Security

Can Splunk or an app notify a user and provide a reset option if LDAP password expires and their account is locked after failed logins?

cdstealer
Contributor

Hi,

My company's LDAP authentication is set to expire all user passwords every 30 days to meet PCI-DSS requirements. However, splunk does not return any errors when this happens, so the end user repeatedly tries to login which then locks their account. I'm unsure if there is anything within splunk or if an app exists that will notify the user of the login error and offer the option to them to reset their password. I've had a search around, but can see nothing. Has anyone here come across this?

Thanks in advance.
Steve

Tags (3)
0 Karma
1 Solution

grijhwani
Motivator

Splunk only makes a query to validate the user/password. All it knows is that it cannot match the credentials. It knows nothing about why, merely that it fails. At work we used to suffer the exact same issue, for the exact same reason, save that in most cases because we authenticated against the Active Directory LDAP and most users were Windoze users they would be aware of their credential expiry by other more informative means before ever encountering it in Splunk.

View solution in original post

grijhwani
Motivator

Splunk only makes a query to validate the user/password. All it knows is that it cannot match the credentials. It knows nothing about why, merely that it fails. At work we used to suffer the exact same issue, for the exact same reason, save that in most cases because we authenticated against the Active Directory LDAP and most users were Windoze users they would be aware of their credential expiry by other more informative means before ever encountering it in Splunk.

MuS
SplunkTrust
SplunkTrust

You could do it a bit less awkward if you setup / use a SSO http://docs.splunk.com/Documentation/Splunk/6.1.3/Security/HowSplunkSSOworks for your Splunk server

0 Karma

cdstealer
Contributor

Many thanks for the info. That does make things rather awkward. 😞 Ah well.

0 Karma
Get Updates on the Splunk Community!

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...