Security

LDAP authentication to Search Head using Smart Card

joshua_hart1
Path Finder

My computing environment mandates authentication via smart card and has disabled username/password authentication to the domain. Does Splunk allow smart card auth to LDAP when logging into the search head?

0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

Splunk uses AD/LDAP filters and settings to login to the search head. If you want to use Smart Card authentication, you will want to use the proxy sso option. We have SSO enabled to use Windows credentials to login to the searchheads. Should work for smart card as well, as long as you are logged into the workstation with it. Depending on how user access is controlled, you will either need to connect it to AD for users/groups/roles mapping, or do everything by hand.

Note: set permissive SSO to false to force logins via the proxy. Otherwise, you can still login via a direct connection to the search head.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

Splunk uses AD/LDAP filters and settings to login to the search head. If you want to use Smart Card authentication, you will want to use the proxy sso option. We have SSO enabled to use Windows credentials to login to the searchheads. Should work for smart card as well, as long as you are logged into the workstation with it. Depending on how user access is controlled, you will either need to connect it to AD for users/groups/roles mapping, or do everything by hand.

Note: set permissive SSO to false to force logins via the proxy. Otherwise, you can still login via a direct connection to the search head.

lguinn2
Legend

Thanks for the answer! IHAC with a mandate for smart-card authentication (DOD CAC). Their mandate explicitly EXCLUDES a proxy solution.

Since this solution uses a proxy, it doesn't meet the requirements.
Any other ideas?

Thanks!

joshua_hart1
Path Finder

Thanks for the write-up. I'll see how our environment is set up and go from there.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...