# Is LDAP connectivity open forever? How to close connection to LDAP server after authentication is done?

**URL:** <https://discuss.elastic.co/t/is-ldap-connectivity-open-forever-how-to-close-connection-to-ldap-server-after-authentication-is-done/248338>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 11, 2020, 2:19pm UTC](https://discuss.elastic.co/t/is-ldap-connectivity-open-forever-how-to-close-connection-to-ldap-server-after-authentication-is-done/248338 "2020-09-11T14:19:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![adarsh.venugopal](https://avatars.discourse-cdn.com/v4/letter/a/c68b51/32.png) [@adarsh.venugopal](https://discuss.elastic.co/u/adarsh.venugopal)\
**Post date:** [September 11, 2020, 2:19pm UTC](https://discuss.elastic.co/t/is-ldap-connectivity-open-forever-how-to-close-connection-to-ldap-server-after-authentication-is-done/248338/1 "2020-09-11T14:19:13Z")

</div>

We are expecting that the LDAP connection closes after the authentication search but it is not happening.

This is what we would want to see in the logs:-

```auto
    [logs]$grep conn=1138167 access

    CONNECT conn=1138167 from=XXXXXXXXX to=XXXXXXXXX:XXXX protocol=LDAPS
    BIND REQ conn=1138167 op=0 msgID=1 type=SIMPLE dn="cn=XXXXXX,ou=users,o=XXXXXXXXX" version=3
    BIND RES conn=1138167 op=0 msgID=1 result=0 authDN="cn=XXXXXX,ou=users,o=XXXXXXXX" etime=1
    **DISCONNECT conn=1138167 reason="** Client Disconnect **"**

```

This is the config that we are using for LDAP connectivity -

```auto
    xpack:
      security:
        authc:
          realms:
            ldap:
              ldap1:
                bind_dn: cn=XXXXXXX,ou=XXX,ou=apps,o=XXXXXXXXXXXXXXX
                group_search:
                  base_dn: ou=XXX,ou=apps,o=XXXXXXXXXXXXXXX
                  filter: uniqueMember={0}
                order: 0
                ssl:
                  certificate_authorities:
                  - /etc/elasticsearcarch/ELK-LDAP.pem
                unmapped_groups_as_roles: false
                url: ldaps://XXXXXXXXXXXXXXXXXXX
                user_search:
                  base_dn: ou=users,o=XXXXXXXXXXXXXXX
                  filter: (&(objectclass=scbperson)(|((ismemberof=cn=XXXXXXXX,ou=XXX,ou=apps,o=XXXXXXXXXXXXXXX))(cn={0}))
            native:
              realm1:
                order: 1 

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2020, 2:19pm UTC](https://discuss.elastic.co/t/is-ldap-connectivity-open-forever-how-to-close-connection-to-ldap-server-after-authentication-is-done/248338/2 "2020-10-09T14:19:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
