# Elasticsearch et al SSO with kerberos/AD and groups doesn't work

**URL:** <https://discuss.elastic.co/t/elasticsearch-et-al-sso-with-kerberos-ad-and-groups-doesnt-work/148057>\
**Category:** Elasticsearch\
**Created:** [September 11, 2018, 6:38am UTC](https://discuss.elastic.co/t/elasticsearch-et-al-sso-with-kerberos-ad-and-groups-doesnt-work/148057 "2018-09-11T06:38:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![hakan-carlsson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hakan-carlsson/32/35404_2.png) [@hakan-carlsson](https://discuss.elastic.co/u/hakan-carlsson)\
**Post date:** [September 11, 2018, 6:38am UTC](https://discuss.elastic.co/t/elasticsearch-et-al-sso-with-kerberos-ad-and-groups-doesnt-work/148057/1 "2018-09-11T06:38:04Z")

</div>

Following this:  
[https://www.elastic.co/blog/how-to-secure-your-elasticsearch-clusters-using-kerberos](https://www.elastic.co/blog/how-to-secure-your-elasticsearch-clusters-using-kerberos)  
gets it working with users.  
However, the mapping of groups seems not to work.

LDAP

According to the log, with active\_directory via LDAP I get groups  
[DEBUG][o.e.x.s.a.s.m.NativeRoleMappingStore] [xxxx] Mapping user [UserData{username:haca01; dn:CN=haca01,OU=Users,OU=People,xxxx; groups:[CN=xxx...]

Kerberos

but using kerberos (type=kerberos) it seems no groups are recognized  
[DEBUG][o.e.x.s.a.s.m.NativeRoleMappingStore] [xxxx] Mapping user [UserData{username:haca01@OUR\_REALM; dn:null; groups:[]; metadata:{}; realm=kerb1}] to roles [[monitoring\_user, kibana\_user]]

Tried with role\_mapping to specific group  
"groups": "CN=...OU=, OU=..." (works with LDAP)  
"groups": "groupname"  
"groups": "_"  
"groups": "S-1-...."  
Nothing works, using username, e.g.  
"username": "_"  
works

Config:

elasticsearch 6.4.0 on Fedora 28

elasticsearch.yml with active\_directory LDAP:  
active\_directory\_ldaps:  
type: active\_directory  
order: 1  
domain\_name: OUR\_REALM  
url: ldaps://our\_realm:636  
bind\_dn: xxxx  
bind\_password: xxxx  
follow\_referrals: false  
enabled: true

elasticsearch.yml with kerberos:  
kerb1:  
type: kerberos  
order: 1  
keytab.path: xxxx.keytab  
krb.debug: true  
krb\_debug: true  
remove\_realm\_name: false  
enabled: true

and a krb5.conf

Also: how to get kerberos debug?

# UPDATE

Seems to be limited to username in this release according to:  
[https://www.elastic.co/guide/en/elasticsearch/reference/6.4/configuring-kerberos-realm.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/configuring-kerberos-realm.html)

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [September 11, 2018, 8:37am UTC](https://discuss.elastic.co/t/elasticsearch-et-al-sso-with-kerberos-ad-and-groups-doesnt-work/148057/2 "2018-09-11T08:37:01Z")

</div>

Hi @hakan-carlsson,

Elasticsearch 6.4 adds support for Kerberos but it does not fetch group information to be used in role mapping. For 6.4, the _only_ way to map users to roles is using the information available in the user metadata and using native role mapping.

**In the upcoming release,** we will be **adding a feature to support authorizing realms** where **AD/LDAP realms can act as authorizing realms for the given user**. For more details see, [https://github.com/elastic/elasticsearch/issues/31267](https://github.com/elastic/elasticsearch/issues/31267).  
This would allow you to configure the Kerberos realm for authentication and the roles can be managed by the AD/LDAP realms.

In case you need to enable debug logs for Kerberos, you can refer following documentation:  
[https://www.elastic.co/guide/en/elastic-stack-overview/6.4/trb-security-kerberos.html](https://www.elastic.co/guide/en/elastic-stack-overview/6.4/trb-security-kerberos.html)

Hope this is helpful.

Thanks and Regards,  
Yogesh Gaikwad

---

<div class="post-metadata">

**Author:** ![hakan-carlsson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hakan-carlsson/32/35404_2.png) [@hakan-carlsson](https://discuss.elastic.co/u/hakan-carlsson)\
**Post date:** [September 11, 2018, 9:00am UTC](https://discuss.elastic.co/t/elasticsearch-et-al-sso-with-kerberos-ad-and-groups-doesnt-work/148057/3 "2018-09-11T09:00:46Z")

</div>

I find it strange that it seems that elasticsearch doesn't look at the Authorization Header sent by e.g. web browser. It contains both the user and all the groups that the user has membership in, e.g.

```
Authorization: Negotiate YIIxxxxxxxxx...long.string...

