# Ldap Authentication in elasticsearch and kibana

**URL:** <https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 6, 2019, 12:10pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884 "2019-12-06T12:10:03Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jhansi](https://avatars.discourse-cdn.com/v4/letter/j/7cd45c/32.png) [@Jhansi](https://discuss.elastic.co/u/Jhansi)\
**Post date:** [December 6, 2019, 12:10pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884/1 "2019-12-06T12:10:04Z")

</div>

I am trying to login the elastic and kibana by using ldap users.For ldap configuration I follows the below reference link  
[https://www.elastic.co/guide/en/elasticsearch/reference/7.4/ldap-realm.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/ldap-realm.html)

I configured the ldap realm settings in my elasticsearch.yml file and again run the elastic service and trying to login with ldap users in elastic and kibana.But I am not able to login with ldapusers it gave the error like invalid user and invalid user.

this is my elasticsearch.yml

```auto
# ======================== Elasticsearch Configuration =========================
#
# NOTE: Elasticsearch comes with reasonable defaults for most settings.
# Before you set out to tweak and tune the configuration, make sure you
# understand what are you trying to accomplish and the consequences.
#
# The primary way of configuring a node is via this file. This template lists
# the most important settings you may want to configure for a production cluster.
#
# Please consult the documentation for further information on configuration options:
# https://www.elastic.co/guide/en/elasticsearch/reference/index.html
#
# ---------------------------------- Cluster -----------------------------------
#
# Use a descriptive name for your cluster:
#
cluster.name: my-application
#
# ------------------------------------ Node ------------------------------------
#
# Use a descriptive name for the node:
#
node.name: node1
#
# Add custom attributes to the node:
#
#node.attr.rack: r1
#
# ----------------------------------- Paths ------------------------------------
#
# Path to directory where to store the data (separate multiple locations by comma):
#
#path.data: /var/lib/elasticsearch
#
# Path to log files:
#
path.logs: /var/log/elasticsearch
#
# ----------------------------------- Memory -----------------------------------
#
# Lock the memory on startup:
#
#bootstrap.memory_lock: true
#
# Make sure that the heap size is set to about half the memory available
# on the system and that the owner of the process is allowed to use this
# limit.
#
# Elasticsearch performs poorly when the system is swapping the memory.
#
# ---------------------------------- Network -----------------------------------
#
# Set the bind address to a specific IP (IPv4 or IPv6):
#
network.host: "192.168.3.96"
#
# Set a custom port for HTTP:
#
http.port: 9201
#
# For more information, consult the network module documentation.
#
# --------------------------------- Discovery ----------------------------------
#
# Pass an initial list of hosts to perform discovery when this node is started:
# The default list of hosts is ["127.0.0.1", "[::1]"]
#
discovery.seed_hosts: ["192.168.3.96"]
#
# Bootstrap the cluster using an initial set of master-eligible nodes:
#
cluster.initial_master_nodes: ["192.168.3.96"]
#
# For more information, consult the discovery and cluster formation module documentation.
#
# ---------------------------------- Gateway -----------------------------------
#
# Block initial recovery after a full cluster restart until N nodes are started:
#
#gateway.recover_after_nodes: 3
#
# For more information, consult the gateway module documentation.
#
# ---------------------------------- Various -----------------------------------
#
# Require explicit names when deleting indices:
#
#action.destructive_requires_name: true
xpack.ml.enabled: false
bootstrap.system_call_filter: false
node.max_local_storage_nodes: 10
xpack.license.self_generated.type: basic
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.key: /etc/elasticsearch-7.4.0/config/certs/node1/node1.key
xpack.security.http.ssl.certificate: /etc/elasticsearch-7.4.0/config/certs/node1/node1.crt
xpack.security.http.ssl.certificate_authorities: /etc/elasticsearch-7.4.0/config/certs/ca/ca.crt
xpack.security.transport.ssl.key: /etc/elasticsearch-7.4.0/config/certs/node1/node1.key
xpack.security.transport.ssl.certificate: /etc/elasticsearch-7.4.0/config/certs/node1/node1.crt
xpack.security.transport.ssl.certificate_authorities: /etc/elasticsearch-7.4.0/config/certs/ca/ca.crt
xpack.security.http.ssl.verification_mode: certificate
xpack.security.authc.token.enabled: true

xpack:
security:
    authc:
      realms:
        ldap:
          ldap1:
            order: 0
            url: "ldaps://ldaps.sfty.com:636"
            bind_dn: "cn=Manager,ou=people, dc=sfty, dc=com"
            user_search:
              base_dn: "dc=sfty,dc=com"
              filter: "(cn={0})"
            group_search:
              base_dn: "dc=sfty,dc=com"
            files:
              role_mapping: "/etc/elasticsearch-7.4.0/config/role_mapping.yml"
            unmapped_groups_as_roles: false

```

and i am getting the below error

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f58b40b9ade27960de8c867b368769118f0aef8c.png)  
`[2019-12-06T17:36:18,356][WARN][o.e.x.s.a.AuthenticationService] [node1] Authentication to realm ldap1 failed - authenticate failed (Caused by LDAPException(resultCode=91 (connect error), errorMessage='An error occurred while attempting to connect to server ldaps.sfty.com:636: IOException(LDAPException(resultCode=91 (connect error), errorMessage='An error occurred while attempting to establish a connection to server ldaps.sfty.com/192.168.3.96:636: ConnectException(Connection refused (Connection refused)), ldapSDKVersion=4.0.8, revision=28812'))')) `

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 6, 2019, 12:51pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884/2 "2019-12-06T12:51:08Z")

</div>

Please don't post unformatted code, logs, or configuration as it's very hard to read. Also please don't post images of text as they are hard to read, may not display correctly for everyone, and are not searchable.

