# PKI Authentication can't map users

**URL:** <https://discuss.elastic.co/t/pki-authentication-cant-map-users/120385>\
**Category:** Elasticsearch\
**Created:** [February 19, 2018, 1:54am UTC](https://discuss.elastic.co/t/pki-authentication-cant-map-users/120385 "2018-02-19T01:54:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![koebane](https://avatars.discourse-cdn.com/v4/letter/k/eb9ed0/32.png) [@koebane](https://discuss.elastic.co/u/koebane)\
**Post date:** [February 19, 2018, 1:54am UTC](https://discuss.elastic.co/t/pki-authentication-cant-map-users/120385/1 "2018-02-19T01:54:51Z")

</div>

Hello all, I am trying to setup PKI authentication on my ES cluster with X-Pack but I must have done something wrong. I have setup the roles, mappings and certificates but my filebeat (the only thing that I have tested so far), seems to only get the access of an anonymous user

/etc/elasticsearch/elasticsearch.yml

> ```
> cluster:
> name: my-cluster
> discovery:
> zen:
> hosts_provider: ec2
> minimum_master_nodes: 3
> ec2:
> endpoint: ec2.us-west-2.amazonaws.com
> groups: sg-509a6529
> availability_zones: us-west-2a,us-west-2b
> tag.Role: es-cluster
> cloud:
> node:
> auto_attributes: true
> path:
> data: /var/lib/elasticsearch
> logs: /var/log/elasticsearch
> xpack.security.audit.enabled: true
> network:
> host: _ec2:privateIp_
> script:
> allowed_types: inline
> node.name: i-0c583529e070fb2e9
> xpack:
> security:
> transport.ssl:
> enabled: true
> verification_mode: certificate 
> key: /etc/elasticsearch/certs/es_cert.key
> certificate: /etc/elasticsearch/certs/es_cert.crt
> certificate_authorities: ["/etc/elasticsearch/certs/ca.crt"]
> http.ssl:
> enabled: true 
> client_authentication: optional
> verification_mode: certificate 
> key: /etc/elasticsearch/certs/es_cert.key
> certificate: /etc/elasticsearch/certs/es_cert.crt
> certificate_authorities: ["/etc/elasticsearch/certs/ca.crt"]
> authc:
> realms:
> pki1:
> order: 0
> type: pki
> certificate_authorities: ["/etc/elasticsearch/certs/ca.crt"]
> files.role_mapping: /etc/elasticsearch/x-pack/role_mapping.yml
> anonymous.username: anonymous_user
> anonymous.roles: monitor_jobs
> 
> ```

---

<div class="post-metadata">

**Author:** ![koebane](https://avatars.discourse-cdn.com/v4/letter/k/eb9ed0/32.png) [@koebane](https://discuss.elastic.co/u/koebane)\
**Post date:** [February 19, 2018, 1:56am UTC](https://discuss.elastic.co/t/pki-authentication-cant-map-users/120385/2 "2018-02-19T01:56:36Z")

</div>

/etc/elasticsearch/x-pack/roles.yml  
# All cluster rights  
# All operations on all indices  
admin:  
cluster:  
- all  
indices:  
- names: '\*'  
privileges:  
- all

```
# monitoring cluster privileges
# All operations on all indices
power_user:
  cluster:
    - monitor
  indices:
    - names: '*'
      privileges:
        - all

# Defines permissions for filebeat containers
filebeat_container:
  cluster:
    - monitor
  indices:
    - names: 'filebeat-*'
      privileges:
        - write
        - create_index

# Defines permissions for auditlogs middleware container
es_reader:
  cluster:
    - transport_client
  indices:
    - names: '*'
      privileges:
        - read

monitor_jobs:
  cluster:
    - monitor

```

etc/elasticsearch/x-pack/role\_mapping.yml  
filebeat\_container:  
- "[cn=filebeat.int.myorg.com](http://cn=filebeat.int.myorg.com)"  
- "c=US, st=Tennessee, l=Memphis, o=My Organization, ou=IT Dev, [cn=filebeat.int.myorg.com](http://cn=filebeat.int.myorg.com)"  
- "cn=filebeats,ou=int,ou=int,ou=myorg,o=com"  
auditlog\_mw\_container:  
- "[cn=middleware.int.myorg.com](http://cn=middleware.int.myorg.com)"  
- "c=US, st=Tennessee, l=Memphis, o=My Organization, ou=IT Dev, [cn=middleware.int.myorg.com](http://cn=middleware.int.myorg.com)"  
- "cn=middleware,ou=int,ou=int,ou=myorg,o=com"  
admin:  
- "[cn=es.int.myorg.com](http://cn=es.int.myorg.com)"  
- "c=US, st=Tennessee, l=Memphis, o=My Organization, ou=IT Dev, [cn=es.int.myorg.com](http://cn=es.int.myorg.com)"  
- "cn=es,ou=int,ou=int,ou=myorg,o=com"

```
openssl x509 -in filebeat.crt -noout -text
Certificate:
    Data:
        Version: 1 (0x0)
        Serial Number: 11937562650760635722 (0xa5aabdfba28ee54a)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Tennessee, L=Memphis, O=My Organization, OU=IT Dev, CN=filebeat.int.myorg.com
        Validity
            Not Before: Feb 16 17:07:56 2018 GMT
            Not After : Feb 14 17:07:56 2028 GMT
        Subject: C=US, ST=Tennessee, L=Memphis, O=My Organization, OU=IT Dev, CN=ffilebeat.int.myorg.com/emailAddress=filebeat@int.myorg.com
```

