# Authentication against Active Directory

**URL:** <https://discuss.elastic.co/t/authentication-against-active-directory/217383>\
**Category:** Elasticsearch\
**Created:** [January 31, 2020, 1:40pm UTC](https://discuss.elastic.co/t/authentication-against-active-directory/217383 "2020-01-31T13:40:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![admin\_berlin](https://avatars.discourse-cdn.com/v4/letter/a/e36b37/32.png) [@admin\_berlin](https://discuss.elastic.co/u/admin_berlin)\
**Post date:** [January 31, 2020, 1:40pm UTC](https://discuss.elastic.co/t/authentication-against-active-directory/217383/1 "2020-01-31T13:40:41Z")

</div>

Hi there,  
I've been trying to set authentication via Active Directory / LDAP for days.

With the correct login data I get the error message:  
{ "Status code" 403 "error": "Forbidden", "message": "Forbidden"}

With incorrect login data as you expected:

- Kibana: Invalid username or password. Please try again.
- Elasticsearch logs:  
[ep-note-1] Authentication to realm my\_ad failed - authenticate failed (Caused by LDAPException (resultCode = 49 (invalid credentials), diagnosticMessage = '80090308: LdapErr: DSID-0C090400, comment: AcceptSecurityContext error, data 52e, v1db1', ldapSDKVersion = 4.0.8, revision = 28812))

My configs:

```
    elasticsearch.yml
    xpack:
      security:
        authc:
          realms:
            active_directory:
              my_ad:
                order: 0
                domain_name: xx.xx.xx.de
                url: ldap://ad.xx.xx.xx.de:389
                bind_dn: CN=xx,OU=xx,OU=xx,OU=xx,OU=xx,DC=xx,DC=iplan,DC=xx,DC=de
                files:
                  role_mapping: "/etc/elasticsearch/role_mapping.yml"
                unmapped_groups_as_roles: false

        xpack.license.self_generated.type: trial
        xpack.monitoring.collection.enabled: true
        xpack.security.enabled: true

    role_mapping.yml
        # Role mapping configuration file which has elasticsearch roles as keys
        # that map to one or more user or group distinguished names

        #roleA: this is an elasticsearch role
        # - groupA-DN this is a group distinguished name
        # - groupB-DN
        # - user1-DN this is the full user distinguished name

        #power_user:
        # - "cn=admins,dc=example,dc=com"
        #user:
        # - "cn=users,dc=example,dc=com"
        # - "cn=admins,dc=example,dc=com"
        # - "cn=John Doe,cn=other users,dc=example,dc=com"
        # 4 testing
        monitoring:
              #- "cn=admins,dc=example,dc=com"
              - "CN=Group,OU=xx,OU=xx,OU=xx,DC=xx,DC=xx,DC=xx,DC=de"

```

My specs: 1 x elasticsearch note, 1 x kibana note, 1 x logstash note

Pls helwwp 😕

---

<div class="post-metadata">

**Author:** ![admin\_berlin](https://avatars.discourse-cdn.com/v4/letter/a/e36b37/32.png) [@admin\_berlin](https://discuss.elastic.co/u/admin_berlin)\
**Post date:** [February 11, 2020, 12:22pm UTC](https://discuss.elastic.co/t/authentication-against-active-directory/217383/2 "2020-02-11T12:22:05Z")

</div>

Hi we did fix it.  
We didn't have the same roles in kibana and role\_mapping.yml 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2020, 12:22pm UTC](https://discuss.elastic.co/t/authentication-against-active-directory/217383/3 "2020-03-10T12:22:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
