Security

Does Microsoft enabling "LDAP signing" and "LDAP enforcement channel binding" affect Splunk?

nfutatsugi_splu
Splunk Employee
Splunk Employee

Microsoft seems to be planning a security release on January 2020 for Windows Server which enables both config by default. How this will affect Splunk?

1 Solution

nfutatsugi_splu
Splunk Employee
Splunk Employee

Splunk is using Simple Bind method for LDAP connection. For users who are:

  • Using Active Directory (AD) and
  • Choosing LDAP (AD) as authentication method for Splunk and
  • NOT using LDAPS (LDAP on SSL)

will need to take action as AD will deny connection from non-SSL connection when Simple Bind is used.

For resolution, users are required to configure AD to accept SSL connection and set SSLEnabled = 1 in authentication.conf file.

Note that if self-signed cert is used in AD, settings like TLS_REQCERT=never or TLSCACertificatePath=<path> (CA cert used to generate self-signed cert required) needs to be set in $SPLUNK_HOME/etc/openldap/ldap.conf file. (Link to documentation on this config file)

View solution in original post

spayneort
Contributor

nfutatsugi_splu
Splunk Employee
Splunk Employee

Splunk is using Simple Bind method for LDAP connection. For users who are:

  • Using Active Directory (AD) and
  • Choosing LDAP (AD) as authentication method for Splunk and
  • NOT using LDAPS (LDAP on SSL)

will need to take action as AD will deny connection from non-SSL connection when Simple Bind is used.

For resolution, users are required to configure AD to accept SSL connection and set SSLEnabled = 1 in authentication.conf file.

Note that if self-signed cert is used in AD, settings like TLS_REQCERT=never or TLSCACertificatePath=<path> (CA cert used to generate self-signed cert required) needs to be set in $SPLUNK_HOME/etc/openldap/ldap.conf file. (Link to documentation on this config file)

Get Updates on the Splunk Community!

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...

Platform Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestIntroducing Splunk Edge Processor, simplified data ...