# Elasticsearch Active Directory Configuration Errors- User authentication

**URL:** <https://discuss.elastic.co/t/elasticsearch-active-directory-configuration-errors-user-authentication/259294>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 21, 2020, 6:07pm UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-configuration-errors-user-authentication/259294 "2020-12-21T18:07:25Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![linfordwoode](https://avatars.discourse-cdn.com/v4/letter/l/5fc32e/32.png) [@linfordwoode](https://discuss.elastic.co/u/linfordwoode)\
**Post date:** [December 21, 2020, 6:07pm UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-configuration-errors-user-authentication/259294/1 "2020-12-21T18:07:25Z")

</div>

Hello,  
I have been stuck on this for a couple of days now. I have tried several options from the forum but I still can't get it to work. Used this documentation [https://www.elastic.co/guide/en/elasticsearch/reference/current/active-directory-realm.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/active-directory-realm.html)  
Below is my active directory realm config for Elasticsearch. Service account used as bind\_dn is already been used by another application to authenticate ldap successfully. Confirmed from security team, there is no firewall block from Elasticsearch server to ldap servers.  
Thanks in advance for your help.

```auto
xpack:
  security:
    authc:
      realms:
        active_directory:
          my_ad:
            order: 0
            domain_name: domain.net
            url: ldaps://ldapserver1@domain.net:389, ldaps://ldapserver2@domain.net:389, ldaps://ldapserver3@domain.net:389, ldaps://ldapserver4@domain.net:389
            bind_dn: serviceaccount@domain.net
            load_balance:
              type: "round_robin"

```

These are the errors I have been getting.

```auto

2020-12-21T12:37:57,760][INFO][o.e.x.s.a.AuthenticationService] [elasticserver@domain.net] Authentication of [elastic] was terminated by realm [reserved] - failed to authenticate user [elastic]

[2020-12-21T12:38:11,631][WARN][o.e.x.s.a.AuthenticationService] [elasticserver@domain.net] Authentication to realm my_ad failed - authenticate failed (Caused by LDAPException(resultCode=91 (connect error), errorMessage='An error occurred while attempting to connect to server ldapserver@domain.net:389: IOException(LDAPException(resultCode=91 (connect error), errorMessage='Unable to verify an attempt to to establish a secure connection to 'ldapserver@domain.net:389' because an unexpected error was encountered during validation processing: SSLPeerUnverifiedException(peer not authenticated), ldapSDKVersion=4.0.8, revision=28812'))'))

[2020-12-21T12:38:11,986][WARN][o.e.x.s.a.AuthenticationService] [elasticserver@domain.net] Authentication to realm my_ad failed - authenticate failed (Caused by LDAPException(resultCode=91 (connect error), errorMessage='An error occurred while attempting to connect to server ldapserver@domain.net:389: IOException(LDAPException(resultCode=91 (connect error), errorMessage='Unable to verify an attempt to to establish a secure connection to 'ldapserver@domain.net:389' because an unexpected error was encountered during validation processing: SSLPeerUnverifiedException(peer not authenticated), ldapSDKVersion=4.0.8, revision=28812'))'))

[2020-12-21T12:38:16,638][WARN][o.e.x.s.a.AuthenticationService] [elasticserver@domain.net] Authentication to realm my_ad failed - authenticate failed (Caused by LDAPException(resultCode=91 (connect error), errorMessage='An error occurred while attempting to connect to server ldapserver@domain.net:389: IOException(LDAPException(resultCode=91 (connect error), errorMessage='Unable to verify an attempt to to establish a secure connection to 'ldapserver@domain.net:389' because an unexpected error was encountered during validation processing: SSLPeerUnverifiedException(peer not authenticated), ldapSDKVersion=4.0.8, revision=28812'))'))

[2020-12-21T12:38:18,457][WARN][o.e.x.s.a.AuthenticationService] [elasticserver@domain.net] Authentication to realm my_ad failed - authenticate failed (Caused by LDAPException(resultCode=91 (connect error), errorMessage='An error occurred while attempting to connect to server ldapserver@domain.net:389: IOException(LDAPException(resultCode=91 (connect error), errorMessage='Unable to verify an attempt to to establish a secure connection to 'ldapserver@domain.net:389' because an unexpected error was encountered during validation processing: SSLPeerUnverifiedException(peer not authenticated), ldapSDKVersion=4.0.8, revision=28812'))'))

[2020-12-21T12:38:29,003][WARN][o.e.x.s.a.AuthenticationService] [elasticserver@domain.net] Authentication to realm my_ad failed - authenticate failed (Caused by LDAPException(resultCode=91 (connect error), errorMessage='An error occurred while attempting to connect to server ldapserver@domain.net:389: IOException(LDAPException(resultCode=91 (connect error), errorMessage='Unable to verify an attempt to to establish a secure connection to 'ldapserver@domain.net:389' because an unexpected error was encountered during validation processing: SSLPeerUnverifiedException(peer not authenticated), ldapSDKVersion=4.0.8, revision=28812'))'))

