# Elasticsearch shield relam problem

**URL:** <https://discuss.elastic.co/t/elasticsearch-shield-relam-problem/22688>\
**Category:** Elasticsearch\
**Created:** [March 16, 2015, 2:57pm UTC](https://discuss.elastic.co/t/elasticsearch-shield-relam-problem/22688 "2015-03-16T14:57:48Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Phani\_Nadiminti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phani_nadiminti/32/45381_2.png) [@Phani\_Nadiminti](https://discuss.elastic.co/u/Phani_Nadiminti)\
**Post date:** [March 16, 2015, 2:57pm UTC](https://discuss.elastic.co/t/elasticsearch-shield-relam-problem/22688/1 "2015-03-16T14:57:48Z")

</div>

Hi All,

I am using elastic version 1.4.2 in development i installed  
elasticsearch shield on each node of my cluster i have 3 nodes in my  
cluster.

i followed the below procedure to install shield.

```
*Step 1: Install* bin/plugin -i elasticsearch/license/latestbin/plugin 

```

-i elasticsearch/shield/latest _Step 2: Start Elasticsearch_  
bin/elasticsearch _Step 3: Add an admin user_ bin/shield/esusers useradd  
es\_admin -r admin _Step 4: Try it out - secured_ curl -XGET  
'[http://localhost:9200/](http://localhost:9200/)' _Step 5: And with a user_ curl -u es\_admin  
-XGET '[http://localhost:9200](http://localhost:9200)

i added admin user by using above command but when i tried to get cluster  
health status form sense console it is asking password  
when i enter my admin password it is showing authentication failed  
exception from console. please suggest me what could be the issues am i  
doing wrong any where?

Thanks  
phani

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/122a5401-a07b-4007-a664-f06e7834d83c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/122a5401-a07b-4007-a664-f06e7834d83c%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [March 16, 2015, 4:42pm UTC](https://discuss.elastic.co/t/elasticsearch-shield-relam-problem/22688/2 "2015-03-16T16:42:00Z")

</div>

Hi Phani,

How did you install elasticsearch and where is your elasticsearch  
configuration located? If you have used a RPM or DEB package, you will need  
to add an environment variable before running the esusers command, please  
see [Getting Started with Shield | Shield [2.4] | Elastic](http://www.elastic.co/guide/en/shield/current/getting-started.html)

On Monday, March 16, 2015 at 7:57:48 AM UTC-7, [phani.n...@goktree.com](mailto:phani.n...@goktree.com) wrote:

> Hi All,
> 
> I am using elastic version 1.4.2 in development i installed  
> elasticsearch shield on each node of my cluster i have 3 nodes in my  
> cluster.
> 
> i followed the below procedure to install shield.
> 
> ```
> *Step 1: Install* bin/plugin -i elasticsearch/license/latestbin/plugin 
> 
> ```
> 
> -i elasticsearch/shield/latest _Step 2: Start Elasticsearch_  
> bin/elasticsearch _Step 3: Add an admin user_ bin/shield/esusers  
> useradd es\_admin -r admin _Step 4: Try it out - secured_ curl -XGET '  
> [http://localhost:9200/](http://localhost:9200/)' _Step 5: And with a user_ curl -u es\_admin  
> -XGET '[http://localhost:9200](http://localhost:9200)
> 
> i added admin user by using above command but when i tried to get cluster  
> health status form sense console it is asking password  
> when i enter my admin password it is showing authentication failed  
> exception from console. please suggest me what could be the issues am i  
> doing wrong any where?
> 
> Thanks  
> phani

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/70210d29-2e7a-49a0-833c-dad4f0542a9f%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/70210d29-2e7a-49a0-833c-dad4f0542a9f%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Phani\_Nadiminti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phani_nadiminti/32/45381_2.png) [@Phani\_Nadiminti](https://discuss.elastic.co/u/Phani_Nadiminti)\
**Post date:** [March 18, 2015, 9:33am UTC](https://discuss.elastic.co/t/elasticsearch-shield-relam-problem/22688/3 "2015-03-18T09:33:36Z")

</div>

HI Jay,

Thank you for the reply i tried the following steps.

i did .rpm installation in linux servers my configuration file located  
at /etc/elasticsearch (main es coniguration file)

But when i install shied i see there is a configurations directory  
created inside ES\_HOME(/usr/share/elasticsearch/config)

I issued following command to add path :export  
ES\_JAVA\_OPTS="-Des.path.conf=/usr/share/elasticsearch/config"

```
    i am able to create user but when i try to authenticate it is not 

```

validating even though we added the path. please suggest me if i am doing  
wrong here?

