<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Update authentication.conf by Pushing an app From Deployer to SHC in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Update-authentication-conf-by-Pushing-an-app-From-Deployer-to/m-p/648190#M16647</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;you cannot push anything from deployer to SHC's members .../etc/system/local.&lt;/P&gt;&lt;P&gt;The correct way it use separate app for SHC generic configurations and put those there. Then you must remove everything what has added via GUI from .../etc/system/local/authentication.conf. You could try to clean your local changes by GUI and check if those are removed from fs. If not then the last option is stop your SHC and then remove those by hand from files one by one.&lt;/P&gt;&lt;P&gt;When you have SHC or actually any other SH the best practices is use e.g. AD or any SAML authentication to manage your users in any corporate environments. Then you should have this kind of policies implemented already on your master IDM system.&lt;/P&gt;&lt;P&gt;You could change password e.g. like this&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/how-to-change-user-password-using-rest-url-without-using-curl/m-p/232785" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/how-to-change-user-password-using-rest-url-without-using-curl/m-p/232785&lt;/A&gt;&amp;nbsp;Just replace localhost with your SHC REST api address.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jun 2023 11:10:32 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2023-06-26T11:10:32Z</dc:date>
    <item>
      <title>Update authentication.conf by Pushing an app From Deployer to SHC?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Update-authentication-conf-by-Pushing-an-app-From-Deployer-to/m-p/648168#M16646</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a task with two steps&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create an app taht will increase local account password complexity from 8 chars to 18chars , push it from deployer to SHC&lt;/LI&gt;
&lt;LI&gt;Using REST API Calls Update local admin account password with long 18chars random generated string&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I found the file I need to update it is under :&amp;nbsp;/opt/splunk/etc/system/local/authentication.conf, I can create an APP folder on deployer such as /opt/splunk/etc/shcluster/apps/EXAMPLE_PASSWORD_COMPLEXITY_APP&lt;BR /&gt;How do I rout that the file inside updates the file in&amp;nbsp;/opt/splunk/etc/system/local/authentication.conf&lt;BR /&gt;&lt;BR /&gt;And on point 2. if anyone has the API Call to update SH password for local account&amp;nbsp; I woul appreciate it .&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 15:10:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Update-authentication-conf-by-Pushing-an-app-From-Deployer-to/m-p/648168#M16646</guid>
      <dc:creator>a1bg503461</dc:creator>
      <dc:date>2023-06-26T15:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: Update authentication.conf by Pushing an app From Deployer to SHC</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Update-authentication-conf-by-Pushing-an-app-From-Deployer-to/m-p/648190#M16647</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;you cannot push anything from deployer to SHC's members .../etc/system/local.&lt;/P&gt;&lt;P&gt;The correct way it use separate app for SHC generic configurations and put those there. Then you must remove everything what has added via GUI from .../etc/system/local/authentication.conf. You could try to clean your local changes by GUI and check if those are removed from fs. If not then the last option is stop your SHC and then remove those by hand from files one by one.&lt;/P&gt;&lt;P&gt;When you have SHC or actually any other SH the best practices is use e.g. AD or any SAML authentication to manage your users in any corporate environments. Then you should have this kind of policies implemented already on your master IDM system.&lt;/P&gt;&lt;P&gt;You could change password e.g. like this&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/how-to-change-user-password-using-rest-url-without-using-curl/m-p/232785" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/how-to-change-user-password-using-rest-url-without-using-curl/m-p/232785&lt;/A&gt;&amp;nbsp;Just replace localhost with your SHC REST api address.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 11:10:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Update-authentication-conf-by-Pushing-an-app-From-Deployer-to/m-p/648190#M16647</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-26T11:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Update authentication.conf by Pushing an app From Deployer to SHC?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Update-authentication-conf-by-Pushing-an-app-From-Deployer-to/m-p/649638#M16757</link>
      <description>&lt;P&gt;Sorry but we decided to take another approach using REST Api calls&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 14:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Update-authentication-conf-by-Pushing-an-app-From-Deployer-to/m-p/649638#M16757</guid>
      <dc:creator>a1bg503461</dc:creator>
      <dc:date>2023-07-07T14:51:53Z</dc:date>
    </item>
  </channel>
</rss>

