# Active directory Authentication Problem

**URL:** <https://discuss.elastic.co/t/active-directory-authentication-problem/240838>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 12, 2020, 12:45pm UTC](https://discuss.elastic.co/t/active-directory-authentication-problem/240838 "2020-07-12T12:45:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mahmoud\_Shash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mahmoud_shash/32/71992_2.png) [@Mahmoud\_Shash](https://discuss.elastic.co/u/Mahmoud_Shash)\
**Post date:** [July 12, 2020, 12:45pm UTC](https://discuss.elastic.co/t/active-directory-authentication-problem/240838/1 "2020-07-12T12:45:26Z")

</div>

Hello Gents,  
I'm a newbie in the elastic World, actually, I'm counting on you to solve my problem.  
I've elastic search cluster and I need to do the Active directory integration  
I followed the https://www.elastic.co/guide/en/elasticsearch/reference/current/active-directory-realm.html after enabling the trial license.  
the cluster has 3 (master and data ) nodes with 3 client nodes in total 6 nodes.  
the master nodes have the following Elasticsearch.yml  
I enabled the encryption between the Elastic cluster inter-node communication but I didn't enable the HTTP encryption.

I did the enter as well the binding user credential via bin/elasticsearch-keystore add   
xpack.security.authc.realms.active\_directory.my\_ad.secure\_bind\_password

```
xpack:
 security:
  authc:
   realms:
    active_directory:
      nic_ad:
        order: 1
        domain_name: elastic.example.com
        url: ldap://server01.elastic.example.com:389, ldap://server02.elastic.example.com:389
        bind_dn: CN=NDB,OU=Service Account,DC=elastic,DC=example,DC=com
        user_search:
          base_dn: "OU=sharaf,DC=elastic,DC=example,DC=com"
        group_search:
          base_dn: "CN=elastic_admin,DC=elastic,DC=example,DC=com"
        files:
          role_mapping: "/etc/elasticsearch/role_mapping.yml"
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 12, 2020, 1:02pm UTC](https://discuss.elastic.co/t/active-directory-authentication-problem/240838/2 "2020-07-12T13:02:09Z")

</div>

AD integration is a commercial feature. Do you have the appropriate license?

---

<div class="post-metadata">

**Author:** ![Mahmoud\_Shash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mahmoud_shash/32/71992_2.png) [@Mahmoud\_Shash](https://discuss.elastic.co/u/Mahmoud_Shash)\
**Post date:** [July 12, 2020, 1:25pm UTC](https://discuss.elastic.co/t/active-directory-authentication-problem/240838/3 "2020-07-12T13:25:45Z")

</div>

Thanks for your response I enabled the trial license.

---

<div class="post-metadata">

**Author:** ![Mahmoud\_Shash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mahmoud_shash/32/71992_2.png) [@Mahmoud\_Shash](https://discuss.elastic.co/u/Mahmoud_Shash)\
**Post date:** [July 12, 2020, 8:16pm UTC](https://discuss.elastic.co/t/active-directory-authentication-problem/240838/4 "2020-07-12T20:16:41Z")

</div>

more over the log file is not sating anything regarding the authentication process although with the following configuration, more over the log file is not saying anything regarding the authentication process although with the following configuration :

```auto
  PUT /_cluster/settings 
        { 
          "transient": { 
             "logger.org.elasticsearch.xpack.security.authc.ldap":"TRACE", 
             "logger.org.elasticsearch.xpack.security.authz":"TRACE" 
           } 
        }

```

please guys anyone can help me here ?

---

<div class="post-metadata">

**Author:** ![Mahmoud\_Shash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mahmoud_shash/32/71992_2.png) [@Mahmoud\_Shash](https://discuss.elastic.co/u/Mahmoud_Shash)\
**Post date:** [July 14, 2020, 4:16pm UTC](https://discuss.elastic.co/t/active-directory-authentication-problem/240838/5 "2020-07-14T16:16:34Z")

</div>

I managed to solve it.  
this are other important points :  
1- check if the AD is multi Domain so you have to talk with Global catalog node with the port (3268) if not SSL  
2- you have to make sure that the Elasticsearch node you are connected with has both the configuration of the AD configuration in elasticsearch.yml and the bind user password in the node keystore even if this node is a client Elastic node.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 11, 2020, 4:16pm UTC](https://discuss.elastic.co/t/active-directory-authentication-problem/240838/6 "2020-08-11T16:16:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
