# How to grant superuser permission to ladp user

**URL:** https://discuss.elastic.co/t/how-to-grant-superuser-permission-to-ladp-user/78443
**Category:** Elasticsearch
**Created:** [March 14, 2017, 5:16am UTC](https://discuss.elastic.co/t/how-to-grant-superuser-permission-to-ladp-user/78443 "2017-03-14T05:16:09Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Bhavik\_Shah](https://avatars.discourse-cdn.com/v4/letter/b/ecb155/32.png) [@Bhavik\_Shah](https://discuss.elastic.co/u/Bhavik_Shah)
#### Post date: [March 14, 2017, 5:16am UTC](https://discuss.elastic.co/t/how-to-grant-superuser-permission-to-ladp-user/78443/1 "2017-03-14T05:16:09Z")

</div>

Hello,  
I installed x-pack plugin to elasticsearch as well as kibana. I setup ldap realm for authentication purpose. The ldap user is able to login to kibana but unable to perform any other activity such as clicking on Management or Dev tools only show white page and clicking on Monitoring show access\_denied message.

I have following in my role\_mapping.yml  
superuser:

- "cn=Shah, Bhavik,ou=XXX,ou=yyy,ou=01\_Users,dc=zzz,dc=bbb,dc=com"
- "cn=test-admins,ou=ccc,ou=XXX,ou=ccc,dc=zzz,dc=bbb,dc=com"  
still I am not able to use the api or kibana to manage the cluster

---

<div class="post-metadata">

### Author: ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)
#### Post date: [March 14, 2017, 3:36pm UTC](https://discuss.elastic.co/t/how-to-grant-superuser-permission-to-ladp-user/78443/2 "2017-03-14T15:36:33Z")

</div>

The most likely cause is the role is not being mapped. When escaping a value, I believe you need to use single quotes in the role mapping. You can try changing that and see if it works. Also, I suggest you use the [authenticate API](https://www.elastic.co/guide/en/x-pack/current/security-api-authenticate.html) so that you can see what roles the user has.

If that doesn't work then you will need to[troubleshoot what is being returned by LDAP.](https://www.elastic.co/guide/en/x-pack/current/security-troubleshooting.html#_ldap)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 11, 2017, 3:36pm UTC](https://discuss.elastic.co/t/how-to-grant-superuser-permission-to-ladp-user/78443/3 "2017-04-11T15:36:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
