Security

LDAP authentication to Search Head using Smart Card

joshua_hart1
Path Finder

My computing environment mandates authentication via smart card and has disabled username/password authentication to the domain. Does Splunk allow smart card auth to LDAP when logging into the search head?

0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

Splunk uses AD/LDAP filters and settings to login to the search head. If you want to use Smart Card authentication, you will want to use the proxy sso option. We have SSO enabled to use Windows credentials to login to the searchheads. Should work for smart card as well, as long as you are logged into the workstation with it. Depending on how user access is controlled, you will either need to connect it to AD for users/groups/roles mapping, or do everything by hand.

Note: set permissive SSO to false to force logins via the proxy. Otherwise, you can still login via a direct connection to the search head.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

Splunk uses AD/LDAP filters and settings to login to the search head. If you want to use Smart Card authentication, you will want to use the proxy sso option. We have SSO enabled to use Windows credentials to login to the searchheads. Should work for smart card as well, as long as you are logged into the workstation with it. Depending on how user access is controlled, you will either need to connect it to AD for users/groups/roles mapping, or do everything by hand.

Note: set permissive SSO to false to force logins via the proxy. Otherwise, you can still login via a direct connection to the search head.

lguinn2
Legend

Thanks for the answer! IHAC with a mandate for smart-card authentication (DOD CAC). Their mandate explicitly EXCLUDES a proxy solution.

Since this solution uses a proxy, it doesn't meet the requirements.
Any other ideas?

Thanks!

joshua_hart1
Path Finder

Thanks for the write-up. I'll see how our environment is set up and go from there.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...