Security

Does Microsoft enabling "LDAP signing" and "LDAP enforcement channel binding" affect Splunk?

nfutatsugi_splu
Splunk Employee
Splunk Employee

Microsoft seems to be planning a security release on January 2020 for Windows Server which enables both config by default. How this will affect Splunk?

1 Solution

nfutatsugi_splu
Splunk Employee
Splunk Employee

Splunk is using Simple Bind method for LDAP connection. For users who are:

  • Using Active Directory (AD) and
  • Choosing LDAP (AD) as authentication method for Splunk and
  • NOT using LDAPS (LDAP on SSL)

will need to take action as AD will deny connection from non-SSL connection when Simple Bind is used.

For resolution, users are required to configure AD to accept SSL connection and set SSLEnabled = 1 in authentication.conf file.

Note that if self-signed cert is used in AD, settings like TLS_REQCERT=never or TLSCACertificatePath=<path> (CA cert used to generate self-signed cert required) needs to be set in $SPLUNK_HOME/etc/openldap/ldap.conf file. (Link to documentation on this config file)

View solution in original post

spayneort
Contributor

nfutatsugi_splu
Splunk Employee
Splunk Employee

Splunk is using Simple Bind method for LDAP connection. For users who are:

  • Using Active Directory (AD) and
  • Choosing LDAP (AD) as authentication method for Splunk and
  • NOT using LDAPS (LDAP on SSL)

will need to take action as AD will deny connection from non-SSL connection when Simple Bind is used.

For resolution, users are required to configure AD to accept SSL connection and set SSLEnabled = 1 in authentication.conf file.

Note that if self-signed cert is used in AD, settings like TLS_REQCERT=never or TLSCACertificatePath=<path> (CA cert used to generate self-signed cert required) needs to be set in $SPLUNK_HOME/etc/openldap/ldap.conf file. (Link to documentation on this config file)

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...