<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic After configuring LDAP authentication with Active Directory in Splunk, why are LDAP user details for some users deleted after a login attempt? in Security</title>
    <link>https://community.splunk.com/t5/Security/After-configuring-LDAP-authentication-with-Active-Directory-in/m-p/143636#M4405</link>
    <description>&lt;P&gt;I have configured LDAP authentication with Active Directory on Splunk. We are still waiting on the group to role mapping, so currently we have mapped individual users to specific roles.&lt;/P&gt;

&lt;P&gt;However, 1 of the 5 users we have currently mapped is unable to login. When I add his username to the authentication.conf file, I see his username, Full name and email address under Settings-&amp;gt;Access controls-&amp;gt;Users&lt;/P&gt;

&lt;P&gt;When he tries to log in, he gets "Invalid username or password" and immediately after that, his details are no longer visible under Settings-&amp;gt;Access controls-&amp;gt;Users&lt;/P&gt;

&lt;P&gt;splunkd.log only shows &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;user=xxx action=login status=failure reason=user-initiated
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The password can't be invalid since he logs into his local machine with the same credentials. The other 4 users are able to log in successfully.&lt;BR /&gt;
Also, since I can see his 'Full Name' under  Settings-&amp;gt;Access controls-&amp;gt;Users , I don't think its a problem with his display name, either. &lt;/P&gt;</description>
    <pubDate>Tue, 14 Apr 2015 17:43:38 GMT</pubDate>
    <dc:creator>nivedita_viswan</dc:creator>
    <dc:date>2015-04-14T17:43:38Z</dc:date>
    <item>
      <title>After configuring LDAP authentication with Active Directory in Splunk, why are LDAP user details for some users deleted after a login attempt?</title>
      <link>https://community.splunk.com/t5/Security/After-configuring-LDAP-authentication-with-Active-Directory-in/m-p/143636#M4405</link>
      <description>&lt;P&gt;I have configured LDAP authentication with Active Directory on Splunk. We are still waiting on the group to role mapping, so currently we have mapped individual users to specific roles.&lt;/P&gt;

&lt;P&gt;However, 1 of the 5 users we have currently mapped is unable to login. When I add his username to the authentication.conf file, I see his username, Full name and email address under Settings-&amp;gt;Access controls-&amp;gt;Users&lt;/P&gt;

&lt;P&gt;When he tries to log in, he gets "Invalid username or password" and immediately after that, his details are no longer visible under Settings-&amp;gt;Access controls-&amp;gt;Users&lt;/P&gt;

&lt;P&gt;splunkd.log only shows &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;user=xxx action=login status=failure reason=user-initiated
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The password can't be invalid since he logs into his local machine with the same credentials. The other 4 users are able to log in successfully.&lt;BR /&gt;
Also, since I can see his 'Full Name' under  Settings-&amp;gt;Access controls-&amp;gt;Users , I don't think its a problem with his display name, either. &lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2015 17:43:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/After-configuring-LDAP-authentication-with-Active-Directory-in/m-p/143636#M4405</guid>
      <dc:creator>nivedita_viswan</dc:creator>
      <dc:date>2015-04-14T17:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: After configuring LDAP authentication with Active Directory in Splunk, why are LDAP user details for some users deleted after a login attempt?</title>
      <link>https://community.splunk.com/t5/Security/After-configuring-LDAP-authentication-with-Active-Directory-in/m-p/143637#M4406</link>
      <description>&lt;P&gt;It turns out that this only happened for users who had capital letters in their LDAP usernames. I had initially configured the role mapping assuming case sensitivity. So I had&lt;/P&gt;

&lt;P&gt;admin = User1, user2, usEr3&lt;/P&gt;

&lt;P&gt;Thought the users could log into their systems irrespective of the case, they were unable to log into splunk. I changed the mapping so that all usernames had lower case letters:&lt;/P&gt;

&lt;P&gt;admin=user1,user2,user3&lt;/P&gt;

&lt;P&gt;This seemed to fix the issue, and all users can now log into Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 21:27:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/After-configuring-LDAP-authentication-with-Active-Directory-in/m-p/143637#M4406</guid>
      <dc:creator>nivedita_viswan</dc:creator>
      <dc:date>2015-04-28T21:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: After configuring LDAP authentication with Active Directory in Splunk, why are LDAP user details for some users deleted after a login attempt?</title>
      <link>https://community.splunk.com/t5/Security/After-configuring-LDAP-authentication-with-Active-Directory-in/m-p/143638#M4407</link>
      <description>&lt;P&gt;You just saved me, made some permission changes , roles etc... and if you have the LDAP in uppercase letters it fails. &lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 16:31:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/After-configuring-LDAP-authentication-with-Active-Directory-in/m-p/143638#M4407</guid>
      <dc:creator>mendesjo</dc:creator>
      <dc:date>2017-04-17T16:31:48Z</dc:date>
    </item>
  </channel>
</rss>

