# Issue Authenticating with Active Directory

**URL:** <https://discuss.elastic.co/t/issue-authenticating-with-active-directory/58481>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 19, 2016, 5:54pm UTC](https://discuss.elastic.co/t/issue-authenticating-with-active-directory/58481 "2016-08-19T17:54:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![nate.fleming](https://avatars.discourse-cdn.com/v4/letter/n/e495f1/32.png) [@nate.fleming](https://discuss.elastic.co/u/nate.fleming)\
**Post date:** [August 19, 2016, 5:54pm UTC](https://discuss.elastic.co/t/issue-authenticating-with-active-directory/58481/1 "2016-08-19T17:54:17Z")

</div>

I am working on configuring Shield for authentication and authorization and have run into some issues with the Active Directory integration. I have used ldapsearch as well as my own Java application which can authenticate with AD but it appears as though ES is not able to a authenticate using similar parameters. I had one of the AD admins sit with me and we noticed that my java application logs invalid logins when providing invalid credentials, however, although the ES logs show AD error codes that would indicate invalid credentials the request does not appear to be getting logged in the AD server logs. We also noticed that ldapsearch also wasn't logging invalid credentials but my app would (ldap search at least appeared to authenticate my user when providing a correct password) I have been testing the login using curl command as well as logging in through Kibana. There are some additional role configuration which I have added but I don't think I'm getting passed authentication.

elasticsearch.yaml

shield:  
authc:  
realms:  
active\_directory:  
type: active\_directory  
order: 0  
domain\_name: "the hostname"  
unmapped\_groups\_as\_roles: true  
native:  
type: native  
order: 1  
file:  
type: file  
order: 2

I have turned logging up on shield.authc to TRACE but I'm not getting much insight as to what is going on.

Example exception from the cluster log.

[2016-08-19 13:45:00,148][DEBUG][shield.authc.activedirectory] [iot-prod-1] authentication failed for user [n325138@doit.state.in.us]  
ElasticsearchSecurityException[unable to authenticate user [n325138@hostname] to active directory domain [[gc.iot.in.gov](http://gc.iot.in.gov)]]; nested: LDAPException[80090308: LdapErr: DSID-0C0903D0, comment: AcceptSecurityContext error, data 52e, v2580^@];  
at org.elasticsearch.shield.support.Exceptions.authenticationError(Exceptions.java:33)

$\> elasticsearch --version  
Version: 2.3.4, Build: e455fd0/2016-06-30T11:24:31Z, JVM: 1.8.0\_91

Shield Version  
{  
"status" : "enabled",  
"name" : "iot-prod-1",  
"cluster\_name" : "iot-prod",  
"version" : {  
"number" : "2.3.4",  
"build\_hash" : "bd3199a84c10bda200ad31b1f72d1587738d77a1",  
"build\_timestamp" : "2016-07-05T12:39:55Z",  
"build\_snapshot" : false  
},  
"tagline" : "You Know, for Security"  
}

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [August 22, 2016, 11:04am UTC](https://discuss.elastic.co/t/issue-authenticating-with-active-directory/58481/2 "2016-08-22T11:04:10Z")

</div>

Hi Nate,

The exception indicates an authentication failure when a bind is attempted. Do you have multiple domains or are you just trying to authenticate against a single domain?

Jay

---

<div class="post-metadata">

**Author:** ![nate.fleming](https://avatars.discourse-cdn.com/v4/letter/n/e495f1/32.png) [@nate.fleming](https://discuss.elastic.co/u/nate.fleming)\
**Post date:** [August 22, 2016, 2:40pm UTC](https://discuss.elastic.co/t/issue-authenticating-with-active-directory/58481/3 "2016-08-22T14:40:56Z")

</div>

Thanks for the response Jay. There are many domains and at the moment we are using the global catalog as the entry point. After some experimentation I found that if that change the shield domain\_name option to my specific domain than it will resolve using just my username. For example:

username@myhostname does not authenticate against the GC domain name  
username@myhostname does not authenticate against myhostname (specific domain name)  
username does not authenticate against the GC domain name  
username **DOES** authenticate against myhostname (specific domain name)

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [August 22, 2016, 2:57pm UTC](https://discuss.elastic.co/t/issue-authenticating-with-active-directory/58481/4 "2016-08-22T14:57:50Z")

</div>

That is a limitation of the active directory realm in Shield 2.3. Some workarounds would be to use multiple AD realms or to use a LDAP realm with a bind user that can search for the user in AD.

In X-Pack 5.0 (currently in alpha), we have [added support for multi domain authentication](https://www.elastic.co/guide/en/x-pack/current/active-directory-realm.html#_multiple_domain_support_phrase_revisionflag_added_revision_5_0_0_added_in_5_0_0_phrase) with a single realm.

---

<div class="post-metadata">

**Author:** ![nate.fleming](https://avatars.discourse-cdn.com/v4/letter/n/e495f1/32.png) [@nate.fleming](https://discuss.elastic.co/u/nate.fleming)\
**Post date:** [August 22, 2016, 6:52pm UTC](https://discuss.elastic.co/t/issue-authenticating-with-active-directory/58481/5 "2016-08-22T18:52:39Z")

</div>

Thanks Jay,  
We were able to get LDAP configured and working. What is the future role of xpack? Will it end up replacing Shield?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/issue-authenticating-with-active-directory/58481/6 "2017-07-06T13:42:15Z")

</div>


