<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Splunk not support LDAP group inheritance? in Security</title>
    <link>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16689#M511</link>
    <description>&lt;P&gt;Correct, Splunk does not support nested groups currently.  Splunk users will need to be a direct member of the LDAP group mapped to Splunk role.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jul 2010 05:46:30 GMT</pubDate>
    <dc:creator>the_wolverine</dc:creator>
    <dc:date>2010-07-02T05:46:30Z</dc:date>
    <item>
      <title>Does Splunk not support LDAP group inheritance?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16688#M510</link>
      <description>&lt;P&gt;The way LDAP and Active Directory group membership usually works is through inheritance - groups can be members of other groups, and these subgroups' members are then effectively members of the higher level group. Its tree structure and inheritance are one of the benefits of using LDAP.&lt;/P&gt;

&lt;P&gt;I have just created two AD groups for Splunk, one with individual staff records as members, and the other with sub groups as members (in this case, our department/team groups that we use for access across all other apps). The latter is better, because it means that each time someone leaves or joins the team, the Splunk group does not have to be changed. It will just inherit the changes from the team groups.&lt;/P&gt;

&lt;P&gt;However, Splunk does not seem to understand the inheritance - members of the first group are the only ones who are allowed to access the app that has been secured to these two groups. The others get the message "App "ig_pci" does not support UI access. See its app.conf for more information".&lt;/P&gt;

&lt;P&gt;Does Splunk not support LDAP group inheritance?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2010 00:00:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16688#M510</guid>
      <dc:creator>Glenn</dc:creator>
      <dc:date>2010-07-02T00:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk not support LDAP group inheritance?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16689#M511</link>
      <description>&lt;P&gt;Correct, Splunk does not support nested groups currently.  Splunk users will need to be a direct member of the LDAP group mapped to Splunk role.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2010 05:46:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16689#M511</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-07-02T05:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk not support LDAP group inheritance?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16690#M512</link>
      <description>&lt;P&gt;Thanks. Do you think it is worth raising an enhancement request for it, or do you know if it already planned? It would make user management so much better if people could use their existing automatically managed team groups, rather than double handling.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2010 13:08:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16690#M512</guid>
      <dc:creator>Glenn</dc:creator>
      <dc:date>2010-07-02T13:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk not support LDAP group inheritance?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16691#M513</link>
      <description>&lt;P&gt;Yes, it is always worth filing an enhancement request for features that you would like to see in the product.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2010 13:18:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16691#M513</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-07-02T13:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk not support LDAP group inheritance?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16692#M514</link>
      <description>&lt;P&gt;I have had an enhancement request (45531) in for this functionality since &lt;STRONG&gt;Jul 8, 2010 7:08 AM&lt;/STRONG&gt; (yes that's about 16 months).&lt;/P&gt;

&lt;P&gt;It wastes a couple of hours of time for a few people in my organisation each week, due to them having to assign individual members (new starters) to the groups, rather than them automatically being included for appropriate access via their team's role group. Over the course of the last 2 years this probably adds up to quite a large operating cost!&lt;/P&gt;

&lt;P&gt;Please include this enhancement soon. How can we get its priority raised?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2011 12:59:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16692#M514</guid>
      <dc:creator>Glenn</dc:creator>
      <dc:date>2011-10-11T12:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk not support LDAP group inheritance?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16693#M515</link>
      <description>&lt;P&gt;This feature is available in the forthcoming Splunk Release, you can request for a beta evaluation from the PMs now. &lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2011 17:55:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16693#M515</guid>
      <dc:creator>ithangasamy_spl</dc:creator>
      <dc:date>2011-10-11T17:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk not support LDAP group inheritance?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16694#M516</link>
      <description>&lt;P&gt;Sweet, thanks for the update. That would be 4.2.4?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2011 20:19:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16694#M516</guid>
      <dc:creator>Glenn</dc:creator>
      <dc:date>2011-10-11T20:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk not support LDAP group inheritance?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16695#M517</link>
      <description>&lt;P&gt;it would be 4.3&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2011 20:37:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-not-support-LDAP-group-inheritance/m-p/16695#M517</guid>
      <dc:creator>ithangasamy_spl</dc:creator>
      <dc:date>2011-10-11T20:37:26Z</dc:date>
    </item>
  </channel>
</rss>

