Splunk® Enterprise

Securing Splunk Enterprise

Download manual as PDF

Download topic as PDF

Secure LDAP with TLS certificates

Splunk uses OpenLDAP and OpenSSL. You can leverage both tools to secure your LDAP authentication with certificates. For more information on creating and managing certificates, see the OpenSSL documentation

The following examples are certificate configurations for LDAP. For more information about ways you can configure certificates in LDAP, see the OpenLDAP documentation at http://www.openldap.org/doc/admin24/tls.html:

LDAP server configuration

TLSCACertificateFile <filename>: the PEM-format file containing certificates for the CA's that 
slapd will trust, including the certificate for the CA that signed the server certificate. Multiple 
certificates can be appended to the file in no particular order.

TLSCertificateKeyFile <filename></code>: the file that contains the private key that matches 
the certificate stored in the TLSCertificateFile file.

TLSCipherSuite <cipher-suite-spec>: ciphers will be accepted and the preference order. 
<cipher-suite-spec> should be a cipher specification for OpenSSL. Use 
"openssl ciphers -v ALL" for a list of available cipher specifications.

TLSRandFile <filename>: the file to obtain random bits from when /dev/urandom is not 
available. If the system provides /dev/urandom then this option is not needed, otherwise 
a source of random data must be configured. 

TLSEphemeralDHParamFile <filename>: the file that contains parameters for 
Diffie-Hellman ephemeral key exchange. 

TLSVerifyClient { never | allow | try | demand }: specifies what checks to perform on client 
certificates in an incoming TLS session, if any. This option is set to never by default, in 
which case the server never asks the client for a certificate. 

LDAP client configuration

This directive specifies the file that contains the client certificate. This is a user-only directive and can only be specified in a user's .ldaprc file.

TLS_KEY <filename> specifies the file that contains the private key that matches the certificate 
stored in the TLS_CERT file. The same constraints mentioned for TLSCertificateKeyFile apply here. 
This is also a user-only directive.

TLS_RANDFILE <filename> the same as the server's TLSRandFile option.

TLS_REQCERT { never | allow | try | demand }

Note that if you host two or more LDAP servers, you may not want to use self-signed certificates, since each client will have to be configured to work with each certificate. In such a case it would be easier to create a certificate authority to sign your server certificates.

LDAP prerequisites and considerations
How Splunk Enterprise works with multiple LDAP servers

This documentation applies to the following versions of Splunk® Enterprise: 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.1.0, 7.1.1, 7.1.2

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters