# Hard code metadata values in ldap realm configuration

**URL:** <https://discuss.elastic.co/t/hard-code-metadata-values-in-ldap-realm-configuration/119678>\
**Category:** Elasticsearch\
**Created:** [February 13, 2018, 4:44pm UTC](https://discuss.elastic.co/t/hard-code-metadata-values-in-ldap-realm-configuration/119678 "2018-02-13T16:44:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jchannon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jchannon/32/23280_2.png) [@jchannon](https://discuss.elastic.co/u/jchannon)\
**Post date:** [February 13, 2018, 4:44pm UTC](https://discuss.elastic.co/t/hard-code-metadata-values-in-ldap-realm-configuration/119678/1 "2018-02-13T16:44:19Z")

</div>

In the LDAP realm configuration you can set the `metadata` value to be an ldap attribute that the realm uses to populate the user's metadata property. Is there a way to hardcode a value for metadata for example if I didn't want the realm to find a attribute on the ldap server but use a hardcoded value of "foo" as user metadata, is that possible?

Thanks

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 14, 2018, 2:13am UTC](https://discuss.elastic.co/t/hard-code-metadata-values-in-ldap-realm-configuration/119678/2 "2018-02-14T02:13:28Z")

</div>

> [@jchannon](#):
>
> is that possible

No. Why do you want it?

---

<div class="post-metadata">

**Author:** ![jchannon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jchannon/32/23280_2.png) [@jchannon](https://discuss.elastic.co/u/jchannon)\
**Post date:** [February 14, 2018, 11:13am UTC](https://discuss.elastic.co/t/hard-code-metadata-values-in-ldap-realm-configuration/119678/3 "2018-02-14T11:13:20Z")

</div>

Because we can't ask customers to change their ldap schema we were thinking that we setup multiple ldap realms with different filters to import different types of users. If we know they are different types of users we could hardcode the metadata field to something relevant for that type of user

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 14, 2018, 12:26pm UTC](https://discuss.elastic.co/t/hard-code-metadata-values-in-ldap-realm-configuration/119678/4 "2018-02-14T12:26:20Z")

</div>

What are you going to use that metadata for?  
If it's for role mapping, then you might be able to use the realm name instead.  
That wouldn't work for DLS templates though.

---

<div class="post-metadata">

**Author:** ![jchannon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jchannon/32/23280_2.png) [@jchannon](https://discuss.elastic.co/u/jchannon)\
**Post date:** [February 14, 2018, 12:31pm UTC](https://discuss.elastic.co/t/hard-code-metadata-values-in-ldap-realm-configuration/119678/5 "2018-02-14T12:31:05Z")

</div>

We want to use it to do document level security and a role that contains a query to match a user's metadata to a field on the document - eg - [https://www.elastic.co/blog/attribute-based-access-control-with-xpack](https://www.elastic.co/blog/attribute-based-access-control-with-xpack)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2018, 12:31pm UTC](https://discuss.elastic.co/t/hard-code-metadata-values-in-ldap-realm-configuration/119678/6 "2018-03-14T12:31:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
