# LDAP integrated ELK with Shield

**URL:** <https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 15, 2016, 6:14am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810 "2016-06-15T06:14:10Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [June 15, 2016, 6:14am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/1 "2016-06-15T06:14:10Z")

</div>

We are configuring ELK Shield plugin. The ELK server is integrated with LDAP server which is working fine. For Kibana, we have used Apache reverse proxy.

The problem we are facing is with the configuration of Shield plugin.  
We have followed the official documentation but our Kibana dashboard is not coming up and giving error 502.  
One more thing , is SSL/TLS encryption mandatory in this case ?

Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 15, 2016, 6:18am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/2 "2016-06-15T06:18:05Z")

</div>

If you are using Shield on ES, why not in KB?

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [June 15, 2016, 6:23am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/3 "2016-06-15T06:23:28Z")

</div>

Hi ,

Sorry, what's KB ? ohh got it, We are evaluating the Shield.

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [June 17, 2016, 4:54am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/4 "2016-06-17T04:54:08Z")

</div>

Hi ,

Before configuring Shield , I have gone through its complete documentation.  
As a part of configuration , I have followed the steps given in - [https://www.elastic.co/guide/en/shield/current/kibana.html](https://www.elastic.co/guide/en/shield/current/kibana.html)  
We have not configured SSL/TLS encryption and as per my understanding that is not mandatory.  
We will enable it later on.

But after restarting kibana , I get following error - ![](https://us1.discourse-cdn.com/elastic/original/2X/b/b75c29a7a8c0a7ce0a632befba17aac4cab6c92b.JPG)

[root@irldxvm002 kibana]# curl [http://9.126.112.35:5601](http://9.126.112.35:5601)  
curl: (52) Empty reply from server  
[root@irldxvm002 kibana]# curl [http://9.126.112.35:9200](http://9.126.112.35:9200)  
{"error":{"root\_cause":[{"type":"security\_exception","reason":"missing authentication token for REST request [/]","header":{"WWW-Authenticate":"Basic realm="shield""}}],"type":"security\_exception","reason":"missing authentication token for REST request [/]","header":{"WWW-Authenticate":"Basic realm="shield""}},"status":401}

I have gone through the logs of ELK , httpd but did not get any clue.  
Let me know if you need any specific details.

Regards,  
Vinod

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [June 17, 2016, 9:35am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/5 "2016-06-17T09:35:28Z")

</div>

Hi ,

I have made some progress and now proxy error has gone. I am getting the login page with https and able to login with with my LDAP credentials but after login I am getting security exception as shown in attached screenshot-

 ![](https://us1.discourse-cdn.com/elastic/original/2X/f/f7399ce83deba4a96bb97b5b4de4d556cfc19757.JPG)

Regards,  
Vinod

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 17, 2016, 11:21am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/6 "2016-06-17T11:21:12Z")

</div>

What roles are mapped to your ldap user? It appears as though the user is missing cluster monitor permissions; take a look at the `my_kibana_user` role on [https://www.elastic.co/guide/en/shield/current/kibana.html](https://www.elastic.co/guide/en/shield/current/kibana.html)

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [June 17, 2016, 12:52pm UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/7 "2016-06-17T12:52:54Z")

</div>

Hi Jay,

Here is the role -

my\_kibana\_user:  
cluster:  
- monitor  
indices:  
- names: 'filebeat-_'  
privileges:  
- all  
- names: '.kibana_'  
privileges:  
- all

and role mapping

kibana4\_server:

- "mail=vinodar3@in.ibm.com,ou=bluepages,[o=ibm.com](http://o=ibm.com)"  
admin:
- "mail=vinodar3@in.ibm.com,ou=bluepages,[o=ibm.com](http://o=ibm.com)"  
power\_user:
- "mail=vinodar3@in.ibm.com,ou=bluepages,[o=ibm.com](http://o=ibm.com)"  
my\_kibana\_user:
- "mail=vinodar3@in.ibm.com,ou=bluepages,[o=ibm.com](http://o=ibm.com)"  
kibana4:
- "mail=vinodar3@in.ibm.com,ou=bluepages,[o=ibm.com](http://o=ibm.com)"

