<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error &amp;quot;You do not have permission to perform this operation (requires capability: admin_all_objects).&amp;quot;? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127555#M10233</link>
    <description>&lt;P&gt;@jaxjohnny2000 @afret2007, This capability is obviously not ideal (or secure) to casually give to users, I've engaged the product team to review this. Please do talk to your Splunk Account team (Sales Rep/Engineers) and reference this Splunk Answer asking for a solution.&lt;/P&gt;

&lt;P&gt;Just in case it helps, I did post the most recent workarounds for this in this answer: &lt;A href="https://answers.splunk.com/answers/189732/splunk-support-for-active-directory-why-are-non-ad.html#answer-717076"&gt;https://answers.splunk.com/answers/189732/splunk-support-for-active-directory-why-are-non-ad.html#answer-717076&lt;/A&gt; &lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2019 08:47:48 GMT</pubDate>
    <dc:creator>rkantamaneni_sp</dc:creator>
    <dc:date>2019-11-14T08:47:48Z</dc:date>
    <item>
      <title>Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127517#M10195</link>
      <description>&lt;P&gt;Hi all, &lt;/P&gt;

&lt;P&gt;Installed SA-ldapsearch and it works perfectly for my account. I told the users to go ahead and start using it but they are returned the following red banner message:&lt;/P&gt;

&lt;P&gt;External search command 'ldapsearch' returned error code 1. Script output = " ERROR "HTTPError at ""/apps/splunk/etc/apps/SA-ldapsearch/bin/packages/splunklib/binding.py"", line 1108 : HTTP 403 Forbidden -- In handler 'passwords': You (user=testuser) do not have permission to perform this operation (requires capability: admin_all_objects)." "&lt;/P&gt;

&lt;P&gt;I have adjusted the app permissions to allow read and write permissions to all users. I have looked through the scripts to the best of my ability but am unable to locate the parameter to requires admin_all_objects to execute. Anyone have an idea of where I can find the config and what I need to change it to -  to allow all users to be able to execute the SA-ldapsearch commands?&lt;/P&gt;

&lt;P&gt;Thanks in advance,&lt;BR /&gt;
George&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:12:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127517#M10195</guid>
      <dc:creator>glancaster</dc:creator>
      <dc:date>2020-09-28T18:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127518#M10196</link>
      <description>&lt;P&gt;Forgot to mention, running version 2.0.0&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2014 17:47:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127518#M10196</guid>
      <dc:creator>glancaster</dc:creator>
      <dc:date>2014-11-18T17:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127519#M10197</link>
      <description>&lt;P&gt;We use Splunk's storage passwords endpoint to read/write passwords. This endpoint cannot be accessed by users without admin_all_objects capability. You might wish to create a new role for this. You might, for example, create an "SA-ldapsearch user" role that inherits from user and adds the admin_all_objects capability.&lt;/P&gt;

&lt;P&gt;The admin_all_objects capability grants users significant access rights:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;A role with this capability has access to objects in the system (user objects, search jobs, etc.).&lt;/LI&gt;
&lt;LI&gt;This bypasses any ACL restrictions (similar to root access in a *nix environment).&lt;/LI&gt;
&lt;LI&gt;We check this capability when accessing manager pages and objects.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;See the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Admin/Authorizeconf" target="_blank"&gt;authorize.conf&lt;/A&gt; spec for additional information. &lt;/P&gt;

&lt;P&gt;We are considering developing an alternative to the storage password endpoint for securely storing credentials in a future release of the Splunk Support Add-on for Active Directory; one that would not require admin_all_objects capability. Please stay tuned.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:13:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127519#M10197</guid>
      <dc:creator>David_Noble_at_</dc:creator>
      <dc:date>2020-09-28T18:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127520#M10198</link>
      <description>&lt;P&gt;Thank you for the response, I understand the limitations and hope that Splunk is able to work around this, In our situation we use a read-only account to query LDAP and need a wide range of users to be able to execute these commands in Splunk - a range of users that we wouldn't want to give admin_all_objects capabilities to.&lt;/P&gt;

