Security

Allowed characters in passwords via the cli

Blu3fish
Path Finder

Hello,

When issuing the following command on an initial install of Splunk (Splunk is running) I receive the expected "User admin edited" confirmation but when I try to log on to the web ui it appears that the password won't take.

When changing the password via the webui it works every time.

./splunk edit user admin -password 7eyRa$# -roles admin Your session is invalid. Please login. Splunk username: admin Password: changeme User admin edited.

(Also tried with quotes surrounding the new password: ./splunk edit user admin -password "7eyRa$#" -roles admin)

I was able to get the password to stick (via the cli) if I removed the final "#" character. Is there any way around this?

Thanks, Brennan

Tags (1)
1 Solution

hexx
Splunk Employee
Splunk Employee

We have a bug currently open against this issue. It will be fixed in a future release. The work-around in the meantime is to use the UI to set passwords that contain characters such as "$" or "#", or simply to avoid using those characters to set a password.

View solution in original post

hexx
Splunk Employee
Splunk Employee

We have a bug currently open against this issue. It will be fixed in a future release. The work-around in the meantime is to use the UI to set passwords that contain characters such as "$" or "#", or simply to avoid using those characters to set a password.

jawaharas
Motivator

Even in Splunk 7.1 , login is failed while using CLI, when the symbols are in password.

0 Karma

ejharts2015
Communicator

Still exists in Splunk 6.3 as well... 😞

0 Karma

ianformanek
Explorer

This problem is still present in the current version, I cannot use password with a dollar sign if I want to use the CLI (./splunk install app xxx -auth admin:my$pass fails)

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...