<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Splunk LDAP support STARTTLS? in Security</title>
    <link>https://community.splunk.com/t5/Security/Does-Splunk-LDAP-support-STARTTLS/m-p/187254#M5527</link>
    <description>&lt;P&gt;As of this writing the latest Splunk does not support STARTTLS. &lt;/P&gt;</description>
    <pubDate>Thu, 03 Sep 2015 00:13:14 GMT</pubDate>
    <dc:creator>sylim_splunk</dc:creator>
    <dc:date>2015-09-03T00:13:14Z</dc:date>
    <item>
      <title>Does Splunk LDAP support STARTTLS?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-LDAP-support-STARTTLS/m-p/187253#M5526</link>
      <description>&lt;P&gt;According to &lt;A href="http://www.tenable.com/blog/pci-ssc-announces-the-end-of-ssl-usage-for-the-payment-card-industry"&gt;Tenable&lt;/A&gt; we will have to disable LDAPS soon.&lt;BR /&gt;
Is it possible to use STARTTLS on LDAP port in Splunk instead?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2015 09:43:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-LDAP-support-STARTTLS/m-p/187253#M5526</guid>
      <dc:creator>mpavlas</dc:creator>
      <dc:date>2015-03-17T09:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk LDAP support STARTTLS?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-LDAP-support-STARTTLS/m-p/187254#M5527</link>
      <description>&lt;P&gt;As of this writing the latest Splunk does not support STARTTLS. &lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 00:13:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-LDAP-support-STARTTLS/m-p/187254#M5527</guid>
      <dc:creator>sylim_splunk</dc:creator>
      <dc:date>2015-09-03T00:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk LDAP support STARTTLS?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-LDAP-support-STARTTLS/m-p/187255#M5528</link>
      <description>&lt;P&gt;LDAPS as with most things (s) such as https the s stands for secure not SSL. The LDAP server configuration determines what crypto is offered and should be updated to only permit appropriately secure TLS options. "STARTTLS" is a potentially less secure choice where the server defaults to insecure communication and requires the client to request a step up to secure. This was a useful bridge for legacy communications such as LDAP, SMTP, and FTP but is not related to the need to remove support for older now less secure encryption protocols SSL* TLS 1.0 and TLS 1.1&lt;/P&gt;

&lt;P&gt;Presuming your LDAP server is Microsoft Active Directory this vulnerability should be reviewed by your Active Directory admins to resolve.&lt;/P&gt;

&lt;P&gt;This may also be a great time to consider moving to SAML based authentication to reduce the risk of credential compromise via plain text bind.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 15:54:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-LDAP-support-STARTTLS/m-p/187255#M5528</guid>
      <dc:creator>rfaircloth_splu</dc:creator>
      <dc:date>2019-10-28T15:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk LDAP support STARTTLS?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-LDAP-support-STARTTLS/m-p/187256#M5529</link>
      <description>&lt;P&gt;This is not an answer. This is weasely language to put off the fact that we don't have a clear answer. &lt;EM&gt;Does Splunk support STARTTLS or not?&lt;/EM&gt; It is a &lt;STRONG&gt;Yes&lt;/STRONG&gt; or &lt;STRONG&gt;No&lt;/STRONG&gt; answer.&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;"STARTTLS" is a potentially less secure choice where the server defaults to insecure communication&lt;BR /&gt;
This is avoiding the technical question and a non-answer.&lt;/P&gt;

&lt;P&gt;This was a useful bridge for legacy communications such as LDAP, SMTP, and FTP but is not related to the need to remove support for older now less secure encryption protocols SSL* TLS 1.0 and TLS 1.1&lt;BR /&gt;
The question is not about the default security considerations of the users LDAP server.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Mon, 02 Dec 2019 17:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-LDAP-support-STARTTLS/m-p/187256#M5529</guid>
      <dc:creator>jpl3harris</dc:creator>
      <dc:date>2019-12-02T17:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk LDAP support STARTTLS?</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-LDAP-support-STARTTLS/m-p/187257#M5530</link>
      <description>&lt;P&gt;the original answer "no start TLS" is the correct answer. My response was to provide additional color to the reason for the question which is a vuln scanner is driving an incorrect response to "disable" ldaps. When the proper fix is simply to harden ldaps. &lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2019 17:27:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-LDAP-support-STARTTLS/m-p/187257#M5530</guid>
      <dc:creator>rfaircloth_splu</dc:creator>
      <dc:date>2019-12-02T17:27:54Z</dc:date>
    </item>
  </channel>
</rss>