&lt;P&gt;Would we be able to get someone to update the documentation and add this to the "About" section or maybe the release notes? Reading this before I tested and deployed would have saved me and others some time.&lt;/P&gt;

&lt;P&gt;Thanks for the assistance,&lt;BR /&gt;
George &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:13:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127520#M10198</guid>
      <dc:creator>glancaster</dc:creator>
      <dc:date>2020-09-28T18:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127521#M10199</link>
      <description>&lt;P&gt;I opened a bug to update the documentation. That change will be made soon.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2014 16:13:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127521#M10199</guid>
      <dc:creator>David_Noble_at_</dc:creator>
      <dc:date>2014-11-19T16:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127522#M10200</link>
      <description>&lt;P&gt;Is this issue resolved in the later versions of SA-ldapsearch app?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2015 11:35:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127522#M10200</guid>
      <dc:creator>dineshraj9</dc:creator>
      <dc:date>2015-03-05T11:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127523#M10201</link>
      <description>&lt;P&gt;Not that I am aware of, I did open an enhancement request to allow us to assign roles outside of admin_all_objects to control access to this feature.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127523#M10201</guid>
      <dc:creator>glancaster</dc:creator>
      <dc:date>2020-09-28T19:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127524#M10202</link>
      <description>&lt;P&gt;Has anyone found a way around this requirement? This is a seriously bad design choice. Fix a potential security issue by allowing everyone the equivalent of root access?&lt;/P&gt;

&lt;P&gt;Hashed local password storage for your ldap servers were much better than having users changing/deleting whatever they like across your platform just to access a custom command &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;We just has a user reconfigure a heap of server level options on our clustered search heads. It was only when they said "why doesn't X" work did we find out that they'd believed they were changing options just for themselves.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2015 02:42:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127524#M10202</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2015-03-17T02:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127525#M10203</link>
      <description>&lt;P&gt;For a cheap work around you can export the results you need from an admin account out to a lookup table and let normal users query against that. I have some high level queries set on daily cron. &lt;/P&gt;

&lt;P&gt;Also, please open an enhancement request for the fix like I did to let them know we need this changed. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2015 03:56:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127525#M10203</guid>
      <dc:creator>glancaster</dc:creator>
      <dc:date>2015-03-17T03:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127526#M10204</link>
      <description>&lt;P&gt;See my response below. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2015 03:57:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127526#M10204</guid>
      <dc:creator>glancaster</dc:creator>
      <dc:date>2015-03-17T03:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127527#M10205</link>
      <description>&lt;P&gt;Great app but I can't allow my users to use it... will this ever be fixed? &lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 22:53:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127527#M10205</guid>
      <dc:creator>johnsjm</dc:creator>
      <dc:date>2015-12-01T22:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127528#M10206</link>
      <description>&lt;P&gt;Is there a solution to this now? I need to make a dashboard for people to take work on and i can't give admin access to them all.&lt;/P&gt;

&lt;P&gt;Please help?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 15:55:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127528#M10206</guid>
      <dc:creator>rahul_jasrotia</dc:creator>
      <dc:date>2016-01-19T15:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127529#M10207</link>
      <description>&lt;P&gt;Just ran into this issue as well - the solution of adding admin_all_objects to all users is simply not acceptable.  The (much) older version of this SA-ldapsearch had the password stored in the ldap.conf file; whilst that's not ideal, for a read-only LDAP user this was far, far better than the proposed solution.&lt;/P&gt;

&lt;P&gt;I do NOT recommend doing what I just did, but it got me working:&lt;/P&gt;

&lt;P&gt;You can modify the .py files and embed the password directly rather than using the password storage routines.  This means that your LDAP/AD password would be readable at the filesystem level by whomever has access to that, but, if you're like me, that's probably a lot more palatable than giving all Splunk users the required permission.&lt;/P&gt;

&lt;P&gt;I modified:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;ldapsearch.py&lt;/LI&gt;
&lt;LI&gt;./packages/app/connection_pool.py&lt;/LI&gt;
&lt;LI&gt;Possibly ./packages/app/configuration.py&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Point is, I looked for the Python functions which were waiting for the results of the storage routines to return the password and just inserted password='whatever-the-password-was' instead.  &lt;/P&gt;

