<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP authentication not working on Splunk version 6.3.1 in Security</title>
    <link>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257640#M7081</link>
    <description>&lt;P&gt;Hi esix,&lt;/P&gt;

&lt;P&gt;Yeah, we can ping the LDAP server and telnet both 389 / 636...&lt;/P&gt;</description>
    <pubDate>Mon, 30 Nov 2015 17:35:33 GMT</pubDate>
    <dc:creator>guimilare</dc:creator>
    <dc:date>2015-11-30T17:35:33Z</dc:date>
    <item>
      <title>LDAP authentication not working on Splunk version 6.3.1</title>
      <link>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257637#M7078</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;

&lt;P&gt;I have a Splunk environment runnning on cluster.&lt;BR /&gt;
My indexers (7 peers) were at version 6.1.3 and my search heads (6 SHs) at version 6.2.3.&lt;BR /&gt;
The autenthication is done by LDAP. &lt;/P&gt;

&lt;P&gt;We updated all servers to Splunk version 6.3.1 .&lt;BR /&gt;
But now I'm not able to connect to LDAP.&lt;/P&gt;

&lt;P&gt;The error message is: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;An error occurred completing this request: In handler 'LDAP-groups : strategy="Server"' Error binding to LDAP. reason="Can't connect to LDAP server".
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Have anyone experienced this issue?&lt;BR /&gt;
I think this may be a bug.&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;BR /&gt;
Best regards&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2015 06:38:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257637#M7078</guid>
      <dc:creator>guimilare</dc:creator>
      <dc:date>2015-11-28T06:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not working on Splunk version 6.3.1</title>
      <link>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257638#M7079</link>
      <description>&lt;P&gt;We use LDAP in Splunk 6.3.1 on our Search Heads in a Search Head Cluster and LDAP does work for us.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2015 06:54:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257638#M7079</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2015-11-28T06:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not working on Splunk version 6.3.1</title>
      <link>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257639#M7080</link>
      <description>&lt;P&gt;This message is indicative of being unable to connect to the ldap server / port specified in your configuration. I'd confirm you can connect to the LDAP server from the OS level. You can ping the server or telnet to 389 / 636 of the ldap server to validate this.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2015 13:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257639#M7080</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2015-11-28T13:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not working on Splunk version 6.3.1</title>
      <link>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257640#M7081</link>
      <description>&lt;P&gt;Hi esix,&lt;/P&gt;

&lt;P&gt;Yeah, we can ping the LDAP server and telnet both 389 / 636...&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 17:35:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257640#M7081</guid>
      <dc:creator>guimilare</dc:creator>
      <dc:date>2015-11-30T17:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not working on Splunk version 6.3.1</title>
      <link>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257641#M7082</link>
      <description>&lt;P&gt;If you can connect, make sure you config file specifies the correct host / ip address. Also, test with a known working good user account.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 20:14:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257641#M7082</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2015-11-30T20:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not working on Splunk version 6.3.1</title>
      <link>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257642#M7083</link>
      <description>&lt;P&gt;Hey, any resolution? I'm now getting the same issue going from 6.1 &amp;gt; 6.3&lt;BR /&gt;
I tried the same config on 6.2 which worked fine&lt;BR /&gt;
I have another config for another LDAP server which works, so I think it's a combination of 6.3 + something about this specific AD server&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2016 05:02:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257642#M7083</guid>
      <dc:creator>timhope</dc:creator>
      <dc:date>2016-02-15T05:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not working on Splunk version 6.3.1</title>
      <link>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257643#M7084</link>
      <description>&lt;P&gt;Hi timhope,&lt;/P&gt;

&lt;P&gt;Yes, we found the problem.&lt;BR /&gt;
The problem is related to the opnessl version with Microsoft 2003 AD.&lt;/P&gt;

&lt;P&gt;Adding the following  cipher list to the &lt;STRONG&gt;$SPLUNK_HOME/etc/openldap/ldap.conf&lt;/STRONG&gt; fixed the error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TLS_CIPHER_SUITE HIGH:MEDIUM:@STRENGTH:+3DES:+RC4:!aNULL:!MD5:!SRP:!PSK:!aDSS:!kECDH:!kDH:!SEED,!IDEA:!RC2:!RC5
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope this helps you.&lt;BR /&gt;
Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2016 12:34:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257643#M7084</guid>
      <dc:creator>guimilare</dc:creator>
      <dc:date>2016-02-15T12:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication not working on Splunk version 6.3.1</title>
      <link>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257644#M7085</link>
      <description>&lt;P&gt;Problem solved.&lt;/P&gt;

&lt;P&gt;The problem is related to the opnessl version with Microsoft 2003 AD.&lt;/P&gt;

&lt;P&gt;Adding the following cipher list to the &lt;STRONG&gt;$SPLUNK_HOME/etc/openldap/ldap.conf&lt;/STRONG&gt; fixed the error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TLS_CIPHER_SUITE HIGH:MEDIUM:@STRENGTH:+3DES:+RC4:!aNULL:!MD5:!SRP:!PSK:!aDSS:!kECDH:!kDH:!SEED,!IDEA:!RC2:!RC5
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
guimilare&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2016 12:35:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-authentication-not-working-on-Splunk-version-6-3-1/m-p/257644#M7085</guid>
      <dc:creator>guimilare</dc:creator>
      <dc:date>2016-02-15T12:35:54Z</dc:date>
    </item>
  </channel>
</rss>

