-enabled/m-p/81868#M2730</guid>
      <dc:creator>anoopambli</dc:creator>
      <dc:date>2013-07-02T12:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: logging in with local admin while SSO is enabled.</title>
      <link>https://community.splunk.com/t5/Security/logging-in-with-local-admin-while-SSO-is-enabled/m-p/81869#M2731</link>
      <description>&lt;P&gt;You can login with the local admin user. You need to set SSOMode = permissive.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;Permissive: Requests to Splunk Web that originate from an untrusted IP address &lt;BR /&gt;
     are redirected to a login page where they can log into Splunk without using SSO.&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 14:09:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/logging-in-with-local-admin-while-SSO-is-enabled/m-p/81869#M2731</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-07-02T14:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: logging in with local admin while SSO is enabled.</title>
      <link>https://community.splunk.com/t5/Security/logging-in-with-local-admin-while-SSO-is-enabled/m-p/81870#M2732</link>
      <description>&lt;P&gt;You can with your default splunk web access port. which is by default 8000. Splunk authenticated user will be able to access through this. Others can use SSO like you have configured.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 15:49:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/logging-in-with-local-admin-while-SSO-is-enabled/m-p/81870#M2732</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2013-07-02T15:49:20Z</dc:date>
    </item>
  </channel>
</rss>