```

If you look at the content, it has all the SID-s of the groups the user has membership in (encrypted by the service ticket keytab the server has).

According to the logs I described it seems that the active\_direcory authc realm looks at these  
[DEBUG][o.e.x.s.a.s.m.NativeRoleMappingStore] [xxxx] Mapping user [UserData{username:haca01; dn:CN=haca01,OU=Users,OU=People,xxxx; **groups:[CN=xxx...]**

but not the kerberos authc realm  
[DEBUG][o.e.x.s.a.s.m.NativeRoleMappingStore] [xxxx] Mapping user [UserData{username:haca01@OUR\_REALM; dn:null; **groups:[]**;

About kerberos debug: I followed the instruction in the link,

jvm.options:  
-Dsun.security.krb5.debug=true  
-Dsun.security.spnego.debug=true  
-Djava.security.krb5.conf=/etc/krb5.conf  
-Djava.security.debug=all

elasticsearch.yml  
xpack.security.authc.realms:  
kerb1:  
type: kerberos  
krb.debug: true

log4j2.properties:  
rootLogger.level: debug

But I fail to find any kerberos debug...

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [September 11, 2018, 12:46pm UTC](https://discuss.elastic.co/t/elasticsearch-et-al-sso-with-kerberos-ad-and-groups-doesnt-work/148057/4 "2018-09-11T12:46:08Z")

</div>

Hi @hakan-carlsson,

You are right the information is there in the ticket, known as _Kerberos_ Privilege Attribute Certificate ( _PAC_ ) carrying authorisation information. **ES 6.4 does not have support for PAC and its on the roadmap for future releases.**

Not much gets logged for Kerberos authentication from Elasticsearch other than authentication information as the implementation is catering towards more on authentication, for authorization the only information required is user principal name and the role mapping is based on that.

The debug settings that I pointed earlier and the ones you enabled, are helpful when you want to troubleshoot problems with Kerberos authentication. They are the JVM logs for debugging Kerberos as Elasticsearch implementation uses JAAS Kerberos login module.

Hope this is helpful.

Thanks and Regards,  
Yogesh Gaikwad

---

<div class="post-metadata">

**Author:** ![hakan-carlsson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hakan-carlsson/32/35404_2.png) [@hakan-carlsson](https://discuss.elastic.co/u/hakan-carlsson)\
**Post date:** [September 12, 2018, 9:37am UTC](https://discuss.elastic.co/t/elasticsearch-et-al-sso-with-kerberos-ad-and-groups-doesnt-work/148057/5 "2018-09-12T09:37:23Z")

</div>

Ok. Thanks for the info.

Is there a ticket/issue on PAC for ES that we could follow?  
Is there any release for which you aim to include this support?

Can't get Kerberos SSO to work with Kibana.  
Is there support for Kerberos SSO in Kibana (I can't seem to find any info about this). Or is the Kerberos SSO only for direct access to elasticsearch?

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [September 12, 2018, 1:07pm UTC](https://discuss.elastic.co/t/elasticsearch-et-al-sso-with-kerberos-ad-and-groups-doesnt-work/148057/6 "2018-09-12T13:07:27Z")

</div>

Hi @hakan-carlsson,

As mentioned in 6.4 Kerberos blog, we have started with Kerberos in ES and the support for other stack components are being planned.

Kibana SSO support for Kerberos is work in progress though not decided on the timelines, rest assured that the feature will be coming.

PAC Support is under consideration but we do not know of any timelines for the same. As an alternative

> [@Yogesh\_Gaikwad](#):
>
> **In the upcoming release,** we will be **adding a feature to support authorizing realms** where **AD/LDAP realms can act as authorizing realms for the given user**. For more details see, [Support for Authorization realms · Issue #31267 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/issues/31267).

Hope this helps.

Thanks and Regards,  
Yogesh Gaikwad

---

<div class="post-metadata">

**Author:** ![hakan-carlsson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hakan-carlsson/32/35404_2.png) [@hakan-carlsson](https://discuss.elastic.co/u/hakan-carlsson)\
**Post date:** [September 12, 2018, 1:27pm UTC](https://discuss.elastic.co/t/elasticsearch-et-al-sso-with-kerberos-ad-and-groups-doesnt-work/148057/7 "2018-09-12T13:27:06Z")

</div>

Thanks for clarifying Kerberos SSO, hope this will be high priority to release 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 10, 2018, 1:27pm UTC](https://discuss.elastic.co/t/elasticsearch-et-al-sso-with-kerberos-ad-and-groups-doesnt-work/148057/8 "2018-10-10T13:27:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
