Security

LDAP authentication to Search Head using Smart Card

joshua_hart1
Path Finder

My computing environment mandates authentication via smart card and has disabled username/password authentication to the domain. Does Splunk allow smart card auth to LDAP when logging into the search head?

0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

Splunk uses AD/LDAP filters and settings to login to the search head. If you want to use Smart Card authentication, you will want to use the proxy sso option. We have SSO enabled to use Windows credentials to login to the searchheads. Should work for smart card as well, as long as you are logged into the workstation with it. Depending on how user access is controlled, you will either need to connect it to AD for users/groups/roles mapping, or do everything by hand.

Note: set permissive SSO to false to force logins via the proxy. Otherwise, you can still login via a direct connection to the search head.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

Splunk uses AD/LDAP filters and settings to login to the search head. If you want to use Smart Card authentication, you will want to use the proxy sso option. We have SSO enabled to use Windows credentials to login to the searchheads. Should work for smart card as well, as long as you are logged into the workstation with it. Depending on how user access is controlled, you will either need to connect it to AD for users/groups/roles mapping, or do everything by hand.

Note: set permissive SSO to false to force logins via the proxy. Otherwise, you can still login via a direct connection to the search head.

lguinn2
Legend

Thanks for the answer! IHAC with a mandate for smart-card authentication (DOD CAC). Their mandate explicitly EXCLUDES a proxy solution.

Since this solution uses a proxy, it doesn't meet the requirements.
Any other ideas?

Thanks!

joshua_hart1
Path Finder

Thanks for the write-up. I'll see how our environment is set up and go from there.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...