# ES Blog: User Impersonation with X-Pack

**URL:** <https://discuss.elastic.co/t/es-blog-user-impersonation-with-x-pack/77573>\
**Category:** Elasticsearch\
**Created:** [March 6, 2017, 8:32pm UTC](https://discuss.elastic.co/t/es-blog-user-impersonation-with-x-pack/77573 "2017-03-06T20:32:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [March 6, 2017, 8:32pm UTC](https://discuss.elastic.co/t/es-blog-user-impersonation-with-x-pack/77573/1 "2017-03-06T20:32:54Z")

</div>

Hi All,

I read recently a very good [article](https://www.elastic.co/blog/user-impersonation-with-x-pack-integrating-third-party-auth-with-kibana) regarding integration of the ES with 3rd party auth, and I'd like to discuss with the community the following point:  
the author has created an internal ES "fake" account (user1) for the "real" user's account "user1":

```
curl -u elastic:changeme -XPOST "http://localhost:9200/_xpack/security/user/user1" -H 'Content-Type: application/json' -d'
{
 "password" : "B&J$v,&%2SV*g9Xv", 
 "roles" : ["kibana_user", "shakespeare_bank_read"], 
 "full_name" : "My Test User 1"
}'

```

and granted the technical role `nginx` permission to impersonate that user:

```
curl -u elastic:changeme -XPOST "http://localhost:9200/_xpack/security/role/nginx" -H 'Content-Type: application/json' -d'
{ 
 "run_as": ["user1"]
}'

```

That means, if we're going to use an LDAP (AD) server of an enterprise with, let's say, 200.000 users, we'd have to create an internal ES user for every "real" account? And, if wildcards are not allowed, the second query above, would contain a huge `run_as` list with these 200k accounts? (to say nothing of maintaining/synchronizing the external and internal user names).

So, do I get it right, that this kind of architecture

![architecture](https://www.elastic.co/assets/blt602fa6d6881c5455/image02.png)

would make sense for systems with a "manageable" amount of users?  
Thanks!

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [March 6, 2017, 9:47pm UTC](https://discuss.elastic.co/t/es-blog-user-impersonation-with-x-pack/77573/3 "2017-03-06T21:47:11Z")

</div>

Hi there - Robbie did a great job with that blog - glad you liked it! I see at least two specific questions, and I think we have reasonable answers for both.

First, when assigning `run_as` privileges to a user, you can use wildcards. The docs don't seem to make that clear, and we can improve that.

Second, you can use run-as with the LDAP realm, as long as you've configured a bind user, which is a service user that can access the LDAP server to look up the user and properties. We document this here: [https://www.elastic.co/guide/en/x-pack/current/ldap-realm.html#ldap-user-search](https://www.elastic.co/guide/en/x-pack/current/ldap-realm.html#ldap-user-search)

Hope that helps!  
Steve

---

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [March 7, 2017, 7:35am UTC](https://discuss.elastic.co/t/es-blog-user-impersonation-with-x-pack/77573/4 "2017-03-07T07:35:56Z")

</div>

hi Steve,

yes, the article is very interesting, as it gave me a hope, that it could be possible to integrate an external auth gateway with ES cluster **without** having to develop a custom realm.

thank you for the pointing to the non-native realms, how could I only forget about it?! 🙂  
Regarding the LDAP realm - I still don't have a clear picture, how it could work:  
the LDAP technical user (bind\_dn/bind\_password) will be used to look up user- and group-information. But for the authentication of a particular user in ES:

> Once found, the user will be authenticated by attempting to bind to the LDAP server using the found DN and the provided password

And we don't have the "provided password", as the user has been already authenticated on the previous stage (oauth\_proxy or some other SSO gateway) - only user-name is available.

It'd great if you could clarify that point as well!  
Thanks a lot!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2017, 7:36am UTC](https://discuss.elastic.co/t/es-blog-user-impersonation-with-x-pack/77573/5 "2017-04-04T07:36:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
