Security

Splunk SAML Assertion X509Certificate

maffreitas
Path Finder

Hi all,

Do you know the procedure to change the SAML Assertion X509Certificate (= server.pem) for a certificate signed by a third-party?

Regards.

0 Karma
1 Solution

suarezry
Builder

I'm not sure if you're referring to changing the certificate of your Identity Provider or your Splunk Service Provider. Take a look at the authentication.conf spec.

The settings you're looking for are idpCertPath, clientCert, and caCertFile.

View solution in original post

0 Karma

suarezry
Builder

I'm not sure if you're referring to changing the certificate of your Identity Provider or your Splunk Service Provider. Take a look at the authentication.conf spec.

The settings you're looking for are idpCertPath, clientCert, and caCertFile.

0 Karma

maffreitas
Path Finder

Thanks @suarezry, the question is regarding the Splunk Service Provider (SPmetadata.xml).

0 Karma

suarezry
Builder

Great, once you change the settings in your authentication.conf you'll have to restart your Splunk instance or reload the authentication config. Then you'll need to regenerate your SPmetadata.xml and confirm that XML has the new certs. Then you'll need to pass this to your IdP.

Let me know if you have any further questions. If not, please accept this answer.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...