# Is it possible to connect to different ldap realm?

**URL:** <https://discuss.elastic.co/t/is-it-possible-to-connect-to-different-ldap-realm/232361>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 13, 2020, 5:21am UTC](https://discuss.elastic.co/t/is-it-possible-to-connect-to-different-ldap-realm/232361 "2020-05-13T05:21:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [May 13, 2020, 5:21am UTC](https://discuss.elastic.co/t/is-it-possible-to-connect-to-different-ldap-realm/232361/1 "2020-05-13T05:21:59Z")

</div>

Hey there,  
Can I map 2, or more, different ldap realms? i.e. from 2 different domains?  
So user 1 can access with user@domain **1**.com and user 2 can access with user@domain **2**.com  
I did not see any limitations around this issue. But, the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/security-settings.html#ref-ldap-settings) does not say explicitly that it is allowed.  
The configuration will be something like

```auto
xpack.security.authc.realms:

    ldap.realm1: 
        order: 0
        ...

    ldap.realm2:
        order: 1
        ...

    ldap.realm3:
        order: 2

```

Thank you!

---

<div class="post-metadata">

**Author:** ![KoettingSimon](https://avatars.discourse-cdn.com/v4/letter/k/ba9def/32.png) [@KoettingSimon](https://discuss.elastic.co/u/KoettingSimon)\
**Post date:** [May 13, 2020, 5:46am UTC](https://discuss.elastic.co/t/is-it-possible-to-connect-to-different-ldap-realm/232361/2 "2020-05-13T05:46:09Z")

</div>

Hi,  
Yes thats possible.  
In the Documentation about [realm-chains](https://www.elastic.co/guide/en/elasticsearch/reference/current/realm-chains.html) is also a example for a config with 2 ldap realm.

Regards,  
Simon

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [May 13, 2020, 5:54am UTC](https://discuss.elastic.co/t/is-it-possible-to-connect-to-different-ldap-realm/232361/3 "2020-05-13T05:54:28Z")

</div>

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 13, 2020, 6:19am UTC](https://discuss.elastic.co/t/is-it-possible-to-connect-to-different-ldap-realm/232361/4 "2020-05-13T06:19:55Z")

</div>

A few things to keep in mind:

- Realms are traversed in order so if a user that is in ldap realm attempts to authenticate, we will try realm 1 first and when that fails we will try realm 2 and when that fails we will try realm 3.
- The above happens only the first time, we subsequently cache both the authentication and the realm that last authenticated that user and will attempt to use that first so next authentications will be fast(er).
- The above might or might not be problematic for you depending on how many different realms you want to add. 2,3 are fine, 30 might not be 🙂

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [May 13, 2020, 6:33am UTC](https://discuss.elastic.co/t/is-it-possible-to-connect-to-different-ldap-realm/232361/5 "2020-05-13T06:33:28Z")

</div>

Thanks for the info @ikakavas  
Do you have any guidance around this topic? Best practices? Performance testing you have done?  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2020, 6:37am UTC](https://discuss.elastic.co/t/is-it-possible-to-connect-to-different-ldap-realm/232361/6 "2020-06-10T06:37:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
