# Active Directory integration

**URL:** <https://discuss.elastic.co/t/active-directory-integration/38488>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 6, 2016, 10:22am UTC](https://discuss.elastic.co/t/active-directory-integration/38488 "2016-01-06T10:22:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bibikmik](https://avatars.discourse-cdn.com/v4/letter/b/898d66/32.png) [@bibikmik](https://discuss.elastic.co/u/bibikmik)\
**Post date:** [January 6, 2016, 10:22am UTC](https://discuss.elastic.co/t/active-directory-integration/38488/1 "2016-01-06T10:22:22Z")

</div>

Hi, Community.

Here is elasticsearch.yml:  
`shield.authc.realms.esusers.type: esusers shield.authc.realms.esusers.order: 0 shield.authc.realms.esusers.enabled: true`

`shield.authc.realms.active_directory1.type: active_directory shield.authc.realms.active_directory1.order: 1 shield.authc.realms.active_directory1.domain_name: ad_hostname1 shield.authc.realms.active_directory1.url: ldaps://ad_hostname1:636 shield.authc.realms.active_directory1.enabled: true shield.authc.realms.active_directory1.hostname_verification: false`

`shield.authc.realms.active_directory2.type: active_directory shield.authc.realms.active_directory2.order: 2 shield.authc.realms.active_directory2.domain_name: ad_hostname2 shield.authc.realms.active_directory2.url: ldaps://ad_hostname2:636 shield.authc.realms.active_directory2.enabled: true shield.authc.realms.active_directory2.hostname_verification: false`

`shield.ssl.keystore.path: /elasticsearch/config/shield/node01.jks shield.ssl.keystore.password: 123abc shield.ssl.keystore.key_password: 123abc`

Here is role\_mapping.yml:  
`user:

- "cn=elastic,ou=Service,ou=users,ou=xxxx,dc=yyyy,dc=zzzz,dc=vvvv"`

Here is roles.yml:  
`user: indices: 'logstash*': privileges: read`

When i'm trying to authorize in ES (when checking cluster availability for example) I'm getting error as follows:  
`[2016-01-06 04:46:51,361][WARN][shield.authc.activedirectory] [elastic_host1] authentication failed for user [elastic]: unable to authenticate user [elastic] to active directory domain [ad_hostname1] cause: com.unboundid.ldap.sdk.LDAPException: 80090308: LdapErr: DSID-0C0903AA, comment: AcceptSecurityContext error, data 525, v1772 [2016-01-06 04:46:51,374][WARN][shield.authc.activedirectory] [elastic_host1] authentication failed for user [elastic]: unable to authenticate user [elastic] to active directory domain [ad_hostname2] cause: com.unboundid.ldap.sdk.LDAPException: 80090308: LdapErr: DSID-0C0903AA, comment: AcceptSecurityContext error, data 525, v1772`

Keystore was created as per [https://www.elastic.co/guide/en/shield/current/active-directory.html#active-directory-ssl](https://www.elastic.co/guide/en/shield/current/active-directory.html#active-directory-ssl)

Any thoughts why unable to authenticate user?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [January 6, 2016, 11:58am UTC](https://discuss.elastic.co/t/active-directory-integration/38488/2 "2016-01-06T11:58:55Z")

</div>

The error codes indicate that the username was not found. Are `ad_hostname1` and `ad_hostname2` the DNS names of the servers or are they the _domain name_ and you have two separate domains?

If they are server hostnames/DNS entries (for example `ad1.mycompany.com`), you need to change the value of the `domain_name` setting to just the domain name (`mycompany.com`) and not the active directory server's hostname.

---

<div class="post-metadata">

**Author:** ![bibikmik](https://avatars.discourse-cdn.com/v4/letter/b/898d66/32.png) [@bibikmik](https://discuss.elastic.co/u/bibikmik)\
**Post date:** [January 6, 2016, 12:18pm UTC](https://discuss.elastic.co/t/active-directory-integration/38488/3 "2016-01-06T12:18:13Z")

</div>

> [@jaymode](#):
>
> are they the domain name and you have two separate domains?

Hi Jay,  
These are two separate domains. The second one is a failover in case first one is out of service.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [January 6, 2016, 1:37pm UTC](https://discuss.elastic.co/t/active-directory-integration/38488/4 "2016-01-06T13:37:51Z")

</div>

The users will exist in both domains? The ActiveDirectory integration works by using the userPrincipalName to bind. In your configuration that would be constructed as `elastic@ad_hostname1` and `elastic@ad_hostname2`. Are you able to check the active directory logs for information about why the request fails if this is the correct user principal name?

---

<div class="post-metadata">

**Author:** ![bibikmik](https://avatars.discourse-cdn.com/v4/letter/b/898d66/32.png) [@bibikmik](https://discuss.elastic.co/u/bibikmik)\
**Post date:** [January 11, 2016, 12:56pm UTC](https://discuss.elastic.co/t/active-directory-integration/38488/5 "2016-01-11T12:56:25Z")

</div>

> [@jaymode](#):
>
> If they are server hostnames/DNS entries (for example `ad1.mycompany.com`), you need to change the value of the `domain_name` setting to just the domain name (`mycompany.com`) and not the active directory server's hostname.

Hi Jay,  
Thank you for clarifying this. You were right here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:47pm UTC](https://discuss.elastic.co/t/active-directory-integration/38488/6 "2017-07-06T13:47:17Z")

</div>


