All Apps and Add-ons

Cisco IronPort - Splunk Integration (SCP Issue)

socespap
Explorer

Hi,

I am trying to integrate a Cisco ESA into splunk and I realized that I have constraints regarding to privileges related to the user that I am using. In this brief test I have been using 'root' but doesn't work properly

type=USER_AUTH msg=audit(1548086500.719:6438): pid=31410 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=10.150.0.11 terminal=ssh res=failed'

SSH folder was configures as 700 privileges, and authorized_keys file as 644.

Any idea about this issue?

Sincerely,

Vitor Leitao

Tags (1)
0 Karma

hcanivel_splunk
Splunk Employee
Splunk Employee

First of all, you should never be using root to SSH/SCP anything, especially if it's publicly facing infrastructure.
Secondly, can you even verify if SSH for root user is enabled? By default, your sshd should have that disabled.
Thirdly, what are your debug logs for both client and server? I would presume testing against root user is disabled for SSH access, but would like to see the actual reason for failure.

0 Karma

socespap
Explorer

Just to add the following log

Mon Jan 21 16:00:04 2019 Info: Appliance:xxxx, Interaction mode: SSH Client, User: *****, Dest IP: X.X.X.X:22, Event: SCP failed. Reason - Permission denied (publickey,password). lost connection
eventtype = cisco-security-events eventtype = err0r error host = XXXX source = /opt/splunk/etc/apps/Splunk_TA_cisco-esa/local/authentication.@20190121T160003.s sourcetype = cisco:esa:authentication

0 Karma

spodda01da
Path Finder

Hi socespap, Did you get it configured, I am too looking to configure via SCP but facing some challenges. Please do let me know how did you fix it.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...