# LDAP Authentication Case Sensitive

**URL:** <https://discuss.elastic.co/t/ldap-authentication-case-sensitive/305224>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 19, 2022, 6:48pm UTC](https://discuss.elastic.co/t/ldap-authentication-case-sensitive/305224 "2022-05-19T18:48:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [May 19, 2022, 6:48pm UTC](https://discuss.elastic.co/t/ldap-authentication-case-sensitive/305224/1 "2022-05-19T18:48:41Z")

</div>

I've recently enabled LDAP authentication and used the Kibana GUI to configure role mappings. Unfortunately, it appears usernames are case sensitive. So if I enter a role mapping for user `example123`, and the user enters `Example123`, login fails. Is there any way to remove case sensitivity?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 20, 2022, 4:32am UTC](https://discuss.elastic.co/t/ldap-authentication-case-sensitive/305224/2 "2022-05-20T04:32:27Z")

</div>

There is not, though we have some ideas about how to solve it

- [Username letter case for role mapping · Issue #48120 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/issues/48120)

Strictly speaking in LDAP it's not guaranteed that `example123` and `Example123` are the same user (some LDAP attributes are case sensitive but others are not). For safety we assume they're a different user, but would like to make that configurable.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [May 20, 2022, 6:50am UTC](https://discuss.elastic.co/t/ldap-authentication-case-sensitive/305224/3 "2022-05-20T06:50:35Z")

</div>

> [@TimV](#):
>
> Strictly speaking in LDAP it's not guaranteed that `example123` and `Example123` are the same user

Not sure about LDAP as a protocol, and I know that Active Directory uses it, but Active Directory is case insensitive when it comes to `sAMAccountName` and `UserPrincipalName`. It seems like if someone is implementing an AD realm, then Elasticsearch should ignore case.

Alternatively, could it not be adjusted to be something like below?

1. LDAP search for user
2. If only one result, ignore case
3. If multiple results, adhere to case as entered by the administrator
4. If no match on case, fail authentication and log failure as multiple users, no case match

I'm by no means a developer, so there may be some (a lot) of ignorance on my part.

I DID notice that case was ignored when mapping to user groups and then tested and verified that case was also ignored if I matched on `dn`. That's fine, just gotta hope nobody moves user accounts around.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2022, 6:51am UTC](https://discuss.elastic.co/t/ldap-authentication-case-sensitive/305224/4 "2022-06-17T06:51:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
