# LDAP configuration for elastic

**URL:** <https://discuss.elastic.co/t/ldap-configuration-for-elastic/312874>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 25, 2022, 6:59am UTC](https://discuss.elastic.co/t/ldap-configuration-for-elastic/312874 "2022-08-25T06:59:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![irivas95](https://avatars.discourse-cdn.com/v4/letter/i/839c29/32.png) [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Post date:** [August 25, 2022, 6:59am UTC](https://discuss.elastic.co/t/ldap-configuration-for-elastic/312874/1 "2022-08-25T06:59:52Z")

</div>

Hi,

I'm a bit new to security configurations that don't involve native realm. The case is that I would like to configure elasticsearch authentication with ldap and the configuration is not very clear about some things.  
I have a self-managed cluster with 8 nodes including dedicated data, dedicated master and dedicated ml, with elasticsearch version 7.16.3 and trial license. I would like to know if I have to configure ldap realm ([LDAP user authentication | Elasticsearch Guide [7.16] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/ldap-realm.html)) on all nodes or only on one.  
Another question I have is how would kibana, logstash and beats authenticate against elasticsearch with this kind of configuration.  
Could someone help me to solve these questions?  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [August 25, 2022, 12:02pm UTC](https://discuss.elastic.co/t/ldap-configuration-for-elastic/312874/2 "2022-08-25T12:02:35Z")

</div>

> [@irivas95](#):
>
> I would like to know if I have to configure ldap realm on all nodes or only on one.

Realm is per node. You need to configure on every node that takes user request. If a node does not directly take user request at all, you don't have to configure realm for it.

> Another question I have is how would kibana, logstash and beats authenticate against elasticsearch with this kind of configuration.

From client's perspective, ldap realm works similarly to username/password authentication (e.g. native realm). It's a viable choice for Kibana. But I think you probably better to go with other authentication mechanisms such as API keys for Beats and leave LDAP realm for interactive usages.

---

<div class="post-metadata">

**Author:** ![irivas95](https://avatars.discourse-cdn.com/v4/letter/i/839c29/32.png) [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Post date:** [August 25, 2022, 12:10pm UTC](https://discuss.elastic.co/t/ldap-configuration-for-elastic/312874/3 "2022-08-25T12:10:29Z")

</div>

Thank you very much for your reply Yang\_Wang,  
One more question, could I use native realm for beats, kibana and logstash?, I am not very familiar with API keys.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [August 25, 2022, 1:17pm UTC](https://discuss.elastic.co/t/ldap-configuration-for-elastic/312874/4 "2022-08-25T13:17:35Z")

</div>

> [@irivas95](#):
>
> One more question, could I use native realm for beats, kibana and logstash?, I am not very familiar with API keys.

You should consider API keys _only_ for Beats. You can also use native users for Beats.

For kibana and logstash to connect to Elasticsearch, you should use the builtin system users, `kibana_system` and `logstash_system`. Technically you can also use native uers, but it is not recommended.

---

<div class="post-metadata">

**Author:** ![irivas95](https://avatars.discourse-cdn.com/v4/letter/i/839c29/32.png) [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Post date:** [August 25, 2022, 6:30pm UTC](https://discuss.elastic.co/t/ldap-configuration-for-elastic/312874/5 "2022-08-25T18:30:54Z")

</div>

Understood, thank you very much for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2022, 6:31pm UTC](https://discuss.elastic.co/t/ldap-configuration-for-elastic/312874/6 "2022-09-22T18:31:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
