Security

Can Splunk or an app notify a user and provide a reset option if LDAP password expires and their account is locked after failed logins?

cdstealer
Contributor

Hi,

My company's LDAP authentication is set to expire all user passwords every 30 days to meet PCI-DSS requirements. However, splunk does not return any errors when this happens, so the end user repeatedly tries to login which then locks their account. I'm unsure if there is anything within splunk or if an app exists that will notify the user of the login error and offer the option to them to reset their password. I've had a search around, but can see nothing. Has anyone here come across this?

Thanks in advance.
Steve

Tags (3)
0 Karma
1 Solution

grijhwani
Motivator

Splunk only makes a query to validate the user/password. All it knows is that it cannot match the credentials. It knows nothing about why, merely that it fails. At work we used to suffer the exact same issue, for the exact same reason, save that in most cases because we authenticated against the Active Directory LDAP and most users were Windoze users they would be aware of their credential expiry by other more informative means before ever encountering it in Splunk.

View solution in original post

grijhwani
Motivator

Splunk only makes a query to validate the user/password. All it knows is that it cannot match the credentials. It knows nothing about why, merely that it fails. At work we used to suffer the exact same issue, for the exact same reason, save that in most cases because we authenticated against the Active Directory LDAP and most users were Windoze users they would be aware of their credential expiry by other more informative means before ever encountering it in Splunk.

MuS
SplunkTrust
SplunkTrust

You could do it a bit less awkward if you setup / use a SSO http://docs.splunk.com/Documentation/Splunk/6.1.3/Security/HowSplunkSSOworks for your Splunk server

0 Karma

cdstealer
Contributor

Many thanks for the info. That does make things rather awkward. 😞 Ah well.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...