On Monday, March 16, 2015 at 10:12:00 PM UTC+5:30, Jay Modi wrote:

> Hi Phani,
> 
> How did you install elasticsearch and where is your elasticsearch  
> configuration located? If you have used a RPM or DEB package, you will need  
> to add an environment variable before running the esusers command, please  
> see [Getting Started with Shield | Shield [2.4] | Elastic](http://www.elastic.co/guide/en/shield/current/getting-started.html)
> 
> On Monday, March 16, 2015 at 7:57:48 AM UTC-7, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> wrote:
> 
> > Hi All,
> > 
> > I am using elastic version 1.4.2 in development i installed  
> > elasticsearch shield on each node of my cluster i have 3 nodes in my  
> > cluster.
> > 
> > i followed the below procedure to install shield.
> > 
> > ```
> > *Step 1: Install* bin/plugin -i elasticsearch/license/latestbin/plugin 
> > 
> > ```
> > 
> > -i elasticsearch/shield/latest _Step 2: Start Elasticsearch_  
> > bin/elasticsearch _Step 3: Add an admin user_ bin/shield/esusers  
> > useradd es\_admin -r admin _Step 4: Try it out - secured_ curl -XGET '  
> > [http://localhost:9200/](http://localhost:9200/)' _Step 5: And with a user_ curl -u es\_admin  
> > -XGET '[http://localhost:9200](http://localhost:9200)
> > 
> > i added admin user by using above command but when i tried to get cluster  
> > health status form sense console it is asking password  
> > when i enter my admin password it is showing authentication failed  
> > exception from console. please suggest me what could be the issues am i  
> > doing wrong any where?
> > 
> > Thanks  
> > phani

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/3b3c3d9e-8dcc-4e3a-97d9-9a34d7c654f5%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3b3c3d9e-8dcc-4e3a-97d9-9a34d7c654f5%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [March 18, 2015, 12:50pm UTC](https://discuss.elastic.co/t/elasticsearch-shield-relam-problem/22688/4 "2015-03-18T12:50:28Z")

</div>

Hi Phani,

I think the correct thing to do is:

export ES\_JAVA\_OPTS="-Des.path.conf=/etc/elasticsearch"  
bin/shield/esusers useradd es\_admin -r admin

Verify that /etc/elasticsearch/shield/users exists and contains an entry  
for the admin user. Once you have confirmed that, then try to authenticate.

The issue with steps you have taken is that your elasticsearch instance is  
looking for configuration in /etc/elasticsearch and the configuration for  
Shield is in ES\_HOME by default. The packaged versions of elasticsearch  
expect all configuration (including that for plugins) to be in  
/etc/elasticsearch. We're looking at how we can make this easier.

On Wednesday, March 18, 2015 at 5:33:36 AM UTC-4, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
wrote:

> HI Jay,
> 
> Thank you for the reply i tried the following steps.
> 
> i did .rpm installation in linux servers my configuration file located  
> at /etc/elasticsearch (main es coniguration file)
> 
> But when i install shied i see there is a configurations directory  
> created inside ES\_HOME(/usr/share/elasticsearch/config)
> 
> I issued following command to add path :export  
> ES\_JAVA\_OPTS="-Des.path.conf=/usr/share/elasticsearch/config"
> 
> ```
> i am able to create user but when i try to authenticate it is not 
> 
> ```
> 
> validating even though we added the path. please suggest me if i am doing  
> wrong here?
> 
> On Monday, March 16, 2015 at 10:12:00 PM UTC+5:30, Jay Modi wrote:
> 
> > Hi Phani,
> > 
> > How did you install elasticsearch and where is your elasticsearch  
> > configuration located? If you have used a RPM or DEB package, you will need  
> > to add an environment variable before running the esusers command, please  
> > see [Getting Started with Shield | Shield [2.4] | Elastic](http://www.elastic.co/guide/en/shield/current/getting-started.html)
> > 
> > On Monday, March 16, 2015 at 7:57:48 AM UTC-7, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> > wrote:
> > 
> > > Hi All,
> > > 
> > > I am using elastic version 1.4.2 in development i installed  
> > > elasticsearch shield on each node of my cluster i have 3 nodes in my  
> > > cluster.
> > > 
> > > i followed the below procedure to install shield.
> > > 
> > > ```
> > > *Step 1: Install* bin/plugin -i elasticsearch/license/latestbin/plugin 
> > > 
> > > ```
> > > 
> > > -i elasticsearch/shield/latest _Step 2: Start Elasticsearch_  
> > > bin/elasticsearch _Step 3: Add an admin user_ bin/shield/esusers  
> > > useradd es\_admin -r admin _Step 4: Try it out - secured_ curl -XGET '  
> > > [http://localhost:9200/](http://localhost:9200/)' _Step 5: And with a user_ curl -u es\_admin  
> > > -XGET '[http://localhost:9200](http://localhost:9200)
> > > 
> > > i added admin user by using above command but when i tried to get  
> > > cluster health status form sense console it is asking password  
> > > when i enter my admin password it is showing authentication failed  
> > > exception from console. please suggest me what could be the issues am i  
> > > doing wrong any where?
> > > 
> > > Thanks  
> > > phani

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/85c55b2c-205d-4c5d-8a44-3b6ae282043d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/85c55b2c-205d-4c5d-8a44-3b6ae282043d%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Phani\_Nadiminti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phani_nadiminti/32/45381_2.png) [@Phani\_Nadiminti](https://discuss.elastic.co/u/Phani_Nadiminti)\
**Post date:** [March 18, 2015, 1:12pm UTC](https://discuss.elastic.co/t/elasticsearch-shield-relam-problem/22688/5 "2015-03-18T13:12:27Z")

</div>

Thank you Jay for quick reply yes it got worked I changed the path to  
es\_home config.now authentication is performing fine next I am looking in  
to LDAP integration with Elasticsearch can you suggest me steps how can we  
integrate ldap to elasticsearch.

