- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/b9cbb/b9cbb54b55d43d1475c411051191da80b47dc630" alt="indigo1 indigo1"
1.custom have own itself single sign-on system,can provide webservice api,such as:
a. api url : http://10.50.11.100/MyWebSite/ProjectHome/WebService/DDLoginService.asmx?wsdl
b.method: UserAuthenticateByDES()
c.Request message:
<UserAuthenticateByDES xmlns="http://mymis.cgg.PublicService/">
<account>******</account>
<encodeText>******</encodeText>
</UserAuthenticateByDES>
d.Response message :
<UserAuthenticateByDESResponse xmlns="http://mymis.cgg.PublicService/">
<UserAuthenticateByDESResult>false</UserAuthenticateByDESResult>
</UserAuthenticateByDESResponse>
as you know,splunk SSO only support saml & reverse proxy,
so,my question is: how to Combine with custom's webservice api to achieved Single sign-on?
any idea or reference?thanks a lot!!!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/dfed8/dfed8f5260a02cb6ff39d2a26a873139224e8881" alt="dwaddle dwaddle"
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
Look into Splunk's scripted authentication support. Build a scripted authentication plugin for Splunk that interacts with this web service. It won't be truly 'single' sign-on (as in sign on once and everything from then on just works), but it will be able to use this web service as an authentication source similar to LDAP.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/dfed8/dfed8f5260a02cb6ff39d2a26a873139224e8881" alt="dwaddle dwaddle"
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
Look into Splunk's scripted authentication support. Build a scripted authentication plugin for Splunk that interacts with this web service. It won't be truly 'single' sign-on (as in sign on once and everything from then on just works), but it will be able to use this web service as an authentication source similar to LDAP.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/b9cbb/b9cbb54b55d43d1475c411051191da80b47dc630" alt="indigo1 indigo1"
Thank you so much!
But can you please explain more detail aboout ' Build a scripted authentication plugin for Splunk that interacts with this web service',
Now I Suppose :
setp1: create a authentication script (run in splunk's server OR Client ?)
setp2: create a authentication.conf to active the script
and than?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/dfed8/dfed8f5260a02cb6ff39d2a26a873139224e8881" alt="dwaddle dwaddle"
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
So to begin with - this is a software development effort - there is some documentation and some sample code available. I would start with http://docs.splunk.com/Documentation/Splunk/6.5.0/Security/ConfigureSplunkToUsePAMOrRADIUSAuthentica... and read and understand the sample code. This is a several day effort at best and will require testing and such.
data:image/s3,"s3://crabby-images/a266d/a266d0c80c12793a952b209c17cc3de41b17fc89" alt=""