Security

How to replace master node with ldap- reconfig required?

nathanpaul8
New Member

I am trying to move master node to a different node.

  1. Setup a new node.
  2. configured as master node.
  3. Modified server.conf similar to old master node for params except ssh key.
  4. Copied _cluster app from old node to new node.
  5. Restarted new master node

I am ready to point indexers and search nodes to new master node.

Old master is configured for ldap auth. But even after restart the server is not working for ldap auth. Do I need to reconfigure ldap on new master ?. I see authentication.conf in _cluster

Thanks,

NP

0 Karma
1 Solution

p_gurav
Champion

Hi,

You have to do following things:
1. move old authentication.conf and LDAP.conf and openldap certs diretory to new server
2. Just replace the hashed values with the plaintext password and copy that file over. The next time the Splunk instance starts, it will re-hash the password.

View solution in original post

p_gurav
Champion

Hi,

You have to do following things:
1. move old authentication.conf and LDAP.conf and openldap certs diretory to new server
2. Just replace the hashed values with the plaintext password and copy that file over. The next time the Splunk instance starts, it will re-hash the password.

basu42002
Path Finder

I tried the above and I get this error:
An error occurred completing this request: In handler 'LDAP-groups': strategy="###" Error binding to LDAP. reason="Invalid credentials".
While the old master node has the same credentials, the new master displays the above error.

which field contains the hashed values? as I did not replace the values.
Under ldap.conf, both "TLS_CACERT" and "TLS_CACERTDIR" are commented and TLS_REQCERT is set to "never".
Could you please let me know what could be the reason.

0 Karma

basu42002
Path Finder

Got it, the credentials in binddnspassword replaced with plaintext password. Now able to login with Ldap credentials. Thank you p_gurav

0 Karma

p_gurav
Champion

Happy to help!!! Requesting you to accept answer if its helpful.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...