# Escape character in LDAP DN?

**URL:** <https://discuss.elastic.co/t/escape-character-in-ldap-dn/24124>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 22, 2015, 8:00pm UTC](https://discuss.elastic.co/t/escape-character-in-ldap-dn/24124 "2015-06-22T20:00:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![slee](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@slee](https://discuss.elastic.co/u/slee)\
**Post date:** [June 22, 2015, 8:00pm UTC](https://discuss.elastic.co/t/escape-character-in-ldap-dn/24124/1 "2015-06-22T20:00:53Z")

</div>

Hello,  
The way our organization organizes the Users in AD causes there to be a , inbetween the last name and the first in the DN. Because of this, when I try to add a user to the role\_mapping.yml file, I get an error that says :

```
Caused by: while scanning a double-quoted scalar
 in 'reader', line 20, column 6:
       - "CN=Last\, First 1231412,OU= ...
         ^
found unknown escape character ,(44)
 in 'reader', line 20, column 15:
       - "CN=Last\, First 1231412,OU=HQ,...

```

Is there a way to escape that comma? Otherwise, it looks for the next level in the AD structure and errors out

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 23, 2015, 12:56pm UTC](https://discuss.elastic.co/t/escape-character-in-ldap-dn/24124/2 "2015-06-23T12:56:10Z")

</div>

Hi @slee,

Can you try to escape the `,` with `\\`? So in your example it would be something like: `"CN=Last\\, First 1231412,OU= ..."`

Please let me know if that resolves the issue with parsing and mapping.

-Jay

---

<div class="post-metadata">

**Author:** ![slee](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@slee](https://discuss.elastic.co/u/slee)\
**Post date:** [June 23, 2015, 4:35pm UTC](https://discuss.elastic.co/t/escape-character-in-ldap-dn/24124/3 "2015-06-23T16:35:21Z")

</div>

Thanks that worked! Is that a standard?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 23, 2015, 8:20pm UTC](https://discuss.elastic.co/t/escape-character-in-ldap-dn/24124/4 "2015-06-23T20:20:54Z")

</div>

The YAML parser interprets a character preceded by a `\` as being an escape sequence. In this case, we want the literal, so the `\` must be escaped by using `\\`.

---

<div class="post-metadata">

**Author:** ![slee](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@slee](https://discuss.elastic.co/u/slee)\
**Post date:** [June 23, 2015, 8:22pm UTC](https://discuss.elastic.co/t/escape-character-in-ldap-dn/24124/5 "2015-06-23T20:22:19Z")

</div>

Ah, so the YAML is escaping the LDAP escape. Gotcha. You and the others have been a great help and resource on this forum, thank you so much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:49pm UTC](https://discuss.elastic.co/t/escape-character-in-ldap-dn/24124/6 "2017-07-06T13:49:06Z")

</div>


