<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Synchronizing the passwd file between Splunk servers with a shared splunk.secret in Security</title>
    <link>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/234350#M6583</link>
    <description>&lt;P&gt;My goal is to update the Splunk admin password across newly configured instances using the same password. These servers all have the same splunk.secret, so I figured I could share the $SPLUNK_HOME/etc/passwd file after updating it on one instance. &lt;/P&gt;

&lt;P&gt;Before sharing the passwd file, I changed the admin password on a couple of instances and noticed that the hashed value in passwd isn't consistent. Is this the expected behavior?&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jan 2017 16:26:02 GMT</pubDate>
    <dc:creator>dflodstrom</dc:creator>
    <dc:date>2017-01-10T16:26:02Z</dc:date>
    <item>
      <title>Synchronizing the passwd file between Splunk servers with a shared splunk.secret</title>
      <link>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/234350#M6583</link>
      <description>&lt;P&gt;My goal is to update the Splunk admin password across newly configured instances using the same password. These servers all have the same splunk.secret, so I figured I could share the $SPLUNK_HOME/etc/passwd file after updating it on one instance. &lt;/P&gt;

&lt;P&gt;Before sharing the passwd file, I changed the admin password on a couple of instances and noticed that the hashed value in passwd isn't consistent. Is this the expected behavior?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2017 16:26:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/234350#M6583</guid>
      <dc:creator>dflodstrom</dc:creator>
      <dc:date>2017-01-10T16:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronizing the passwd file between Splunk servers with a shared splunk.secret</title>
      <link>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/234351#M6584</link>
      <description>&lt;P&gt;I've copied the contents of passwd to another instance and successfully logged in with the new password. It seems that splunk generates different hashes but is somehow  able to decipher them. &lt;/P&gt;

&lt;P&gt;&lt;EM&gt;I'd like someone else to confirm this behavior before I select my own answer&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2017 16:38:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/234351#M6584</guid>
      <dc:creator>dflodstrom</dc:creator>
      <dc:date>2017-01-10T16:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronizing the passwd file between Splunk servers with a shared splunk.secret</title>
      <link>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/234352#M6585</link>
      <description>&lt;P&gt;I've tested this on several different instances. I can copy the contents of $SPLUNK_HOME/etc/passwd to any other instance that shares a splunk.secret. If the instances are left to create the passwd file by themselves they will create a different hash value representing the same password that can be use on other hosts with a shared splunk.secret.  Hopefully someone else finds this useful. Please comment if you've seen other behavior.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 16:44:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/234352#M6585</guid>
      <dc:creator>dflodstrom</dc:creator>
      <dc:date>2017-01-11T16:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronizing the passwd file between Splunk servers with a shared splunk.secret</title>
      <link>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/234353#M6586</link>
      <description>&lt;P&gt;Yes, it is the expected behavior for the hashed values of the same password to be different-- this is because there is a "salt" added when the password is passed through the hashing algorithm .  (This makes it more difficult to reverse-engineer passwords from hashed results). &lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 18:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/234353#M6586</guid>
      <dc:creator>ridwanahmed</dc:creator>
      <dc:date>2018-07-27T18:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronizing the passwd file between Splunk servers with a shared splunk.secret</title>
      <link>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/234354#M6587</link>
      <description>&lt;P&gt;I know this is an old question, but was the first Google result so I thought I'd give it an update.&lt;/P&gt;

&lt;P&gt;Sharing the &lt;CODE&gt;passwd&lt;/CODE&gt; file works without a shared &lt;CODE&gt;splunk.secret&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;Let's take an example line from a &lt;CODE&gt;passwd&lt;/CODE&gt; file:&lt;BR /&gt;
&lt;CODE&gt;:admin:$6$sG0AOkrCThdXQjTF$5Aiq4/slyL4ve0eKrP/iIUP3kE15S2aJOBWrn1YXZzp3o8eqs1luBK8XBBX93ZHg1y6X.Bs5NqTDB98OqSX6Z1::Administrator:admin:changeme@example.com:::32683&lt;/CODE&gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;The &lt;CODE&gt;$6$&lt;/CODE&gt; at the beginning indicates a SHA512 hash.&lt;/LI&gt;
&lt;LI&gt;A so-called salt is saved between the &lt;CODE&gt;$6$&lt;/CODE&gt; and the next &lt;CODE&gt;$&lt;/CODE&gt; - in this case &lt;CODE&gt;sG0AOkrCThdXQjTF&lt;/CODE&gt;. It is selected randomly and different each time the password is set/changed. Read more about why salts are used here: &lt;A href="https://en.wikipedia.org/wiki/Salt_(cryptography)"&gt;Salt@Wikipedia&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;The final string after the &lt;CODE&gt;$&lt;/CODE&gt; is the actual password hash. Even if you set the same password every time, it will be different each time, because a new salt will be randomly chosen and added to the password before it's hashed. In this case, the hash is &lt;CODE&gt;5Aiq4/slyL4ve0eKrP/iIUP3kE15S2aJOBWrn1YXZzp3o8eqs1luBK8XBBX93ZHg1y6X.Bs5NqTDB98OqSX6Z1&lt;/CODE&gt;.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;However, when a user tries to login, Splunk takes the salt stored in the &lt;CODE&gt;passwd&lt;/CODE&gt; file instead of selecting a random one, adds the salt to the password the user entered, and runs that string through the SHA512 function. If the result of that operation matches the string after the &lt;CODE&gt;$&lt;/CODE&gt;, it's considered the right password.&lt;/P&gt;

&lt;P&gt;That is the reason that the same password results in different strings on different instances, but you can just copy them over.&lt;BR /&gt;
Again - no shared &lt;CODE&gt;splunk.secret&lt;/CODE&gt; required.&lt;/P&gt;

&lt;P&gt;Hope that helps @dflodstrom!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 14:06:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/234354#M6587</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-12-04T14:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronizing the passwd file between Splunk servers with a shared splunk.secret</title>
      <link>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/705378#M18244</link>
      <description>&lt;P&gt;It is not related with the splunk.secret as suggested in other replies.&lt;/P&gt;&lt;P&gt;When creating the same users with same passwords in two different instances, it first generates a random salt. Then the salt is concatenated with the password and hashed. It is done this way to ensure the security (to prevent rainow tables). As the salt is randomly generated, both instances will have a random salt (between $6$ and $) and therefore a different hash (after the last mentioned $).&lt;/P&gt;&lt;P&gt;When copying the passwd line to another instance, we are enforcing this new server to use the same salt and therefore the hash will be the same.&lt;/P&gt;&lt;P&gt;In summary, you can both create a user in both servers or just create it in one of them and copy the passwd file to the other one.&lt;/P&gt;&lt;P&gt;If this is helpful please give me karma &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 11:43:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Synchronizing-the-passwd-file-between-Splunk-servers-with-a/m-p/705378#M18244</guid>
      <dc:creator>kotp</dc:creator>
      <dc:date>2024-11-27T11:43:15Z</dc:date>
    </item>
  </channel>
</rss>