Instead, paste the text and format it with \</\> icon or pairs of triple backticks (```), and check the preview window to make sure it's properly formatted before posting it. This makes it more likely that your question will receive a useful answer.

It would be great if you could update your post to solve this.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 6, 2019, 12:52pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884/3 "2019-12-06T12:52:54Z")

</div>

The error message is quite clear:

> [@Jhansi](#):
>
> An error occurred while attempting to establish a connection to server [ldaps.sfty.com/192.168.3.96:636](http://ldaps.sfty.com/192.168.3.96:636)

There is either no ldap server listening on port 636 on 192.168.3.96 or there is something ( a firewall probably ) blocking access to that server on that port.

---

<div class="post-metadata">

**Author:** ![Jhansi](https://avatars.discourse-cdn.com/v4/letter/j/7cd45c/32.png) [@Jhansi](https://discuss.elastic.co/u/Jhansi)\
**Post date:** [December 6, 2019, 12:54pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884/4 "2019-12-06T12:54:31Z")

</div>

error occured while trying to login kibana by using ldapusers

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 6, 2019, 1:33pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884/5 "2019-12-06T13:33:53Z")

</div>

> [@Jhansi](#):
>
> error occured while trying to login kibana by using ldapusers

Apologies, but I don't follow what that means or how it is related to the above.

---

<div class="post-metadata">

**Author:** ![Jhansi](https://avatars.discourse-cdn.com/v4/letter/j/7cd45c/32.png) [@Jhansi](https://discuss.elastic.co/u/Jhansi)\
**Post date:** [December 6, 2019, 2:26pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884/6 "2019-12-06T14:26:22Z")

</div>

Actually ,I am trying to authenticate elastic and kibana by using ldap authentication by setting ldap setting in elasticsearch.yml file.  
These are the kibana .yml file

server.ssl.enabled: true  
server.ssl.certificate: /etc/elasticsearch-7.4.0/config/certs/kibana/kibana.crt  
server.ssl.key: /etc/elasticsearch-7.4.0/config/certs/kibana/kibana.key  
elasticsearch.ssl.certificateAuthorities: ["/etc/elasticsearch-7.4.0/config/certs/ca/ca.crt"]

Is there anything to add in kibana.yml for ldap authentication.  
Pleaes help me how to slove it.

---

<div class="post-metadata">

**Author:** ![Jhansi](https://avatars.discourse-cdn.com/v4/letter/j/7cd45c/32.png) [@Jhansi](https://discuss.elastic.co/u/Jhansi)\
**Post date:** [December 6, 2019, 2:27pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884/7 "2019-12-06T14:27:43Z")

</div>

Already firewall service is stopped but still it showing same error.

Thank you for your quick reply.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 6, 2019, 2:32pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884/8 "2019-12-06T14:32:17Z")

</div>

As I said above the problem is

> [@ikakavas](#):
>
> There is either no ldap server listening on port 636 on 192.168.3.96 or there is something ( a firewall probably ) blocking access to that server on that port.

Unfortunately we can't help you with network misconfigurations on your machines. This doesn't seem to be at all related to any component of the Elastic Stack, but rather on your local setup. Please verify or seek the help of someone in the network team of your organization to help you verify that:

- LDAP server is up and running
- LDAP server is running on the machine with IP address 192.168.3.96
- LDAP server is listening on port 636
- There is network connectivity between the machine where elasticsearch runs and the machine that your LDAP server runs
- No firewall is blocking the port on that IP address.

---

<div class="post-metadata">

**Author:** ![Jhansi](https://avatars.discourse-cdn.com/v4/letter/j/7cd45c/32.png) [@Jhansi](https://discuss.elastic.co/u/Jhansi)\
**Post date:** [December 6, 2019, 2:35pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884/9 "2019-12-06T14:35:35Z")

</div>

Ok I will check with them.  
Thank you very much for information

---

<div class="post-metadata">

**Author:** ![Jhansi](https://avatars.discourse-cdn.com/v4/letter/j/7cd45c/32.png) [@Jhansi](https://discuss.elastic.co/u/Jhansi)\
**Post date:** [December 6, 2019, 2:44pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884/10 "2019-12-06T14:44:04Z")

</div>

Hey ,i am really sorry I posted wrong link  
[https://www.elastic.co/guide/en/elasticsearch/reference/7.x/ldap-realm.html#ldap-realm-configuration](https://www.elastic.co/guide/en/elasticsearch/reference/7.x/ldap-realm.html#ldap-realm-configuration)  
the above one is the correct link

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2020, 2:44pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884/11 "2020-01-03T14:44:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
