# Multiple Domain Support - No Common Forest

**URL:** <https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645>\
**Category:** Elasticsearch\
**Created:** [May 30, 2017, 10:25pm UTC](https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645 "2017-05-30T22:25:54Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nobby](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nobby/32/18657_2.png) [@Nobby](https://discuss.elastic.co/u/Nobby)\
**Post date:** [May 30, 2017, 10:25pm UTC](https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645/1 "2017-05-30T22:25:55Z")

</div>

Hey guys,

I'm looking to see if there's a solution for authentication users in two different domains that don't exist in the same forest, don't have a common root domain but have a two-way trust between them.

For example: I have a security group in [example.com](http://example.com) which contains users in [other-domain.com](http://other-domain.com). In every application I've used which supports Active Directory authentication, it has been able to authenticate [other-domain.com](http://other-domain.com) users via the two-way trust with [example.com](http://example.com), without needing to directly query [other-domain.com](http://other-domain.com) domain controllers.

I've tried adding a second Active Directory realm in elasticsearch.yml but elastic dies 5 seconds after startup. I've tried using the recommended Global Catalog port configuration for the URL but I feel like the domain\_name property (which is set to [example.com](http://example.com)) prevents lookups for [my.user@other-domain.com](mailto:my.user@other-domain.com) or [other-domain.com](http://other-domain.com)\my.user. It instantly fails authentication.

Any tips? Thanks!

---

<div class="post-metadata">

**Author:** ![Mike.Barretta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike.barretta/32/16688_2.png) [@Mike.Barretta](https://discuss.elastic.co/u/Mike.Barretta)\
**Post date:** [June 1, 2017, 3:20pm UTC](https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645/2 "2017-06-01T15:20:39Z")

</div>

Can you share the xpack.security.authc.realms chunk of your elasticsearch.yml when you define two AD realms?

---

<div class="post-metadata">

**Author:** ![Nobby](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nobby/32/18657_2.png) [@Nobby](https://discuss.elastic.co/u/Nobby)\
**Post date:** [June 2, 2017, 1:09am UTC](https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645/3 "2017-06-02T01:09:41Z")

</div>

Hey Mike,

Here's the config

```
xpack.security.authc:
 realms:
  native:
   type: native
   order: 0
  active_directory:
   type: active_directory
   order: 1
   domain_name: first-domain.com
   url: ldap://dc1.first-domain.com:3268, ldap://dc2.first-domain.com:3268
   load_balance:
    type: "round_robin"
   unmapped_groups_as_roles: false
  active_directory:
   type: active_directory
   order: 2
   domain_name: another-domain.local
   url: ldap://dc1.first-domain.com:3268, ldap://dc2.first-domain.com:3268
   load_balance:
    type: "round_robin"

```

My expectation here is that this config would permit my.user@another-domain.local to authenticate via the [first-domain.com](http://first-domain.com) domain controllers. I've tried both the GC ports and 389 in the ldap URLs. If I comment-out the second AD config section, Elastic starts but I can't authentication with another-domain.local user accounts (instantly fails login attempt)

---

<div class="post-metadata">

**Author:** ![Mike.Barretta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike.barretta/32/16688_2.png) [@Mike.Barretta](https://discuss.elastic.co/u/Mike.Barretta)\
**Post date:** [June 5, 2017, 9:27pm UTC](https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645/4 "2017-06-05T21:27:23Z")

</div>

I think part of the problem is that you use the same name for both AD realms. Try naming them something like `active_directoy_first` and `active_directory_second`:

```auto
xpack.security.authc:
 realms:
  native:
   type: native
   order: 0
  active_directory:
   type: active_directory_first
   order: 1
   domain_name: first-domain.com
   url: ldap://dc1.first-domain.com:3268, ldap://dc2.first-domain.com:3268
   load_balance:
     type: "round_robin"
   unmapped_groups_as_roles: false
  active_directory_second:
   type: active_directory
   order: 2
   domain_name: another-domain.local
   url: ldap://dc1.first-domain.com:3268, ldap://dc2.first-domain.com:3268
   load_balance:
     type: "round_robin"

```

---

<div class="post-metadata">

**Author:** ![Nobby](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nobby/32/18657_2.png) [@Nobby](https://discuss.elastic.co/u/Nobby)\
**Post date:** [June 6, 2017, 1:03am UTC](https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645/5 "2017-06-06T01:03:08Z")

</div>

Hey Mike,

Thanks for pointing that out. I didn't realise it was a naming label.