Thanks  
phani.

On Wednesday, March 18, 2015 at 6:20:29 PM UTC+5:30, Jay Modi wrote:

> Hi Phani,
> 
> I think the correct thing to do is:
> 
> export ES\_JAVA\_OPTS="-Des.path.conf=/etc/elasticsearch"  
> bin/shield/esusers useradd es\_admin -r admin
> 
> Verify that /etc/elasticsearch/shield/users exists and contains an entry  
> for the admin user. Once you have confirmed that, then try to authenticate.
> 
> The issue with steps you have taken is that your elasticsearch instance is  
> looking for configuration in /etc/elasticsearch and the configuration for  
> Shield is in ES\_HOME by default. The packaged versions of elasticsearch  
> expect all configuration (including that for plugins) to be in  
> /etc/elasticsearch. We're looking at how we can make this easier.
> 
> On Wednesday, March 18, 2015 at 5:33:36 AM UTC-4, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> wrote:
> 
> > HI Jay,
> > 
> > Thank you for the reply i tried the following steps.
> > 
> > i did .rpm installation in linux servers my configuration file located  
> > at /etc/elasticsearch (main es coniguration file)
> > 
> > But when i install shied i see there is a configurations directory  
> > created inside ES\_HOME(/usr/share/elasticsearch/config)
> > 
> > I issued following command to add path :export  
> > ES\_JAVA\_OPTS="-Des.path.conf=/usr/share/elasticsearch/config"
> > 
> > ```
> > i am able to create user but when i try to authenticate it is not 
> > 
> > ```
> > 
> > validating even though we added the path. please suggest me if i am doing  
> > wrong here?
> > 
> > On Monday, March 16, 2015 at 10:12:00 PM UTC+5:30, Jay Modi wrote:
> > 
> > > Hi Phani,
> > > 
> > > How did you install elasticsearch and where is your elasticsearch  
> > > configuration located? If you have used a RPM or DEB package, you will need  
> > > to add an environment variable before running the esusers command, please  
> > > see [Getting Started with Shield | Shield [2.4] | Elastic](http://www.elastic.co/guide/en/shield/current/getting-started.html)
> > > 
> > > On Monday, March 16, 2015 at 7:57:48 AM UTC-7, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> > > wrote:
> > > 
> > > > Hi All,
> > > > 
> > > > I am using elastic version 1.4.2 in development i installed  
> > > > elasticsearch shield on each node of my cluster i have 3 nodes in my  
> > > > cluster.
> > > > 
> > > > i followed the below procedure to install shield.
> > > > 
> > > > ```
> > > > *Step 1: Install* bin/plugin -i elasticsearch/license/latestbin/plugin 
> > > > 
> > > > ```
> > > > 
> > > > -i elasticsearch/shield/latest _Step 2: Start Elasticsearch_  
> > > > bin/elasticsearch _Step 3: Add an admin user_ bin/shield/esusers  
> > > > useradd es\_admin -r admin _Step 4: Try it out - secured_ curl -XGET  
> > > > '[http://localhost:9200/](http://localhost:9200/)' _Step 5: And with a user_ curl -u es\_admin  
> > > > -XGET '[http://localhost:9200](http://localhost:9200)
> > > > 
> > > > i added admin user by using above command but when i tried to get  
> > > > cluster health status form sense console it is asking password  
> > > > when i enter my admin password it is showing authentication failed  
> > > > exception from console. please suggest me what could be the issues am i  
> > > > doing wrong any where?
> > > > 
> > > > Thanks  
> > > > phani

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/7c40552b-f6b1-43bb-8704-b3ed08768016%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/7c40552b-f6b1-43bb-8704-b3ed08768016%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [March 18, 2015, 2:35pm UTC](https://discuss.elastic.co/t/elasticsearch-shield-relam-problem/22688/6 "2015-03-18T14:35:37Z")

</div>

What type of LDAP server are you integrating with? We have some  
documentation for LDAP  
setup, [http://www.elastic.co/guide/en/shield/current/ldap.html](http://www.elastic.co/guide/en/shield/current/ldap.html).

If you are using Active Directory, there is a specific realm for it that  
abstracts some of the LDAP setup to make it  
simpler: [http://www.elastic.co/guide/en/shield/current/active\_directory.html](http://www.elastic.co/guide/en/shield/current/active_directory.html)

On Wednesday, March 18, 2015 at 9:12:27 AM UTC-4, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
wrote:

