<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unhash password found on Slave-apps in Security</title>
    <link>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/409508#M9819</link>
    <description>&lt;P&gt;Hi dkeck, &lt;/P&gt;

&lt;P&gt;so the best practice to move the "org_full_license_server_ssl" from etc/slave-apps to etc/apps and then restart it so it will be hash, correct?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 23:26:44 GMT</pubDate>
    <dc:creator>jaracan</dc:creator>
    <dc:date>2020-09-29T23:26:44Z</dc:date>
    <item>
      <title>Unhash password found on Slave-apps</title>
      <link>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/409506#M9817</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;We had an app for called "org_full_license_server_ssl" and it contains a server.conf&lt;BR /&gt;
This server.conf has a parameter called "sslPassword".&lt;/P&gt;

&lt;P&gt;Let say, the sslPassword is abcd1234 on this example.&lt;/P&gt;

&lt;P&gt;So we had deploy the "org_full_license_server_ssl" using the CM's master-apps, and it was push to the Peer nodes/IDX slave-apps.&lt;BR /&gt;
We notice that the server.conf's parameter value for sslPassword is a readable "abcd1234". Do we have insights why it did not got hash on the first place?&lt;/P&gt;

&lt;P&gt;Or is the best practice to move the  "org_full_license_server_ssl" from etc/slave-apps to etc/apps?&lt;BR /&gt;
I am thinking, it might be the splunk.secret  did not take effect if its on the etc/slave-apps&lt;/P&gt;

&lt;P&gt;Any thoughts/insights?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:26:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/409506#M9817</guid>
      <dc:creator>jaracan</dc:creator>
      <dc:date>2020-09-29T23:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unhash password found on Slave-apps</title>
      <link>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/409507#M9818</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;

&lt;P&gt;its normal that passwords do not get hashed in slave-apps or deplyomentapps. &lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 08:31:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/409507#M9818</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2019-02-27T08:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unhash password found on Slave-apps</title>
      <link>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/409508#M9819</link>
      <description>&lt;P&gt;Hi dkeck, &lt;/P&gt;

&lt;P&gt;so the best practice to move the "org_full_license_server_ssl" from etc/slave-apps to etc/apps and then restart it so it will be hash, correct?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:26:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/409508#M9819</guid>
      <dc:creator>jaracan</dc:creator>
      <dc:date>2020-09-29T23:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unhash password found on Slave-apps</title>
      <link>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/409509#M9820</link>
      <description>&lt;P&gt;Have to be configured on each peer in etc/apps to be hashed yes.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 09:20:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/409509#M9820</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2019-02-27T09:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unhash password found on Slave-apps</title>
      <link>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/504172#M11524</link>
      <description>&lt;P&gt;I am having the same issue. Probably you can get the hash value on the CM, assuming it has the same certificate and splunk secret (which is used to encrypt the password), and plug the hash in the master app, then deploy the bundle to peers.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 14:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/504172#M11524</guid>
      <dc:creator>weicai88</dc:creator>
      <dc:date>2020-06-12T14:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unhash password found on Slave-apps</title>
      <link>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/504321#M11525</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;have you try to put those passwords under local not to default directory? At least some times this has fixed it.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2020 20:49:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Unhash-password-found-on-Slave-apps/m-p/504321#M11525</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-06-14T20:49:05Z</dc:date>
    </item>
  </channel>
</rss>