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 17, 2016, 1:39pm UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/8 "2016-06-17T13:39:28Z")

</div>

Do you have any errors in your log from startup about invalid roles? Also, if you execute the following to increase logging and authenticate as your user, some messages about role mapping should be logged:

```
PUT /_cluster/settings
{
    "transient" : {
        "logger.shield.authc" : "DEBUG"
    }
}
```

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [June 20, 2016, 4:51am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/9 "2016-06-20T04:51:28Z")

</div>

Hi Jay,

I am getting this log in elasticsearch-access.log

> [2016-06-20 10:12:29,894] [Chrome] [transport] [access\_denied] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[vinodar3@in.ibm.com], action=[cluster:monitor/nodes/info

Following logs in logstash.log -

> {:timestamp=\>"2016-06-20T10:16:40.073000+0530", :message=\>"[403] {"error":{"root\_cause":[{"type":"security\_exception","reason":"action [cluster:monitor/nodes/info] is unauthorized for user [vinodar3@in.ibm.com]"}],"type":"security\_exception","reason":"action [cluster:monitor/nodes/info] is unauthorized for user [vinodar3@in.ibm.com]"},"status":403}", :class=\>"Elasticsearch::Transport::Transport::Errors::Forbidden", :backtrace=\>["/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.15/lib/elasticsearch/transport/transport/base.rb:146:in `__raise_transport_error'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.15/lib/elasticsearch/transport/transport/base.rb:256:in `perform\_request'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.15/lib/elasticsearch/transport/transport/http/manticore.rb:54:in `perform_request'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.15/lib/elasticsearch/transport/transport/sniffer.rb:32:in `hosts'", "org/jruby/ext/timeout/Timeout.java:147:in `timeout'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.15/lib/elasticsearch/transport/transport/sniffer.rb:31:in `hosts'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.15/lib/elasticsearch/transport/transport/base.rb:76:in `reload_connections!'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.5.5-java/lib/logstash/outputs/elasticsearch/http_client.rb:72:in `sniff!'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.5.5-java/lib/logstash/outputs/elasticsearch/http\_client.rb:60:in `start_sniffing!'", "org/jruby/ext/thread/Mutex.java:149:in `synchronize'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.5.5-java/lib/logstash/outputs/elasticsearch/http\_client.rb:60:in `start_sniffing!'", "org/jruby/RubyKernel.java:1479:in `loop'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.5.5-java/lib/logstash/outputs/elasticsearch/http\_client.rb:59:in `start\_sniffing!'"], :level=\>:error}

Regards,  
Vinod

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 20, 2016, 10:41am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/10 "2016-06-20T10:41:50Z")

</div>

You'll need to look in the log file of the elasticsearch node that you are connecting to. The access log does not contain the role mapping debug output

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [June 20, 2016, 11:18am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/11 "2016-06-20T11:18:50Z")

</div>

Thanks for the reply Jay, but I have already configuring "shield.authc: TRACE" in /etc/elasticsearch/logging.yml but it looks like somehow it is not working.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 20, 2016, 11:43am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/12 "2016-06-20T11:43:51Z")

</div>

Did you configure it under the logger section? Did you restart elasticsearch after making the change?

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [June 20, 2016, 11:49am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/13 "2016-06-20T11:49:05Z")

</div>

Thanks for pointing out my stupid mistake- I can see debug logs in elasticsearch.log  
Though I have done the mapping , I am getting this -

> [2016-06-20 17:15:36,590][DEBUG][shield.authc.support] [Oneg the Prober] the roles [], are mapped from these [ldap] groups [] for realm [ldap/ldap1]  
> [2016-06-20 17:15:36,591][DEBUG][shield.authc.support] [Oneg the Prober] the roles [], are mapped from the user [ldap] for realm [uid=xxxx,c=in,ou=bluepages,[o=ibm.com/ldap](http://o=ibm.com/ldap)]  
> [2016-06-20 17:15:36,595][DEBUG][shield.authc.ldap] [Oneg the Prober] authenticated user [vinodar3@in.ibm.com], with roles []

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 20, 2016, 12:39pm UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/14 "2016-06-20T12:39:34Z")

</div>

> [@vienodp](#):
>
> uid=xxxx,c=in,ou=bluepages,[o=ibm.com/ldap](http://o=ibm.com/ldap)

You need to use that in your role mapping rather than the `mail=` entries. The role mapping is done off of group DNs or the user DN.

