Security

Account lockout when using LDAP authentication for users?

chris_barrett
SplunkTrust
SplunkTrust

We have our authentication tied to AD using the LDAP strategy.   Password complexity and lifetime is, as a result, handled by the requirements set by the AD Group Policy.  But what about failed login attempts?  If a user manages to type in their password incorrectly multiple times (or worse, someone tries to incorrectly guess a user's password multiple times), will it cause their account to become locked within Splunk (and possibly within the underlying OS too?)

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If someone is locked out of their LDAP account then they are also locked out of Splunk.  However, Splunk is unaware of that.  I merely asks the LDAP server if the user is authenticated and if the server responds with "no" then they are not allowed in.

The 'admin' user still has access to Splunk, however, since it is a local account.

If your OS also uses LDAP then the same applies there as well.

---
If this reply helps you, Karma would be appreciated.
0 Karma

chris_barrett
SplunkTrust
SplunkTrust

But what if the user (or someone else) types in the user's id and then fails to enter the correct password multiple times.  Will the account become locked out? 

The specific situation here is that the authentication is tied to the client's AD.    If the wrong password is typed in for a user on the Splunk login page multiple (let's say 10 times), will the account become locked either within Splunk, or within AD, or both, or neither?

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Easiest way to check how it is configured on your environment is asking from your ad admins and/or just test it. I think that it depends how it is configured.
r. Ismo
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...