# Multiple realms not working

**URL:** <https://discuss.elastic.co/t/multiple-realms-not-working/42433>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 22, 2016, 9:55pm UTC](https://discuss.elastic.co/t/multiple-realms-not-working/42433 "2016-02-22T21:55:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bblank](https://avatars.discourse-cdn.com/v4/letter/b/f14d63/32.png) [@bblank](https://discuss.elastic.co/u/bblank)\
**Post date:** [February 22, 2016, 9:55pm UTC](https://discuss.elastic.co/t/multiple-realms-not-working/42433/1 "2016-02-22T21:55:17Z")

</div>

I can use an esuser realm or an active\_directory realm to authenticate my users but I can't use both. When I add the following to my elasticsearch.yml file the service won't start and it dies before writing to the log file. Does anyone see anything wrong with this? (From the end of my elasticsearch.yml file)  
shield.ssl.keystore.path: /etc/elasticsearch/shield/node01.jks  
shield.ssl.keystore.password:   
shield:  
authc:  
realms:  
active\_directory:  
type: active\_directory  
order: 0  
domain\_name:   
url: ldaps://:636  
unmapped\_groups\_as\_roles: true  
esusers:  
type: esusers  
order: 1

---

<div class="post-metadata">

**Author:** ![bblank](https://avatars.discourse-cdn.com/v4/letter/b/f14d63/32.png) [@bblank](https://discuss.elastic.co/u/bblank)\
**Post date:** [February 22, 2016, 10:08pm UTC](https://discuss.elastic.co/t/multiple-realms-not-working/42433/2 "2016-02-22T22:08:57Z")

</div>

User error... I THOUGHT AD was working, but alas it is not...

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [February 22, 2016, 10:25pm UTC](https://discuss.elastic.co/t/multiple-realms-not-working/42433/3 "2016-02-22T22:25:41Z")

</div>

It can sometimes be tricky to configure AD or LDAP integration.

If you want more logging of the connection to AD, you can add `shield.authc: DEBUG` to the logging.yml configuration file in CONFIG\_DIR.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/multiple-realms-not-working/42433/4 "2017-07-06T13:46:33Z")

</div>


