All Apps and Add-ons

Users can no longer execute ldapsearch; capability required only admins have

tweaktubbie
Communicator

Until months ago the SA-LDAPsearch 2.1.4 (aka Splunk Support for Active Directory) app worked fine, and it still does for me as admin.

But it appears no alerts have come through for a lot of time now.
What users see when trying to query:

External search command 'ldaptestconnection' returned error code 1. Script output = " ERROR " # host: somedomain Could not access the directory service at ldaps://someserver:636: 000004DC: LdapErr: DSID-0C090752, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v2580" " 

Their attempt or even |ldaptestconnection) results in index=_audit in events like these:

 Audit:[timestamp=03-20-2017 11:18:15.673, id=*, user=xxxxx, action=list_storage_passwords,  info=denied object="SA-ldapsearch:default:" operation=list]

Seems not good to grant any non-admin role this capability, but how other way can a specific group of users (or even a few) be given the possibility to run ldap searches?

Running Splunk 6.5.1 on Linux; had as always granted the Power role read-access to the App, users involved had the Power role.

datasearchninja
Communicator

The workaround mentioned in https://answers.splunk.com/answers/189732/splunk-support-for-active-directory-why-are-non-ad.html still works.

You can place the plaintext password in the ldap.conf file against a password= paramater, and remove the encrypted version from passwords.conf, and the code will fallback to the plaintext one.

0 Karma

Kieffer87
Communicator

Also having this issue though we are just now noticing it after upgrading to 7.0.2. Have you found a workaround for this?

ThomasControlwa
Path Finder

hi,
do you find a Workaround?
many thanks in advance

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...