> Thank you Jay for quick reply yes it got worked I changed the path to  
> es\_home config.now authentication is performing fine next I am looking in  
> to LDAP integration with Elasticsearch can you suggest me steps how can we  
> integrate ldap to elasticsearch.
> 
> Thanks  
> phani.
> 
> On Wednesday, March 18, 2015 at 6:20:29 PM UTC+5:30, Jay Modi wrote:
> 
> > Hi Phani,
> > 
> > I think the correct thing to do is:
> > 
> > export ES\_JAVA\_OPTS="-Des.path.conf=/etc/elasticsearch"  
> > bin/shield/esusers useradd es\_admin -r admin
> > 
> > Verify that /etc/elasticsearch/shield/users exists and contains an entry  
> > for the admin user. Once you have confirmed that, then try to authenticate.
> > 
> > The issue with steps you have taken is that your elasticsearch instance  
> > is looking for configuration in /etc/elasticsearch and the configuration  
> > for Shield is in ES\_HOME by default. The packaged versions of elasticsearch  
> > expect all configuration (including that for plugins) to be in  
> > /etc/elasticsearch. We're looking at how we can make this easier.
> > 
> > On Wednesday, March 18, 2015 at 5:33:36 AM UTC-4, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> > wrote:
> > 
> > > HI Jay,
> > > 
> > > Thank you for the reply i tried the following steps.
> > > 
> > > i did .rpm installation in linux servers my configuration file  
> > > located at /etc/elasticsearch (main es coniguration file)
> > > 
> > > But when i install shied i see there is a configurations directory  
> > > created inside ES\_HOME(/usr/share/elasticsearch/config)
> > > 
> > > I issued following command to add path :export  
> > > ES\_JAVA\_OPTS="-Des.path.conf=/usr/share/elasticsearch/config"
> > > 
> > > ```
> > > i am able to create user but when i try to authenticate it is 
> > > 
> > > ```
> > > 
> > > not validating even though we added the path. please suggest me if i am  
> > > doing wrong here?
> > > 
> > > On Monday, March 16, 2015 at 10:12:00 PM UTC+5:30, Jay Modi wrote:
> > > 
> > > > Hi Phani,
> > > > 
> > > > How did you install elasticsearch and where is your elasticsearch  
> > > > configuration located? If you have used a RPM or DEB package, you will need  
> > > > to add an environment variable before running the esusers command, please  
> > > > see [Getting Started with Shield | Shield [2.4] | Elastic](http://www.elastic.co/guide/en/shield/current/getting-started.html)
> > > > 
> > > > On Monday, March 16, 2015 at 7:57:48 AM UTC-7, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> > > > wrote:
> > > > 
> > > > > Hi All,
> > > > > 
> > > > > I am using elastic version 1.4.2 in development i installed  
> > > > > elasticsearch shield on each node of my cluster i have 3 nodes in my  
> > > > > cluster.
> > > > > 
> > > > > i followed the below procedure to install shield.
> > > > > 
> > > > > ```
> > > > > *Step 1: Install* bin/plugin -i elasticsearch/license/latestbin/plugin 
> > > > > 
> > > > > ```
> > > > > 
> > > > > -i elasticsearch/shield/latest _Step 2: Start Elasticsearch_  
> > > > > bin/elasticsearch _Step 3: Add an admin user_ bin/shield/esusers  
> > > > > useradd es\_admin -r admin _Step 4: Try it out - secured_ curl  
> > > > > -XGET '[http://localhost:9200/](http://localhost:9200/)' _Step 5: And with a user_ curl -u  
> > > > > es\_admin -XGET '[http://localhost:9200](http://localhost:9200)
> > > > > 
> > > > > i added admin user by using above command but when i tried to get  
> > > > > cluster health status form sense console it is asking password  
> > > > > when i enter my admin password it is showing authentication failed  
> > > > > exception from console. please suggest me what could be the issues am i  
> > > > > doing wrong any where?
> > > > > 
> > > > > Thanks  
> > > > > phani

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/83bc4a70-fa18-444f-8c2a-efe31a3ce45f%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/83bc4a70-fa18-444f-8c2a-efe31a3ce45f%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Phani\_Nadiminti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phani_nadiminti/32/45381_2.png) [@Phani\_Nadiminti](https://discuss.elastic.co/u/Phani_Nadiminti)\
**Post date:** [March 23, 2015, 6:43am UTC](https://discuss.elastic.co/t/elasticsearch-shield-relam-problem/22688/7 "2015-03-23T06:43:29Z")

</div>

Hi Jay,

sorry for late reply . I am using openldap server .i followed the  
configurations given by es people i did like in example but i am not able  
to login with ldap credentials.is ldap in Elasticsearch is mount ldap or  
it will import users in to the file?  
i have tried following link

```
    http://www.elastic.co/guide/en/shield/current/ldap.html . but i 

```

didn't get proper result i have the following configurations to my LDAP  
server.please find the following.

Principal : cn=Manager,dc=test,dc=org  
Base DN : ou=People,dc=test,dc=org

```
filter : uid=%s
 
        the above are my ldap configuration details please suggest me 

```

how can we achieve with above credentials my using above link  
([http://www.elastic.co/guide/en/shield/current/ldap.html](http://www.elastic.co/guide/en/shield/current/ldap.html) )

Thanks,  
phani

On Wednesday, March 18, 2015 at 8:05:37 PM UTC+5:30, Jay Modi wrote:

