# ES with shield LDAP can't use LDAP group but can login with LDAP user

**URL:** <https://discuss.elastic.co/t/es-with-shield-ldap-cant-use-ldap-group-but-can-login-with-ldap-user/54013>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 27, 2016, 8:48am UTC](https://discuss.elastic.co/t/es-with-shield-ldap-cant-use-ldap-group-but-can-login-with-ldap-user/54013 "2016-06-27T08:48:22Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![tingking23](https://avatars.discourse-cdn.com/v4/letter/t/e68b1a/32.png) [@tingking23](https://discuss.elastic.co/u/tingking23)\
**Post date:** [June 27, 2016, 8:48am UTC](https://discuss.elastic.co/t/es-with-shield-ldap-cant-use-ldap-group-but-can-login-with-ldap-user/54013/1 "2016-06-27T08:48:22Z")

</div>

AS the topic name , i can't use LDAP group just can use LDAP user.  
this is my role\_mapping.yml:

admin:  
- "cn=aaa,ou=groups,dc=company,dc=company"  
- "cn=bbb,ou=people,dc=company,dc=company"

this is the elasticsearch.yml:  
shield:  
authc:  
realms:  
ldap1:  
type: ldap  
order: 0  
url: "ldap://ldap.company.com:389"  
bind\_dn: "cn=admin,dc=company,dc=company"  
bind\_password: changeme  
user\_search:  
base\_dn: "dc=company,dc=company"  
attribute: cn  
group\_search:  
base\_dn: "dc=company,dc=company"  
files:  
role\_mapping: "/elasticsearch/config/shield/role\_mapping.yml"  
unmapped\_groups\_as\_roles: false

there is the logs: [warn] [shield.authc.ldap] [node1] authentication failed for user [admin] : failed LDAP authentication foe DN ["cn=admin,dc=company,dc=company"] cause: com.unboundid.ldap.sdk.LDAPException: invalid crentials

i can use bbb to login ES ,but can't use user of aaa group to login ES. anyone can help?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 27, 2016, 12:20pm UTC](https://discuss.elastic.co/t/es-with-shield-ldap-cant-use-ldap-group-but-can-login-with-ldap-user/54013/2 "2016-06-27T12:20:46Z")

</div>

Can you provide more of the logs around that exception including the stacktrace? Also, it appears as though either the bind\_dn or bind\_password is incorrect; the bind is failing for the user that is supposed to be doing the search. I'm not sure how any user is able to authenticate if that is the only realm you have defined.

---

<div class="post-metadata">

**Author:** ![tingking23](https://avatars.discourse-cdn.com/v4/letter/t/e68b1a/32.png) [@tingking23](https://discuss.elastic.co/u/tingking23)\
**Post date:** [June 28, 2016, 1:17am UTC](https://discuss.elastic.co/t/es-with-shield-ldap-cant-use-ldap-group-but-can-login-with-ldap-user/54013/3 "2016-06-28T01:17:42Z")

</div>

there is no more logs for error or warn,what you mean stacktrace log is the indices-access.log? i add the shield.authc: TRACE in logging.yml but nothing happend. the aaa is admin for my LDAPserver,it is correct i am sure. i can use any LDAP user that i mappinged in the role\_mapping.yml but the group. that means my companny has 100 people i must to add them all  
to the role\_mapping.yml,i think that's not a good way.  
should i must to import the certificate of my ldap server into the truststore or keystore? i don't do this because we don't need that , our internet just local area network

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 28, 2016, 11:29am UTC](https://discuss.elastic.co/t/es-with-shield-ldap-cant-use-ldap-group-but-can-login-with-ldap-user/54013/4 "2016-06-28T11:29:42Z")

</div>

Can you share your logging.yml? There should be other log messages and a stacktrace in the normal elasticsearch log file (not the access log).

> [@tingking23](#):
>
> to the role\_mapping.yml,i think that's not a good way.

That's not what I am saying. We need to figure out why the group is not mapping, most likely because it is not being returned.

> [@tingking23](#):
>
> should i must to import the certificate of my ldap server into the truststore or keystore? i don't do this because we don't need that , our internet just local area network

Yes you must. The certificate must be trusted otherwise connections will not work.

