Security

Can Splunk or an app notify a user and provide a reset option if LDAP password expires and their account is locked after failed logins?

cdstealer
Contributor

Hi,

My company's LDAP authentication is set to expire all user passwords every 30 days to meet PCI-DSS requirements. However, splunk does not return any errors when this happens, so the end user repeatedly tries to login which then locks their account. I'm unsure if there is anything within splunk or if an app exists that will notify the user of the login error and offer the option to them to reset their password. I've had a search around, but can see nothing. Has anyone here come across this?

Thanks in advance.
Steve

Tags (3)
0 Karma
1 Solution

grijhwani
Motivator

Splunk only makes a query to validate the user/password. All it knows is that it cannot match the credentials. It knows nothing about why, merely that it fails. At work we used to suffer the exact same issue, for the exact same reason, save that in most cases because we authenticated against the Active Directory LDAP and most users were Windoze users they would be aware of their credential expiry by other more informative means before ever encountering it in Splunk.

View solution in original post

grijhwani
Motivator

Splunk only makes a query to validate the user/password. All it knows is that it cannot match the credentials. It knows nothing about why, merely that it fails. At work we used to suffer the exact same issue, for the exact same reason, save that in most cases because we authenticated against the Active Directory LDAP and most users were Windoze users they would be aware of their credential expiry by other more informative means before ever encountering it in Splunk.

MuS
Legend

You could do it a bit less awkward if you setup / use a SSO http://docs.splunk.com/Documentation/Splunk/6.1.3/Security/HowSplunkSSOworks for your Splunk server

0 Karma

cdstealer
Contributor

Many thanks for the info. That does make things rather awkward. 😞 Ah well.

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...