> What type of LDAP server are you integrating with? We have some  
> documentation for LDAP setup,  
> [http://www.elastic.co/guide/en/shield/current/ldap.html](http://www.elastic.co/guide/en/shield/current/ldap.html).
> 
> If you are using Active Directory, there is a specific realm for it that  
> abstracts some of the LDAP setup to make it simpler:  
> [http://www.elastic.co/guide/en/shield/current/active\_directory.html](http://www.elastic.co/guide/en/shield/current/active_directory.html)
> 
> On Wednesday, March 18, 2015 at 9:12:27 AM UTC-4, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> wrote:
> 
> > Thank you Jay for quick reply yes it got worked I changed the path to  
> > es\_home config.now authentication is performing fine next I am looking in  
> > to LDAP integration with Elasticsearch can you suggest me steps how can we  
> > integrate ldap to elasticsearch.
> > 
> > Thanks  
> > phani.
> > 
> > On Wednesday, March 18, 2015 at 6:20:29 PM UTC+5:30, Jay Modi wrote:
> > 
> > > Hi Phani,
> > > 
> > > I think the correct thing to do is:
> > > 
> > > export ES\_JAVA\_OPTS="-Des.path.conf=/etc/elasticsearch"  
> > > bin/shield/esusers useradd es\_admin -r admin
> > > 
> > > Verify that /etc/elasticsearch/shield/users exists and contains an entry  
> > > for the admin user. Once you have confirmed that, then try to authenticate.
> > > 
> > > The issue with steps you have taken is that your elasticsearch instance  
> > > is looking for configuration in /etc/elasticsearch and the configuration  
> > > for Shield is in ES\_HOME by default. The packaged versions of elasticsearch  
> > > expect all configuration (including that for plugins) to be in  
> > > /etc/elasticsearch. We're looking at how we can make this easier.
> > > 
> > > On Wednesday, March 18, 2015 at 5:33:36 AM UTC-4, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> > > wrote:
> > > 
> > > > HI Jay,
> > > > 
> > > > Thank you for the reply i tried the following steps.
> > > > 
> > > > i did .rpm installation in linux servers my configuration file  
> > > > located at /etc/elasticsearch (main es coniguration file)
> > > > 
> > > > But when i install shied i see there is a configurations directory  
> > > > created inside ES\_HOME(/usr/share/elasticsearch/config)
> > > > 
> > > > I issued following command to add path :export  
> > > > ES\_JAVA\_OPTS="-Des.path.conf=/usr/share/elasticsearch/config"
> > > > 
> > > > ```
> > > > i am able to create user but when i try to authenticate it is 
> > > > 
> > > > ```
> > > > 
> > > > not validating even though we added the path. please suggest me if i am  
> > > > doing wrong here?
> > > > 
> > > > On Monday, March 16, 2015 at 10:12:00 PM UTC+5:30, Jay Modi wrote:
> > > > 
> > > > > Hi Phani,
> > > > > 
> > > > > How did you install elasticsearch and where is your elasticsearch  
> > > > > configuration located? If you have used a RPM or DEB package, you will need  
> > > > > to add an environment variable before running the esusers command, please  
> > > > > see [Getting Started with Shield | Shield [2.4] | Elastic](http://www.elastic.co/guide/en/shield/current/getting-started.html)
> > > > > 
> > > > > On Monday, March 16, 2015 at 7:57:48 AM UTC-7, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> > > > > wrote:
> > > > > 
> > > > > > Hi All,
> > > > > > 
> > > > > > I am using elastic version 1.4.2 in development i installed  
> > > > > > elasticsearch shield on each node of my cluster i have 3 nodes in my  
> > > > > > cluster.
> > > > > > 
> > > > > > i followed the below procedure to install shield.
> > > > > > 
> > > > > > ```
> > > > > > *Step 1: Install* bin/plugin -i elasticsearch/license/latestbin/plugin 
> > > > > > 
> > > > > > ```
> > > > > > 
> > > > > > -i elasticsearch/shield/latest _Step 2: Start Elasticsearch_  
> > > > > > bin/elasticsearch _Step 3: Add an admin user_ bin/shield/esusers  
> > > > > > useradd es\_admin -r admin _Step 4: Try it out - secured_ curl  
> > > > > > -XGET '[http://localhost:9200/](http://localhost:9200/)' _Step 5: And with a user_ curl -u  
> > > > > > es\_admin -XGET '[http://localhost:9200](http://localhost:9200)
> > > > > > 
> > > > > > i added admin user by using above command but when i tried to get  
> > > > > > cluster health status form sense console it is asking password  
> > > > > > when i enter my admin password it is showing authentication failed  
> > > > > > exception from console. please suggest me what could be the issues am i  
> > > > > > doing wrong any where?
> > > > > > 
> > > > > > Thanks  
> > > > > > phani

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/f2293336-0358-4732-b3ba-18c4562e5cd6%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f2293336-0358-4732-b3ba-18c4562e5cd6%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [March 23, 2015, 10:08pm UTC](https://discuss.elastic.co/t/elasticsearch-shield-relam-problem/22688/8 "2015-03-23T22:08:48Z")

</div>

Since you are using uid, your setup would look something like this

shield:  
authc:  
realms:  
ldap1:  
type: ldap  
order: 0  
url: "ldap://ldapserver:389"  
user\_dn\_templates:  
- "uid={0}, ou=People,dc=test,dc=org"

This assumes all users are directly in the People OU. If that is not the  
case, you'll have to update the template or add additional templates. Can  
you tell me a little more about how the groups are setup in your ldap? What  
is their objectClass and do they have the member, unqiueMember, or  
memberUid attribute? You will probably need to configure the group search  
and that additional information will be necessary to ensure it works.