```

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [December 21, 2020, 6:13pm UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-configuration-errors-user-authentication/259294/2 "2020-12-21T18:13:37Z")

</div>

You need to [configure TLS](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-tls.html#tls-ldap) between elasticsearch and your LDAP

---

<div class="post-metadata">

**Author:** ![linfordwoode](https://avatars.discourse-cdn.com/v4/letter/l/5fc32e/32.png) [@linfordwoode](https://discuss.elastic.co/u/linfordwoode)\
**Post date:** [December 21, 2020, 7:49pm UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-configuration-errors-user-authentication/259294/3 "2020-12-21T19:49:02Z")

</div>

I have configured TLS connection and provided a certificate to elasticsearch. Current elasticsearch.yml looks like this. I am getting the same errors as before. I have currently restricted it to one ldap server

```auto
xpack:
  security:
    authc:
      realms:
        active_directory:
          my_ad:
            order: 0
            domain_name: domain.net
            url: "ldaps://ldapserver1@domain.net:389"
            bind_dn: serviceaccount@domain.net
            load_balance:
              type: "round_robin"
           ssl:
              certificate_authorities: ["/etc/elasticsearch/servercert/cacert.pem"]
```

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [December 21, 2020, 8:09pm UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-configuration-errors-user-authentication/259294/4 "2020-12-21T20:09:34Z")

</div>

Try this

```auto
xpack:
  security:
    authc:
      realms:
        active_directory:
          my_ad:
            order: 0
            domain_name: domain.net
            url: ldaps://ad1.foo.bar.local:636, ldaps://ad2.foo.bar.local:636, ldaps://ad3.foo.bar.local:636
            bind_dn: serviceaccount@domain.net
            load_balance:
              type: "round_robin"
           ssl:
              certificate_authorities: ["/etc/elasticsearch/servercert/cacert.pem"]
              supported_protocols: ["TLSv1.2", "TLSv1.1", "TLSv1"]

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 22, 2020, 7:16am UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-configuration-errors-user-authentication/259294/5 "2020-12-22T07:16:19Z")

</div>

See [https://www.elastic.co/guide/en/elasticsearch/reference/7.11/configuring-tls.html#tls-active-directory](https://www.elastic.co/guide/en/elasticsearch/reference/7.11/configuring-tls.html#tls-active-directory) also

```auto
ssl:
              certificate_authorities:

```

Indentation matters in YAML and the ssl section needs to be under the realm, not under the realm type, so in your case

```auto
xpack:
  security:
    authc:
      realms:
        active_directory:
          my_ad:
            order: 0
            domain_name: domain.net
            url: "ldaps://ldapserver1@domain.net:389"
            bind_dn: serviceaccount@domain.net
            load_balance:
              type: "round_robin"
            ssl:
              certificate_authorities: ["/etc/elasticsearch/servercert/cacert.pem"]

```

---

<div class="post-metadata">

**Author:** ![linfordwoode](https://avatars.discourse-cdn.com/v4/letter/l/5fc32e/32.png) [@linfordwoode](https://discuss.elastic.co/u/linfordwoode)\
**Post date:** [December 22, 2020, 8:51pm UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-configuration-errors-user-authentication/259294/6 "2020-12-22T20:51:16Z")

</div>

Thanks, I was able to get around the error by letting the Elasticsearch server trust the certificate from the LDAP server. But I am stuck on a different issue now. I can log in successfully with elastic built in user but when authenticating with an ldap user, I get below from Kibana. I am not seeing logs on ElasticSearch so I am not quite sure how to troubleshoot this.

```auto
{"statusCode":403,"error":"Forbidden","message":"Forbidden"}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2021, 8:51pm UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-configuration-errors-user-authentication/259294/7 "2021-01-19T20:51:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