&lt;P&gt;Really, really bad idea, but, it's a far less bad idea than the current permissions requirement.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:30:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127529#M10207</guid>
      <dc:creator>howyagoin</dc:creator>
      <dc:date>2020-09-29T08:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127530#M10208</link>
      <description>&lt;P&gt;Hi @howyagoin,&lt;BR /&gt;
Thanks for the reply but, I have 2 domains configured so not sure which passwords are we talking about here. for both these domains there's a different password, which one should i use. I tried one but its giving me an error.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 14:16:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127530#M10208</guid>
      <dc:creator>rahul_jasrotia</dc:creator>
      <dc:date>2016-01-22T14:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127531#M10209</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;We are considering developing an alternative to the storage password endpoint for securely storing credentials in a future release of the Splunk Support Add-on for Active Directory; one that would not require admin_all_objects capability. Please stay tuned.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Any update about fixing this?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:47:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127531#M10209</guid>
      <dc:creator>ontkanin</dc:creator>
      <dc:date>2020-09-29T09:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127532#M10210</link>
      <description>&lt;P&gt;I believe I have found a solution without hacking the Python script code &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I actually got inspired by @howyagoin&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;The (much) older version of this SA-ldapsearch had the password stored in the ldap.conf file&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I looked into &lt;CODE&gt;bin/packages/app/configuration.py&lt;/CODE&gt; file and I saw this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;if password is None:
    password = self._get_value(settings, 'password', default='')
    if password.startswith('{64}'):
        password = b64decode(password[4:])
    pass
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;which pretty much means "if password cannot be read from password storage, then as a last resort try to read it from &lt;CODE&gt;ldap.conf&lt;/CODE&gt; file."&lt;/P&gt;

&lt;P&gt;So just open &lt;CODE&gt;local/ldap.conf&lt;/CODE&gt; and add the following line into a proper stanza (in case you have multiple ADs, then add proper password to its respective stanza):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;password = BINDDN_PASSWORD
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;We have tested it here and it works.&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 19:58:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127532#M10210</guid>
      <dc:creator>ontkanin</dc:creator>
      <dc:date>2016-05-26T19:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127533#M10211</link>
      <description>&lt;P&gt;@rahul_jasrotia, please see my solution below; it works with multiple domains.&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 20:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127533#M10211</guid>
      <dc:creator>ontkanin</dc:creator>
      <dc:date>2016-05-26T20:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127534#M10212</link>
      <description>&lt;P&gt;Thanks @ontkanin, it sure works.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 05:35:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127534#M10212</guid>
      <dc:creator>rahul_jasrotia</dc:creator>
      <dc:date>2016-07-20T05:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127535#M10213</link>
      <description>&lt;P&gt;we just upgraded, which led me here. there are no scenarios where we would throw away security like suggested here. breaking the code to do it ourselves is more likely.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 14:49:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127535#M10213</guid>
      <dc:creator>jhedgpeth</dc:creator>
      <dc:date>2016-08-25T14:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Support for Active Directory: Why are non-admin users getting ldapsearch error "You do not have permission to perform this operation (requires capability: admin_all_objects)."?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127536#M10214</link>
      <description>&lt;P&gt;Same problem with 2.1.4 but I get another Error:&lt;/P&gt;

&lt;P&gt;External search command 'ldaptestconnection' returned error code 1. First 1000 (of 2868) bytes of script output: " ERROR " # host: X.X.X.X: Could not access the directory service at ldaps://X.X.X.X:636: 000004DC: LdapErr: DSID-0C0906E8, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v1db1 # host: X.X.X.X: Could not access the directory service at ldaps://X.X.X.X:636: 000004DC: LdapErr: DSID-0C0906E8, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v1db1 &lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2017 06:27:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Support-for-Active-Directory-Why-are-non-admin-users/m-p/127536#M10214</guid>
      <dc:creator>benlc</dc:creator>
      <dc:date>2017-01-16T06:27:48Z</dc:date>
    </item>
  </channel>
</rss>