Also to help with debugging, it is helpful to set "shield.authc: DEBUG" in  
the logging.yml file

On Monday, March 23, 2015 at 2:43:29 AM UTC-4, [phani.n...@goktree.com](mailto:phani.n...@goktree.com) wrote:

> Hi Jay,
> 
> sorry for late reply . I am using openldap server .i followed the  
> configurations given by es people i did like in example but i am not able  
> to login with ldap credentials.is ldap in Elasticsearch is mount ldap or  
> it will import users in to the file?  
> i have tried following link
> 
> ```
> http://www.elastic.co/guide/en/shield/current/ldap.html . but i 
> 
> ```
> 
> didn't get proper result i have the following configurations to my LDAP  
> server.please find the following.
> 
> Principal : cn=Manager,dc=test,dc=org  
> Base DN : ou=People,dc=test,dc=org
> 
> ```
> filter : uid=%s
>  
> the above are my ldap configuration details please suggest me 
> 
> ```
> 
> how can we achieve with above credentials my using above link (  
> [http://www.elastic.co/guide/en/shield/current/ldap.html](http://www.elastic.co/guide/en/shield/current/ldap.html) )
> 
> Thanks,  
> phani
> 
> On Wednesday, March 18, 2015 at 8:05:37 PM UTC+5:30, Jay Modi wrote:
> 
> > What type of LDAP server are you integrating with? We have some  
> > documentation for LDAP setup,  
> > [http://www.elastic.co/guide/en/shield/current/ldap.html](http://www.elastic.co/guide/en/shield/current/ldap.html).
> > 
> > If you are using Active Directory, there is a specific realm for it that  
> > abstracts some of the LDAP setup to make it simpler:  
> > [http://www.elastic.co/guide/en/shield/current/active\_directory.html](http://www.elastic.co/guide/en/shield/current/active_directory.html)
> > 
> > On Wednesday, March 18, 2015 at 9:12:27 AM UTC-4, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> > wrote:
> > 
> > > Thank you Jay for quick reply yes it got worked I changed the path to  
> > > es\_home config.now authentication is performing fine next I am looking in  
> > > to LDAP integration with Elasticsearch can you suggest me steps how can we  
> > > integrate ldap to elasticsearch.
> > > 
> > > Thanks  
> > > phani.
> > > 
> > > On Wednesday, March 18, 2015 at 6:20:29 PM UTC+5:30, Jay Modi wrote:
> > > 
> > > > Hi Phani,
> > > > 
> > > > I think the correct thing to do is:
> > > > 
> > > > export ES\_JAVA\_OPTS="-Des.path.conf=/etc/elasticsearch"  
> > > > bin/shield/esusers useradd es\_admin -r admin
> > > > 
> > > > Verify that /etc/elasticsearch/shield/users exists and contains an  
> > > > entry for the admin user. Once you have confirmed that, then try to  
> > > > authenticate.
> > > > 
> > > > The issue with steps you have taken is that your elasticsearch instance  
> > > > is looking for configuration in /etc/elasticsearch and the configuration  
> > > > for Shield is in ES\_HOME by default. The packaged versions of elasticsearch  
> > > > expect all configuration (including that for plugins) to be in  
> > > > /etc/elasticsearch. We're looking at how we can make this easier.
> > > > 
> > > > On Wednesday, March 18, 2015 at 5:33:36 AM UTC-4,  
> > > > [phani.n...@goktree.com](mailto:phani.n...@goktree.com) wrote:
> > > > 
> > > > > HI Jay,
> > > > > 
> > > > > Thank you for the reply i tried the following steps.
> > > > > 
> > > > > i did .rpm installation in linux servers my configuration file  
> > > > > located at /etc/elasticsearch (main es coniguration file)
> > > > > 
> > > > > But when i install shied i see there is a configurations directory  
> > > > > created inside ES\_HOME(/usr/share/elasticsearch/config)
> > > > > 
> > > > > I issued following command to add path :export  
> > > > > ES\_JAVA\_OPTS="-Des.path.conf=/usr/share/elasticsearch/config"
> > > > > 
> > > > > ```
> > > > > i am able to create user but when i try to authenticate it is 
> > > > > 
> > > > > ```
> > > > > 
> > > > > not validating even though we added the path. please suggest me if i am  
> > > > > doing wrong here?
> > > > > 
> > > > > On Monday, March 16, 2015 at 10:12:00 PM UTC+5:30, Jay Modi wrote:
> > > > > 
> > > > > > Hi Phani,
> > > > > > 
> > > > > > How did you install elasticsearch and where is your elasticsearch  
> > > > > > configuration located? If you have used a RPM or DEB package, you will need  
> > > > > > to add an environment variable before running the esusers command, please  
> > > > > > see  
> > > > > > [Getting Started with Shield | Shield [2.4] | Elastic](http://www.elastic.co/guide/en/shield/current/getting-started.html)
> > > > > > 
> > > > > > On Monday, March 16, 2015 at 7:57:48 AM UTC-7, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> > > > > > wrote:
> > > > > > 
> > > > > > > Hi All,
> > > > > > > 
> > > > > > > I am using elastic version 1.4.2 in development i installed  
> > > > > > > elasticsearch shield on each node of my cluster i have 3 nodes in my  
> > > > > > > cluster.
> > > > > > > 
> > > > > > > i followed the below procedure to install shield.
> > > > > > > 
> > > > > > > ```
> > > > > > > *Step 1: Install* bin/plugin -i elasticsearch/license/latestbin/plugin 
> > > > > > > 
> > > > > > > ```
> > > > > > > 
> > > > > > > -i elasticsearch/shield/latest _Step 2: Start Elasticsearch_  
> > > > > > > bin/elasticsearch _Step 3: Add an admin user_ bin/shield/esusers  
> > > > > > > useradd es\_admin -r admin _Step 4: Try it out - secured_ curl  
> > > > > > > -XGET '[http://localhost:9200/](http://localhost:9200/)' _Step 5: And with a user_ curl -u  
> > > > > > > es\_admin -XGET '[http://localhost:9200](http://localhost:9200)
> > > > > > > 
> > > > > > > i added admin user by using above command but when i tried to get  
> > > > > > > cluster health status form sense console it is asking password  
> > > > > > > when i enter my admin password it is showing authentication failed  
> > > > > > > exception from console. please suggest me what could be the issues am i  
> > > > > > > doing wrong any where?
> > > > > > > 
> > > > > > > Thanks  
> > > > > > > phani