I can now have two AD blocks in there and Elastic boots fine. Unfortunately, login attempts to another-domain.local still fail instantly. On the login page for Kabana i've tried the following username syntax:

- another-domain.local\my\_user
- my\_user@another-domain.local

Is there anywhere in Kabana or another place in ElasticSearch i need to configure? How can I debug failed logins?

---

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [June 7, 2017, 7:38pm UTC](https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645/6 "2017-06-07T19:38:26Z")

</div>

please double check the `url` parameter for the `active_directory_second`, the config above has the same servers for both AD realms.

---

<div class="post-metadata">

**Author:** ![Mike.Barretta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike.barretta/32/16688_2.png) [@Mike.Barretta](https://discuss.elastic.co/u/Mike.Barretta)\
**Post date:** [June 7, 2017, 7:52pm UTC](https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645/7 "2017-06-07T19:52:17Z")

</div>

@Nobby, what error are you seeing in the logs? Also, have you gone through mapping the AD users/groups to Elasticsearch users/roles?

---

<div class="post-metadata">

**Author:** ![Nobby](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nobby/32/18657_2.png) [@Nobby](https://discuss.elastic.co/u/Nobby)\
**Post date:** [June 9, 2017, 4:22am UTC](https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645/8 "2017-06-09T04:22:33Z")

</div>

Hey jetnet,

This is intentionally the case.

---

<div class="post-metadata">

**Author:** ![Nobby](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nobby/32/18657_2.png) [@Nobby](https://discuss.elastic.co/u/Nobby)\
**Post date:** [June 9, 2017, 4:32am UTC](https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645/9 "2017-06-09T04:32:11Z")

</div>

Hey Mike,

My x-pack trial period has run out so there are billions of errors 😓. I should probably add a bit more detail for the scenario as well.

- There is a Security Group in [first-domain.com](http://first-domain.com) called ElasticGuys which contains a mix of [first-domain.com](http://first-domain.com) and another-domain.local users
- Elastic role\_mapping.yml has been configured to allow ElasticGuys are super users
- Users from [first-domain.com](http://first-domain.com) that are in ElasticGuys can login to Kibana and do anything within the interface
- Users from another-domain.local that are in ElasticGuys can't login to Kibana

Is there a requirement for role\_mapping.yml to contain a security group defined in another-domain.local to both authentication and role authorisation? i.e. there needs to be a CN=ElasticGuys,OU=Groups,DC=first-domain,DC=com and CN=ElasticGuys,OU=Groups,DC=another-domain,DC=local?

When I use other systems with AD integration, it has always permitted authentication and authorisation for both domains via a single domain controllers groups and users catalog.

---

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [June 9, 2017, 7:32am UTC](https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645/10 "2017-06-09T07:32:16Z")

</div>

> This is intentionally the case.

sorry, I started to read the topic from the third message 🙂  
I would start with verification if a user from `another-domain` can be resolved to `ElasticGuys` group, e.g. using the [AdFind](http://www.joeware.net/freetools/tools/adfind/):

```
adfind -h dc1.first-domain.com -gc -f "userPrincipalName=my_user@another-domain.local" memberof

```

if this is the case, than you have to enable trace level and look at the log-files:

```
PUT /_cluster/settings
{"transient":{"logger.org.elasticsearch.xpack.security.authc": "trace"}}

```

and possibly turn the audit logging on:

```
xpack.security.audit.enabled: true
xpack.security.audit.outputs: [logfile]

```

it's better to shutdown kibana, as it sends a lot of queries to ES constantly and it will be hard to read the logs, and to call ES directly, e.g.

```
curl -u my_user http://es-host:9200/_search

```

Note: `my_user` is from `@another_domain.local`

Hope, that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2017, 7:32am UTC](https://discuss.elastic.co/t/multiple-domain-support-no-common-forest/87645/11 "2017-07-07T07:32:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