---

<div class="post-metadata">

**Author:** ![Yasho](https://avatars.discourse-cdn.com/v4/letter/y/c2a13f/32.png) [@Yasho](https://discuss.elastic.co/u/Yasho)\
**Post date:** [September 27, 2016, 8:23am UTC](https://discuss.elastic.co/t/es-with-shield-ldap-cant-use-ldap-group-but-can-login-with-ldap-user/54013/5 "2016-09-27T08:23:29Z")

</div>

@tingking23 @jaymode

Did you reslove this issue? At this moment i am facing the exact same issue, I can authenticate for individual user however not for the the group a user belongs to.

I have not done any sort of configuration with respect to securing the communication between shield & ldap server as i am testing things out i am looking to do this later.

Do let me know if because i did not secure the communication that the group information is not found for the user?

Here is my config -  
shield:  
authc:  
realms:  
ldap1:  
type: ldap  
order: 0  
url: "ldap://192.168.x.xxx:389"  
bind\_dn: "cn=admin,dc=xxxxxx,dc=com"  
bind\_password: xxxxx  
user\_search:  
base\_dn: "dc=xxxxxx,dc=com"  
group\_search:  
base\_dn: "dc=xxxxxx,dc=com"  
files:  
role\_mapping: "/etc/elasticsearch/shield/role\_mapping.yml"  
unmapped\_groups\_as\_roles: false

Here is my log from trace -

[2016-09-27 13:58:04,856][INFO][gateway] [node-1] recovered [26] indices into cluster\_state  
[2016-09-27 13:58:09,598][INFO][watcher] [node-1] starting watch service...  
[2016-09-27 13:58:09,746][INFO][watcher] [node-1] watch service has started  
[2016-09-27 13:58:09,786][INFO][cluster.routing.allocation] [node-1] Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[logstash-2016.09.06][1], [logstash-2016.09.06][3]] ...]).  
[2016-09-27 13:58:33,666][TRACE][shield.authc.esnative] [node-1] cannot poll for user changes since security index [.security] does not exist  
[2016-09-27 13:58:40,484][DEBUG][shield.authc.ldap] [node-1] user not found in cache, proceeding with normal authentication  
[2016-09-27 13:58:40,500][DEBUG][shield.authc.support] [node-1] the roles [[]], are mapped from these [ldap] groups [[]] for realm [ldap/ldap1]  
[2016-09-27 13:58:40,501][DEBUG][shield.authc.support] [node-1] the roles [[]], are mapped from the user [ldap] for realm [cn=Yashodhara Mandepu,ou=users,dc=xxxxxx,dc=com/ldap]  
[2016-09-27 13:58:40,504][DEBUG][shield.authc.ldap] [node-1] authenticated user [ymandepu], with roles [[]]  
[2016-09-27 13:59:03,666][TRACE][shield.authc.esnative] [node-1] cannot poll for user changes since security index [.security] does not exist  
[2016-09-27 13:59:33,667][TRACE][shield.authc.esnative] [node-1] cannot poll for user changes since security index [.security] does not exist

Please let me know.

Thanks

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [September 27, 2016, 1:48pm UTC](https://discuss.elastic.co/t/es-with-shield-ldap-cant-use-ldap-group-but-can-login-with-ldap-user/54013/6 "2016-09-27T13:48:27Z")

</div>

You probably have a different LDAP schema. Wild guess, but maybe try:

```
shield:
    authc:
        realms:
            ldap1:
               ...
            group_search:
               base_dn: "dc=xxxxxx,dc=com"
               filter: "(&(objectclass=posixGroup)(memberUID={0}))"
               user_attribute: "uid"
```

---

<div class="post-metadata">

**Author:** ![Yasho](https://avatars.discourse-cdn.com/v4/letter/y/c2a13f/32.png) [@Yasho](https://discuss.elastic.co/u/Yasho)\
**Post date:** [September 27, 2016, 1:52pm UTC](https://discuss.elastic.co/t/es-with-shield-ldap-cant-use-ldap-group-but-can-login-with-ldap-user/54013/7 "2016-09-27T13:52:22Z")

</div>

@jaymode

Yes Jay, that is the answer, it has worked.

one has to make sure the letter case is correct, in my case "memberUID" is "memberUid"

Thank you so much for the reply.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:41pm UTC](https://discuss.elastic.co/t/es-with-shield-ldap-cant-use-ldap-group-but-can-login-with-ldap-user/54013/8 "2017-07-06T13:41:47Z")

</div>