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [June 20, 2016, 1:00pm UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/15 "2016-06-20T13:00:05Z")

</div>

Thanks , now I am able to login to kibana. But I see following in the elasticsearch logs -

> [2016-06-20 18:28:44,428][DEBUG][shield.authc.ldap] [Man-Brute] authentication failed for user [AVJBYJ744]  
> ElasticsearchSecurityException[failed to find user [AVJBYJ744] with search base [c=in, ou=bluepages, [o=ibm.com](http://o=ibm.com)] scope [sub\_tree]]  
> at org.elasticsearch.shield.support.Exceptions.authenticationError(Exceptions.java:39)

And now role mapping is working fine -

> [2016-06-20 18:28:46,319][DEBUG][shield.authc.ldap] [Man-Brute] authenticated user [vinodar3@in.ibm.com], with roles [[admin, kibana4\_server, power\_user, kibana4, my\_kibana\_user]]

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 20, 2016, 1:16pm UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/16 "2016-06-20T13:16:33Z")

</div>

Is this user `AVJBYJ744` in LDAP? What does your realm configuration look like?

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [June 21, 2016, 3:28am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/17 "2016-06-21T03:28:14Z")

</div>

Yes that user is LDAP user and here is the realm configuration in elasticsearch.yml

> shield:  
> authc:  
> realms:  
> ldap1:  
> type: ldap  
> order: 0  
> url: "ldaps://bluepages.ibm.com:636"  
> user\_search:  
> base\_dn: "c=in, ou=bluepages, [o=ibm.com](http://o=ibm.com)"  
> attribute: mail  
> group\_search:  
> base\_dn: "c=in, ou=bluepages, [o=ibm.com](http://o=ibm.com)"  
> files:  
> role\_mapping: "/etc/elasticsearch/shield/role\_mapping.yml"  
> unmapped\_groups\_as\_roles: false  
> user\_search.pool.health\_check.enabled: false

> shield.audit.enabled: true

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 21, 2016, 11:10am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/18 "2016-06-21T11:10:57Z")

</div>

You are using the `mail` attribute but the username is not a email address. I think that is why the user cannot be found.

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [June 21, 2016, 11:14am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/19 "2016-06-21T11:14:50Z")

</div>

But if I use emai in role mapping file, it does not work. Then I get security exception as soon as I login to kibana.  
It is strange that with this configuration everything is working fine but only getting security exception in elasticsearch logs. The log says both successfully authenticated and did not find the user.

I asked other user to login who got security exception but after assigning role in role mapping file he was able to login successfully.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 21, 2016, 11:41am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810/20 "2016-06-21T11:41:11Z")

</div>

This is the only realm you have enabled? Do you see `access_granted` for this user in the audit logs?

Currently, we only support the distinguished name of a ldap group or user for role mapping. `mail` is not part of the DN so it cannot be used for role mapping, but it can be used to find the user in ldap.

Lets say we have a user with the following:

DN: "uid=JM77456,ou=bluepages,[o=ibm.com](http://o=ibm.com)"  
`mail`: `user@in.ibm.com`

With the configuration you are using, the username to use for this user would be `user@in.ibm.com` and the role mapping definition would be:

kibana4:

- "uid=JM77456,ou=bluepages,[o=ibm.com](http://o=ibm.com)"

What happens is a search is executed to find a user that has the `mail` attribute value that matches `user@in.ibm.com`. Once this is found, the DN is retrieved and the user is authenticated via a bind. After the bind, groups are searched for and then roles are mapped based on the DNs of the groups and the DN of the user.

[Next page](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810.md?page=2)
