# Ldap Authentication not working for multiple groups

**URL:** <https://discuss.elastic.co/t/ldap-authentication-not-working-for-multiple-groups/141105>\
**Category:** Elasticsearch\
**Created:** [July 23, 2018, 8:14am UTC](https://discuss.elastic.co/t/ldap-authentication-not-working-for-multiple-groups/141105 "2018-07-23T08:14:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rohit02bits](https://avatars.discourse-cdn.com/v4/letter/r/8edcca/32.png) [@rohit02bits](https://discuss.elastic.co/u/rohit02bits)\
**Post date:** [July 23, 2018, 8:14am UTC](https://discuss.elastic.co/t/ldap-authentication-not-working-for-multiple-groups/141105/1 "2018-07-23T08:14:18Z")

</div>

I am using the following property  
xpack:  
security:  
authc:  
realms:  
ldap1:  
type: ldap  
order: 1  
url: "ldaps://abc.example.com:1111"  
ssl.verification\_mode: none  
user\_dn\_templates:  
- "CN={0}, OU=xx, DC=xx, DC=xx, DC=xx"  
group\_search.base\_dn: "CN=group1,DC=xx, DC=xx, DC=xx"  
files:  
role\_mapping: "config/role\_mapping.yml"  
#unmapped\_groups\_as\_roles: false  
ldap2:  
type: ldap  
order: 0  
url: "ldaps://abc.example.com:1111"  
ssl.verification\_mode: none  
user\_dn\_templates:  
- "CN={0}, OU=xx, DC=xx, DC=xx, DC=xx"  
group\_search.base\_dn: "CN=group2,DC=xx, DC=xx, DC=xx"  
files:  
role\_mapping: "config/role\_mapping.yml"  
unmapped\_groups\_as\_roles: false

The user gets validated only by the group which is set as order 0. If the user belongs to order 1 then the authentication goes through but the user role is not getting assigned

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 23, 2018, 8:41am UTC](https://discuss.elastic.co/t/ldap-authentication-not-working-for-multiple-groups/141105/2 "2018-07-23T08:41:53Z")

</div>

Can you please format your config as a code block (the `</>` button, or surround the block with "```")

Yaml is whitespace sensitive, so it's impossible for us to reliably validate your configuration if the spacing has been stripped.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 23, 2018, 8:47am UTC](https://discuss.elastic.co/t/ldap-authentication-not-working-for-multiple-groups/141105/3 "2018-07-23T08:47:17Z")

</div>

The behaviour you are seeing is totally expected.

The realms are tried in order, and authentication is complete when one realm succeeds.  
From [the docs](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/realms.html)

> During the authentication process, X-Pack security will consult and try to authenticate the request one realm at a time. Once one of the realms successfully authenticates the request, the authentication is considered to be successful and the authenticated user will be associated with the request (which will then proceed to the authorization phase). If a realm cannot authenticate the request, the next in line realm in the chain will be consulted.

Since your 2 realms are using the same authentication source (same LDAP server, with the same DN templates), it is not possible for one of them to fail and the other succeed.

It seems like you are simply trying to match multiple groups, but you do not do that by having multiple realms, you simply need to configure a single realm, to retrieve all groups for the user.

You probably want to do something like:

```auto
    group_search.base_dn: "DC=xx, DC=xx, DC=xx"

```

---

<div class="post-metadata">

**Author:** ![rohit02bits](https://avatars.discourse-cdn.com/v4/letter/r/8edcca/32.png) [@rohit02bits](https://discuss.elastic.co/u/rohit02bits)\
**Post date:** [July 24, 2018, 4:19am UTC](https://discuss.elastic.co/t/ldap-authentication-not-working-for-multiple-groups/141105/4 "2018-07-24T04:19:10Z")

</div>

Thanks for the update, it worked. That was a silly mistake 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2018, 4:19am UTC](https://discuss.elastic.co/t/ldap-authentication-not-working-for-multiple-groups/141105/5 "2018-08-21T04:19:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
