<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failsafe user working? in Security</title>
    <link>https://community.splunk.com/t5/Security/Failsafe-user-working/m-p/16440#M493</link>
    <description>&lt;P&gt;If you recently migrated to version 4.1.x, your failsafe user (as configured in authentication.conf) is disabled.  The new failsafe user is "admin" and is accessible from the UI:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Manager &amp;gt;&amp;gt; Access Controls &amp;gt;&amp;gt; Users
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The default password is "changeme" and can be changed from the UI as well.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Jun 2010 00:41:25 GMT</pubDate>
    <dc:creator>the_wolverine</dc:creator>
    <dc:date>2010-06-30T00:41:25Z</dc:date>
    <item>
      <title>Failsafe user working?</title>
      <link>https://community.splunk.com/t5/Security/Failsafe-user-working/m-p/16436#M489</link>
      <description>&lt;P&gt;Hi folks.&lt;/P&gt;

&lt;P&gt;I have a Splunk setup to authenticate by LDAP, and this works reasonably well. Sometimes auth stops working for no apparent reason, and that's when this question becomes interesting.&lt;/P&gt;

&lt;P&gt;I can't get the "failsafe" user in LDAP conf to work. Dos this function as intended for anyone?
If so, how do i make it work? Currently any attempt to log on as the user listed as failsafe user in the LDAP config just returns the normal authentication failed message.&lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2010 21:13:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Failsafe-user-working/m-p/16436#M489</guid>
      <dc:creator>hcpr</dc:creator>
      <dc:date>2010-06-29T21:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Failsafe user working?</title>
      <link>https://community.splunk.com/t5/Security/Failsafe-user-working/m-p/16437#M490</link>
      <description>&lt;P&gt;Which version of Splunk are you using?  I am currently on 4.1.2 and you can have both local and ldap users in the Splunk system.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2010 00:09:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Failsafe-user-working/m-p/16437#M490</guid>
      <dc:creator>treinke</dc:creator>
      <dc:date>2010-06-30T00:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: Failsafe user working?</title>
      <link>https://community.splunk.com/t5/Security/Failsafe-user-working/m-p/16438#M491</link>
      <description>&lt;P&gt;You should check the splunkd.log for why the LDAP authentication fails.  If all of the LDAP auth fails, then there is likely a problem with your connectivity to the system.  You should ensure that you are not using an alias for the LDAP host and that your LDAP server is not returning referrals.&lt;/P&gt;

&lt;P&gt;Additionally, if you manually copied the authentication configuration from another machine then you will need to re-enter the passwords so they are encrypted with the correct key.  &lt;/P&gt;

&lt;P&gt;Another possible condition is that your failsafe username exists in your LDAP system, thus causing a conflict.  You should make sure the failsafe username is unique.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2010 00:31:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Failsafe-user-working/m-p/16438#M491</guid>
      <dc:creator>Simeon</dc:creator>
      <dc:date>2010-06-30T00:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: Failsafe user working?</title>
      <link>https://community.splunk.com/t5/Security/Failsafe-user-working/m-p/16439#M492</link>
      <description>&lt;P&gt;Please detail the version of Splunk you are using, as 4.0 differs from 4.1.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2010 00:31:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Failsafe-user-working/m-p/16439#M492</guid>
      <dc:creator>Simeon</dc:creator>
      <dc:date>2010-06-30T00:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Failsafe user working?</title>
      <link>https://community.splunk.com/t5/Security/Failsafe-user-working/m-p/16440#M493</link>
      <description>&lt;P&gt;If you recently migrated to version 4.1.x, your failsafe user (as configured in authentication.conf) is disabled.  The new failsafe user is "admin" and is accessible from the UI:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Manager &amp;gt;&amp;gt; Access Controls &amp;gt;&amp;gt; Users
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The default password is "changeme" and can be changed from the UI as well.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2010 00:41:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Failsafe-user-working/m-p/16440#M493</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-06-30T00:41:25Z</dc:date>
    </item>
  </channel>
</rss>

