Security
Highlighted

Authenticate to REST API through LDAP or SAML?

Explorer

Hi,
Is there a way to authenticate to the API through LDAP or SAML? right now, the only way I can authenticate is by using a local static account that I have configured to have API access. However, our security policy prohibits the use of local unmanaged accounts. I have SAML authentication configured for web access, but when I try to use those same AD credentials to authenticate to the API it does not work.

Thanks!

0 Karma
Highlighted

Re: Authenticate to REST API through LDAP or SAML?

Communicator

Does your AD account have restrictions on which hosts it can login from? I find that I can only make accounts work via the API if they do not have restricted login hosts, or are restricted to the hosts running Splunk (if they are domain members).

0 Karma
Highlighted

Re: Authenticate to REST API through LDAP or SAML?

Explorer

I do not believe our accounts are restricted. I am checking with our AD admins but i am almost certain they are not.

0 Karma
Highlighted

Re: Authenticate to REST API through LDAP or SAML?

Explorer

I am keen to see what you are doing to resolve this issue. Have you contacted Splunk support in regards to this?

0 Karma
Highlighted

Re: Authenticate to REST API through LDAP or SAML?

Explorer

I am facing the same issue here, I do notice Splunk mentioned this on the Splunk Cloud REST API documentation: "You cannot use SAML authentication with the REST API. ". Not sure if the same applies to Splunk Enterprise.

0 Karma
Highlighted

Re: Authenticate to REST API through LDAP or SAML?

Explorer

I am facing the same issue here. We have SAML configured for the web access, but I am not able to use the same AD credential to authenticate to the API. I am getting "Login Failed" as the response from the API. I noted that on the Splunk Cloud documentation, it mentions that "You cannot use SAML authentication with the REST API. ", will this apply to Splunk Enterprise as well? Is this a production limitation or is there a different to configure SAML to get around the issue?

0 Karma
Highlighted

Re: Authenticate to REST API through LDAP or SAML?

Builder

LDAP works fine, but using SAML for the CLI or API doesn't appear to be supported. See the "Unable to authenticate SSO users for CLI commands" issue at:
http://docs.splunk.com/Documentation/Splunk/7.0.0/Security/TroubleshootSAMLSSO

0 Karma