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a890672c-0cfb-4394-b996-4841a566ff71%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a890672c-0cfb-4394-b996-4841a566ff71%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [March 24, 2015, 5:34pm UTC](https://discuss.elastic.co/t/elasticsearch-shield-relam-problem/22688/9 "2015-03-24T17:34:14Z")

</div>

Phani,

We just released Shield 1.1 and 1.2  
([Shield 1.1 and 1.2 Released | Elastic Blog](https://www.elastic.co/blog/shield-1-1-and-1-2-released)). LDAP user search  
is included and may be worth trying out. If you were to use it, I think  
your configuration would look something like:

shield:  
authc:  
realms:  
ldap1:  
type: ldap  
order: 0  
url: "ldap://ldapserver:389"  
bind\_dn: "cn=Manager,dc=test,dc=org"  
bind\_password: changeme  
user\_search:  
base\_dn: "ou=People,dc=test,dc=org"  
group\_search:  
base\_dn: "dc=test,dc=org"

This assumes the "cn=Manager,dc=test,dc=org" is a user with search  
credentials on the ldap. The earlier questions I had about groups would  
still apply

On Monday, March 23, 2015 at 6:08:48 PM UTC-4, Jay Modi wrote:

> Since you are using uid, your setup would look something like this
> 
> shield:  
> authc:  
> realms:  
> ldap1:  
> type: ldap  
> order: 0  
> url: "ldap://ldapserver:389"  
> user\_dn\_templates:  
> - "uid={0}, ou=People,dc=test,dc=org"
> 
> This assumes all users are directly in the People OU. If that is not the  
> case, you'll have to update the template or add additional templates. Can  
> you tell me a little more about how the groups are setup in your ldap? What  
> is their objectClass and do they have the member, unqiueMember, or  
> memberUid attribute? You will probably need to configure the group search  
> and that additional information will be necessary to ensure it works.
> 
> Also to help with debugging, it is helpful to set "shield.authc: DEBUG" in  
> the logging.yml file
> 
> On Monday, March 23, 2015 at 2:43:29 AM UTC-4, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> wrote:
> 
> > Hi Jay,
> > 
> > sorry for late reply . I am using openldap server .i followed the  
> > configurations given by es people i did like in example but i am not able  
> > to login with ldap credentials.is ldap in Elasticsearch is mount ldap  
> > or it will import users in to the file?  
> > i have tried following link
> > 
> > ```
> > http://www.elastic.co/guide/en/shield/current/ldap.html . but i 
> > 
> > ```
> > 
> > didn't get proper result i have the following configurations to my LDAP  
> > server.please find the following.
> > 
> > Principal : cn=Manager,dc=test,dc=org  
> > Base DN : ou=People,dc=test,dc=org
> > 
> > ```
> > filter : uid=%s
> >  
> > the above are my ldap configuration details please suggest me 
> > 
> > ```
> > 
> > how can we achieve with above credentials my using above link (  
> > [http://www.elastic.co/guide/en/shield/current/ldap.html](http://www.elastic.co/guide/en/shield/current/ldap.html) )
> > 
> > Thanks,  
> > phani
> > 
> > On Wednesday, March 18, 2015 at 8:05:37 PM UTC+5:30, Jay Modi wrote:
> > 
> > > What type of LDAP server are you integrating with? We have some  
> > > documentation for LDAP setup,  
> > > [http://www.elastic.co/guide/en/shield/current/ldap.html](http://www.elastic.co/guide/en/shield/current/ldap.html).
> > > 
> > > If you are using Active Directory, there is a specific realm for it that  
> > > abstracts some of the LDAP setup to make it simpler:  
> > > [http://www.elastic.co/guide/en/shield/current/active\_directory.html](http://www.elastic.co/guide/en/shield/current/active_directory.html)
> > > 
> > > On Wednesday, March 18, 2015 at 9:12:27 AM UTC-4, [phani.n...@goktree.com](mailto:phani.n...@goktree.com)  
> > > wrote:
> > > 
> > > > Thank you Jay for quick reply yes it got worked I changed the path to  
> > > > es\_home config.now authentication is performing fine next I am looking in  
> > > > to LDAP integration with Elasticsearch can you suggest me steps how can we  
> > > > integrate ldap to elasticsearch.
> > > > 
> > > > Thanks  
> > > > phani.
> > > > 
> > > > On Wednesday, March 18, 2015 at 6:20:29 PM UTC+5:30, Jay Modi wrote:
> > > > 
> > > > > Hi Phani,
> > > > > 
