# LDAP role\_mapping don't work...?

**URL:** <https://discuss.elastic.co/t/ldap-role-mapping-dont-work/93000>\
**Category:** Elasticsearch\
**Created:** [July 13, 2017, 11:29am UTC](https://discuss.elastic.co/t/ldap-role-mapping-dont-work/93000 "2017-07-13T11:29:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [July 13, 2017, 11:29am UTC](https://discuss.elastic.co/t/ldap-role-mapping-dont-work/93000/1 "2017-07-13T11:29:10Z")

</div>

ES/Logstash/Kibana version: 5.4.1

I have configured LDAP and it works, also I can login with a user in LDAP.  
But there is no permission to access anything. So I configure the role\_mapping file as the official guide tells.

[https://www.elastic.co/guide/en/x-pack/current/mapping-roles.html#ldap-role-mapping](https://www.elastic.co/guide/en/x-pack/current/mapping-roles.html#ldap-role-mapping)

But the role\_mapping do not work, do I miss something? or something is wrong?

Here is my configuration:

```auto
# vim /etc/elasticsearch/elasticsearch.yml
xpack:
  security:
    authc:
      realms:
        ldap1:
          type: ldap
          order: 0
          url: "ldap://192.168.2.164:389"
          user_dn_templates:
            - "uid={0},ou=Users,dc=beijing,dc=op"
          group_search:
            base_dn: "dc=beijing,dc=op"
          files:
            role_mapping: "/etc/elasticsearch/x-pack/role_mapping.yml"
          unmapped_groups_as_roles: false

```

```auto
# vim /etc/elasticsearch/x-pack/role_mapping.yml
superuser:
  - "uid=shengyongp,ou=User,dc=beijing,dc=op"

```

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 13, 2017, 12:25pm UTC](https://discuss.elastic.co/t/ldap-role-mapping-dont-work/93000/2 "2017-07-13T12:25:49Z")

</div>

It appears you have a typo in your mapping file.  
Your `user_dn_templates` is using `ou=Users` but your role-mapping file is using `ou=User`.

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [July 13, 2017, 7:07pm UTC](https://discuss.elastic.co/t/ldap-role-mapping-dont-work/93000/3 "2017-07-13T19:07:51Z")

</div>

Resolved. thanks a lot ! 😃

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2017, 7:08pm UTC](https://discuss.elastic.co/t/ldap-role-mapping-dont-work/93000/4 "2017-08-10T19:08:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
