# LDAP Elasticsearch

**URL:** <https://discuss.elastic.co/t/ldap-elasticsearch/348205>\
**Category:** Elasticsearch\
**Created:** [November 29, 2023, 9:12am UTC](https://discuss.elastic.co/t/ldap-elasticsearch/348205 "2023-11-29T09:12:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Manal\_A](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manal_a/32/123992_2.png) [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Post date:** [November 29, 2023, 9:12am UTC](https://discuss.elastic.co/t/ldap-elasticsearch/348205/1 "2023-11-29T09:12:12Z")

</div>

Hello ,  
I want to know how to connect Elasticsearch to an external LDAP, and if I am in a cluster that contains multiple nodes, do I need to configure LDAP on all Elasticsearch nodes or just one of them (and wich one : master , coordi , data node ...)? The same question applies to opening streams please.

Thank you

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [November 29, 2023, 11:17am UTC](https://discuss.elastic.co/t/ldap-elasticsearch/348205/2 "2023-11-29T11:17:38Z")

</div>

Hi,

You need to configure the `xpack.security.authc.*` settings in elasticsearch.yml and kibana.yml **on all nodes**.

Have a look at:

- [Security settings in Elasticsearch | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html#ref-ldap-settings)
- [Security settings in Kibana | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/security-settings-kb.html#security-settings-kb)

ES would look something like:

```yml
xpack:
  security:
    authc:
      realms:
        ldap.realm1:
          order: 1
          url: ldaps://yourserver:636
          bind_dn: <your_dn>
          bind_password: <password>
          ....

```

LDAP is basic auth, so use the basic realm in kibana as provider.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 29, 2023, 12:22pm UTC](https://discuss.elastic.co/t/ldap-elasticsearch/348205/3 "2023-11-29T12:22:33Z")

</div>

> [@Manal\_A](#):
>
> do I need to configure LDAP on all Elasticsearch nodes or just one of them (and wich one : master , coordi , data node ...)?

It doesn't need to be configured in all nodes, just the ones where your clients, including kibana, will make requests.

For example, if your Kibana and all your clients only make requests to your coordinating nodes, then you can configure the authentication just on those nodes.

This is an example of a configuration that includes the native realm and the active directory realm:

```auto
xpack:
  security:
    authc:
      realms:
        native:
          native1:
            order: 0

        active_directory:
          my_ad:
            order: 1
            domain_name: "company.domain"
            follow_referrals: false
            url: ["ldaps://ladp-server-01.company.domain:636", "ldaps://ldap-server-02.company.domain:636"]
            ssl:
              certificate_authorities: ["/etc/elasticsearch/certs/ldap/ladp-server-01.pem", "/etc/elasticsearch/certs/ldap/ldap-server-02.pem"]
            load_balance:
              type: "round_robin"

```

Also, you didn't say if you have a license or not, but to use LDAP you need a paid license.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2023, 12:22pm UTC](https://discuss.elastic.co/t/ldap-elasticsearch/348205/4 "2023-12-27T12:22:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
