# LDAP Authorization issue X-PACK

**URL:** https://discuss.elastic.co/t/ldap-authorization-issue-x-pack/94997
**Category:** Elasticsearch
**Created:** [July 28, 2017, 6:04pm UTC](https://discuss.elastic.co/t/ldap-authorization-issue-x-pack/94997 "2017-07-28T18:04:36Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![aswinkumart](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@aswinkumart](https://discuss.elastic.co/u/aswinkumart)
#### Post date: [July 28, 2017, 6:04pm UTC](https://discuss.elastic.co/t/ldap-authorization-issue-x-pack/94997/1 "2017-07-28T18:04:36Z")

</div>

Hello,  
I tried configuring the X-Pack LDAP authentication by adding the following to elasticsearch.yml

> ```
> xpack.security.authc.realms:
> native:
> type: native
> order: 0
> ldap1:
> type: ldap
> order: 1
> url: "ldap://<xxxxx host>:<xxxx port>"
> bind_dn: "CN=<service account name>,OU=Users - Service Accounts,OU=Administrative,DC=<groupname>,DC=xxxxxx,DC=com"
> bind_password: "sdfsdfsdfsdfs"
> user_search:
> base_dn: "<groupname>,dc=xxxxxx,dc=com"
> attribute: AccountName
> group_search:
> base_dn: "OU=Applications,OU=Groups,DC=<groupname>,DC=xxxxxx,DC=com"
> files:
> role_mapping: 'D:\ELK\elasticsearch-5.4.3\config\x-pack\role_mapping.yml'
> unmapped_groups_as_roles: false
> 
> ```

and I also created and `role-mapping.yml` under `/x-pack/config/role-mapping.yml`

```
 superuser:
   - "CN=MAR-CI-Admins-S-G,OU=Applications,OU=Groups,DC=dmzprod01,DC=mrshmc,DC=com"

```

It works when I set the role to "superuser" but i am getting below error when I try to create custom role using kibana and then try to use it in `role-mapping.yml`

> Config: Error 403 Forbidden: [security\_exception] action [indices:data/write/update] is unauthorized for user [XXXXX\_User]

---

<div class="post-metadata">

### Author: ![aswinkumart](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@aswinkumart](https://discuss.elastic.co/u/aswinkumart)
#### Post date: [July 31, 2017, 4:09pm UTC](https://discuss.elastic.co/t/ldap-authorization-issue-x-pack/94997/2 "2017-07-31T16:09:40Z")

</div>

any help here?

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [August 1, 2017, 12:24am UTC](https://discuss.elastic.co/t/ldap-authorization-issue-x-pack/94997/3 "2017-08-01T00:24:14Z")

</div>

Your question provided lots of details about the things that are working, and none of the details about the things that aren't working. It is very hard to provide useful advice when the only concrete piece of information we have is that _some_ user with _some_ role isn't able to do update _some_ index.

When asking questions, focus your details on the parts that _aren't working_:

- When I do **_this_** , the user gets **_this error_**.
- The user has **_this role_**.
- The role has **_this definition_**.

Here's what you can do to debug the problem:

Use the [authenticate API](https://www.elastic.co/guide/en/elasticsearch/reference/5.5/security-api-authenticate.html) to check your users roles, and then the [roles API](https://www.elastic.co/guide/en/elasticsearch/reference/5.5/security-api-roles.html) to check the definition of those roles.

```auto
curl -XGET 'localhost:9200/_xpack/security/_authenticate?pretty' -u my_ldap_user

```

That will show you which roles your user has. Check that your custom role is there.

Then run this, and **_copy-and-paste_** the role name from the output of the authenticate API. About 50% of these problems are caused by typos, so make sure you directly copy the role name.

```auto
curl -XGET 'localhost:9200/_xpack/security/role/my_custom_role?pretty' -u elastic

```

That will show you the definition of the role.  
Check what privileges the role has for the index you are trying to update.

---

<div class="post-metadata">

### Author: ![aswinkumart](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@aswinkumart](https://discuss.elastic.co/u/aswinkumart)
#### Post date: [August 1, 2017, 7:24pm UTC](https://discuss.elastic.co/t/ldap-authorization-issue-x-pack/94997/4 "2017-08-01T19:24:46Z")

</div>

Hi TimV,  
Thanks for your reponse.

I tried `GET /_xpack/security/role/kibana?pretty` but I got `{}` as output - `kibana` is the role which I created through `management -> security` under Kibana application. For other users like `superuser` I am getting following output:

```
{
  "superuser": {
    "cluster": [
      "all"
    ],
    "indices": [
      {
        "names": [
          "*"
        ],
        "privileges": [
          "all"
        ]
      }
    ],
    "run_as": [
      "*"
    ],
    "metadata": {
      "_reserved": true
    },
    "transient_metadata": {
      "enabled": true
    }
  }
}

```

Could you please tell me why I am not able get response for the role which I created? does it mean - we can assign only system defined roles for LDAP configuration?

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [August 2, 2017, 12:37am UTC](https://discuss.elastic.co/t/ldap-authorization-issue-x-pack/94997/5 "2017-08-02T00:37:14Z")

</div>

> [@aswinkumart](#):
>
> I tried GET /\_xpack/security/role/kibana?pretty but I got {} as output - kibana is the role which I created through management -\> security under Kibana application

I'm afraid that whatever you did in Kibana didn't actually create a role named `kibana`. If that API returns `{}` then the role doesn't exist.

Perhaps you had a typo in the role name when you created it in Kibana, or perhaps you got an error while trying to create the role, and didn't notice.

What roles does the Kibana UI list?

---

<div class="post-metadata">

### Author: ![aswinkumart](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@aswinkumart](https://discuss.elastic.co/u/aswinkumart)
#### Post date: [August 2, 2017, 1:27pm UTC](https://discuss.elastic.co/t/ldap-authorization-issue-x-pack/94997/6 "2017-08-02T13:27:42Z")

</div>

Hello,  
I kind of figured it out, If I create an role using "`dev Tools`" in Kibana console by suplying following command, it works -

```
POST /_xpack/security/role/readonly
{
  "cluster": ["all"],
  "indices": [
    {
      "names": ["*"],
      "privileges": ["read"]
    }
  ]
  }

```

however, If I create the role using `management -> security` It doesn't work when I configure under role-mapping.yml. Meaning, I am getting the `unauthorized for user [XXXXX_User]` error.

I am facing a new issue now - If I change the indices name to something else like my index name - authorization fails again - I am getting the `unauthorized for user [XXXXX_User]` error.

It works only if I give `"*"` - can you help me to understand this?

```
"indices": [
        {
          "names": ["*"],
```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 30, 2017, 1:27pm UTC](https://discuss.elastic.co/t/ldap-authorization-issue-x-pack/94997/7 "2017-08-30T13:27:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
