# Can´t authenticate against Active Directory

**URL:** <https://discuss.elastic.co/t/can-t-authenticate-against-active-directory/210420>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 3, 2019, 7:23pm UTC](https://discuss.elastic.co/t/can-t-authenticate-against-active-directory/210420 "2019-12-03T19:23:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![atarallo](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@atarallo](https://discuss.elastic.co/u/atarallo)\
**Post date:** [December 3, 2019, 7:23pm UTC](https://discuss.elastic.co/t/can-t-authenticate-against-active-directory/210420/1 "2019-12-03T19:23:39Z")

</div>

I've installed elk stack from repo packages on Centos 7.7. I´ve successfully started collecting data with metric beat and filebeat. But I can´t authenticate against active directory

I tested with openldaptools from the server I have elastic, and can authenticate and query de AD server.

On the elastic.yml file I've added

```
 xpack.security.enabled: true

xpack:
  security:
    authc:
      realms:
        active_directory:
          poc_ad:
            order: 0
            enabled: true
            domain_name: "poc.net"
            bind_dn: "CN=ldapdesa,CN=Users,DC=poc,DC=net"
            bind_password: "SuperSecret"
            url: ldap://srvad01:389, ldap://srvad02:389
            user_search:
              base_dn: "CN=Users,DC=poc,DC=net"
              scope: "sub_tree"
              filter: "(&(objectClass=user)(userPrincipalName={0}))"
            load_balance:
              type: "failover"

```

I've also tested with curl against the API, had no success.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 3, 2019, 8:12pm UTC](https://discuss.elastic.co/t/can-t-authenticate-against-active-directory/210420/2 "2019-12-03T20:12:34Z")

</div>

> [@atarallo](#):
>
> But I can´t authenticate against active directory

Can you please share some logs from elasticsearch? What are you trying to use as a username when you authenticate? Does that user exist in your Active Directory ?

---

<div class="post-metadata">

**Author:** ![atarallo](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@atarallo](https://discuss.elastic.co/u/atarallo)\
**Post date:** [December 4, 2019, 7:25pm UTC](https://discuss.elastic.co/t/can-t-authenticate-against-active-directory/210420/3 "2019-12-04T19:25:42Z")

</div>

Answering your questions

- I use as username the same login name I use to autenticate on Workstations. The LDAP attribute is samAccount, the same value is loaded in userPrincipalName . I type username in the textbox

- Yes the user exists. I use it daily for login into my workstation. I also installed in the ELK server the OpenLDAP tools. With them I've made manual logins, communications and firewall issues are descarded.

- I had TCPDUMP running during the tests, when I've autenticated nothing happens. When I run command line autentication I see traffic from the server to the DC.

Which log do you need?

I use as username

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 5, 2019, 8:00am UTC](https://discuss.elastic.co/t/can-t-authenticate-against-active-directory/210420/4 "2019-12-05T08:00:36Z")

</div>

> [@atarallo](#):
>
> Which log do you need?

`elasticsearch.log` located in `/var/log/elasticsearch`

Can you remove

```auto
              filter: "(&(objectClass=user)(userPrincipalName={0}))"

```

from your configuration , restart elasticsearch and try again ? The default filter value should cover your use case adequately.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2020, 8:00am UTC](https://discuss.elastic.co/t/can-t-authenticate-against-active-directory/210420/5 "2020-01-02T08:00:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
