Security

LDAP authentication to Search Head using Smart Card

joshua_hart1
Path Finder

My computing environment mandates authentication via smart card and has disabled username/password authentication to the domain. Does Splunk allow smart card auth to LDAP when logging into the search head?

0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

Splunk uses AD/LDAP filters and settings to login to the search head. If you want to use Smart Card authentication, you will want to use the proxy sso option. We have SSO enabled to use Windows credentials to login to the searchheads. Should work for smart card as well, as long as you are logged into the workstation with it. Depending on how user access is controlled, you will either need to connect it to AD for users/groups/roles mapping, or do everything by hand.

Note: set permissive SSO to false to force logins via the proxy. Otherwise, you can still login via a direct connection to the search head.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

Splunk uses AD/LDAP filters and settings to login to the search head. If you want to use Smart Card authentication, you will want to use the proxy sso option. We have SSO enabled to use Windows credentials to login to the searchheads. Should work for smart card as well, as long as you are logged into the workstation with it. Depending on how user access is controlled, you will either need to connect it to AD for users/groups/roles mapping, or do everything by hand.

Note: set permissive SSO to false to force logins via the proxy. Otherwise, you can still login via a direct connection to the search head.

lguinn2
Legend

Thanks for the answer! IHAC with a mandate for smart-card authentication (DOD CAC). Their mandate explicitly EXCLUDES a proxy solution.

Since this solution uses a proxy, it doesn't meet the requirements.
Any other ideas?

Thanks!

joshua_hart1
Path Finder

Thanks for the write-up. I'll see how our environment is set up and go from there.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...