> > > > > I think the correct thing to do is:
> > > > > 
> > > > > export ES\_JAVA\_OPTS="-Des.path.conf=/etc/elasticsearch"  
> > > > > bin/shield/esusers useradd es\_admin -r admin
> > > > > 
> > > > > Verify that /etc/elasticsearch/shield/users exists and contains an  
> > > > > entry for the admin user. Once you have confirmed that, then try to  
> > > > > authenticate.
> > > > > 
> > > > > The issue with steps you have taken is that your elasticsearch  
> > > > > instance is looking for configuration in /etc/elasticsearch and the  
> > > > > configuration for Shield is in ES\_HOME by default. The packaged versions of  
> > > > > elasticsearch expect all configuration (including that for plugins) to be  
> > > > > in /etc/elasticsearch. We're looking at how we can make this easier.
> > > > > 
> > > > > On Wednesday, March 18, 2015 at 5:33:36 AM UTC-4,  
> > > > > [phani.n...@goktree.com](mailto:phani.n...@goktree.com) wrote:
> > > > > 
> > > > > > HI Jay,
> > > > > > 
> > > > > > Thank you for the reply i tried the following steps.
> > > > > > 
> > > > > > i did .rpm installation in linux servers my configuration file  
> > > > > > located at /etc/elasticsearch (main es coniguration file)
> > > > > > 
> > > > > > But when i install shied i see there is a configurations directory  
> > > > > > created inside ES\_HOME(/usr/share/elasticsearch/config)
> > > > > > 
> > > > > > I issued following command to add path :export  
> > > > > > ES\_JAVA\_OPTS="-Des.path.conf=/usr/share/elasticsearch/config"
> > > > > > 
> > > > > > ```
> > > > > > i am able to create user but when i try to authenticate it is 
> > > > > > 
> > > > > > ```
> > > > > > 
> > > > > > not validating even though we added the path. please suggest me if i am  
> > > > > > doing wrong here?
> > > > > > 
> > > > > > On Monday, March 16, 2015 at 10:12:00 PM UTC+5:30, Jay Modi wrote:
> > > > > > 
> > > > > > > Hi Phani,
> > > > > > > 
> > > > > > > How did you install elasticsearch and where is your elasticsearch  
> > > > > > > configuration located? If you have used a RPM or DEB package, you will need  
> > > > > > > to add an environment variable before running the esusers command, please  
> > > > > > > see  
> > > > > > > [Getting Started with Shield | Shield [2.4] | Elastic](http://www.elastic.co/guide/en/shield/current/getting-started.html)
> > > > > > > 
> > > > > > > On Monday, March 16, 2015 at 7:57:48 AM UTC-7,  
> > > > > > > [phani.n...@goktree.com](mailto:phani.n...@goktree.com) wrote:
> > > > > > > 
> > > > > > > > Hi All,
> > > > > > > > 
> > > > > > > > I am using elastic version 1.4.2 in development i installed  
> > > > > > > > elasticsearch shield on each node of my cluster i have 3 nodes in my  
> > > > > > > > cluster.
> > > > > > > > 
> > > > > > > > i followed the below procedure to install shield.
> > > > > > > > 
> > > > > > > > ```
> > > > > > > > *Step 1: Install* bin/plugin -i elasticsearch/license/latestbin/plugin 
> > > > > > > > 
> > > > > > > > ```
> > > > > > > > 
> > > > > > > > -i elasticsearch/shield/latest _Step 2: Start Elasticsearch_  
> > > > > > > > bin/elasticsearch _Step 3: Add an admin user_ bin/shield/esusers  
> > > > > > > > useradd es\_admin -r admin _Step 4: Try it out - secured_ curl  
> > > > > > > > -XGET '[http://localhost:9200/](http://localhost:9200/)' _Step 5: And with a user_ curl  
> > > > > > > > -u es\_admin -XGET '[http://localhost:9200](http://localhost:9200)
> > > > > > > > 
> > > > > > > > i added admin user by using above command but when i tried to get  
> > > > > > > > cluster health status form sense console it is asking password  
> > > > > > > > when i enter my admin password it is showing authentication failed  
> > > > > > > > exception from console. please suggest me what could be the issues am i  
> > > > > > > > doing wrong any where?
> > > > > > > > 
> > > > > > > > Thanks  
> > > > > > > > phani

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/122b9dc4-ac0a-4a1e-9c22-d3bbfa7bafe2%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/122b9dc4-ac0a-4a1e-9c22-d3bbfa7bafe2%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:24am UTC](https://discuss.elastic.co/t/elasticsearch-shield-relam-problem/22688/10 "2017-07-06T00:24:23Z")

</div>


