Security

Any tool to encrypt passwords based on a splunk.secret?

koshyk
Super Champion

We have multiple secrets for the different tiers (forwarders/search heads etc.). Some of the apps like IPS needs to have UI to encrypt password 😞 which is not possible on all tiers.

Is there a tool/API which can encrypt the password based on splunk.secret ?

eg. what I'm looking for is

=> supply passwords.conf and splunk.secret as inputs to the tool
=> run the api/tool so that it takes passwords.conf and splunk.secret of the relevant tier/server and hash the password with it

Thanks in advance

1 Solution

starcher
Influencer

You could spin up a splunk instance with the splunk secret. Then use the encrypted password endpoint via your own script to enter passwords then grab the results from passwords.conf.

http://www.georgestarcher.com/splunk-stored-encrypted-credentials/

View solution in original post

xpac
SplunkTrust
SplunkTrust

There's an even easier available now, a Python project called splunksecrets that can be installed via PIP and gives you an easy CLI to encrypt + decrypt new and old secrets:

https://pypi.org/project/splunksecrets/

starcher
Influencer

You could spin up a splunk instance with the splunk secret. Then use the encrypted password endpoint via your own script to enter passwords then grab the results from passwords.conf.

http://www.georgestarcher.com/splunk-stored-encrypted-credentials/

koshyk
Super Champion

I had seen the website, but great to see the answer from the person itself. 🙂 You guys are real heroes.

We had similar issues and great if we can work on a github project to make this automated for ansible
Accepting the answer.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...