---

<div class="post-metadata">

**Author:** ![koebane](https://avatars.discourse-cdn.com/v4/letter/k/eb9ed0/32.png) [@koebane](https://discuss.elastic.co/u/koebane)\
**Post date:** [February 19, 2018, 1:59am UTC](https://discuss.elastic.co/t/pki-authentication-cant-map-users/120385/3 "2018-02-19T01:59:36Z")

</div>

Everytime that filebeats tries to authenticate, I get the following  
/var/log/elasticsearc/my-cluster.log  
[2018-02-18T19:31:19,863][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [i-0c583529e070fb2e9] The security index is not yet available - no role mappings can be loaded  
[2018-02-18T19:31:20,277][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [i-0c583529e070fb2e9] The security index is not yet available - no role mappings can be loaded  
[2018-02-18T19:32:20,603][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [i-0c583529e070fb2e9] The security index is not yet available - no role mappings can be loaded  
[2018-02-18T19:32:20,846][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [i-0c583529e070fb2e9] The security index is not yet available - no role mappings can be loaded  
[2018-02-18T19:32:21,535][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [i-0c583529e070fb2e9] The security index is not yet available - no role mappings can be loaded  
[2018-02-18T19:33:21,725][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [i-0c583529e070fb2e9] The security index is not yet available - no role mappings can be loaded  
[2018-02-18T19:33:21,952][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [i-0c583529e070fb2e9] The security index is not yet available - no role mappings can be loaded  
[2018-02-18T19:33:22,611][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [i-0c583529e070fb2e9] The security index is not yet available - no role mappings can be loaded  
[2018-02-18T19:34:22,802][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [i-0c583529e070fb2e9] The security index is not yet available - no role mappings can be loaded  
[2018-02-18T19:34:23,027][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [i-0c583529e070fb2e9] The security index is not yet available - no role mappings can be loaded  
[2018-02-18T19:34:23,975][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [i-0c583529e070fb2e9] The security index is not yet available - no role mappings can be loaded

/var/log/elasticsearch/my-cluster\_access.log  
\> \> [2018-02-18T19:31:19,678] [transport] [access\_granted] origin\_type=[rest], origin\_address=[10.158.4.5], principal=[[filebeat.int.myorg.com](http://filebeat.int.myorg.com)], roles=[monitor\_jobs], action=[cluster:monitor/main], request=[MainRequest]  
\> \> [2018-02-18T19:31:19,863] [transport] [access\_denied] origin\_type=[rest], origin\_address=[10.158.4.5], principal=[[filebeat.int.myorg.com](http://filebeat.int.myorg.com)], roles=[monitor\_jobs], action=[indices:admin/template/get], request=[GetIndexTemplatesRequest]  
\> \> [2018-02-18T19:31:20,279] [transport] [access\_denied] origin\_type=[rest], origin\_address=[10.158.4.5], principal=[[filebeat.int.myorg.com](http://filebeat.int.myorg.com)], roles=[monitor\_jobs], action=[indices:admin/template/put], indices=[filebeat-6.2.1-_], request=[PutIndexTemplateRequest]  
\> \> [2018-02-18T19:32:20,603] [transport] [access\_granted] origin\_type=[rest], origin\_address=[10.158.4.5], principal=[[filebeat.int.myorg.com](http://filebeat.int.myorg.com)], roles=[monitor\_jobs], action=[cluster:monitor/main], request=[MainRequest]  
\> \> [2018-02-18T19:32:20,846] [transport] [access\_denied] origin\_type=[rest], origin\_address=[10.158.4.5], principal=[[filebeat.int.myorg.com](http://filebeat.int.myorg.com)], roles=[monitor\_jobs], action=[indices:admin/template/get], request=[GetIndexTemplatesRequest]  
\> \> [2018-02-18T19:32:21,537] [transport] [access\_denied] origin\_type=[rest], origin\_address=[10.158.4.5], principal=[[filebeat.int.myorg.com](http://filebeat.int.myorg.com)], roles=[monitor\_jobs], action=[indices:admin/template/put], indices=[filebeat-6.2.1-_], request=[PutIndexTemplateRequest]  
\> \> [2018-02-18T19:33:21,726] [transport] [access\_granted] origin\_type=[rest], origin\_address=[10.158.4.5], principal=[[filebeat.int.myorg.com](http://filebeat.int.myorg.com)], roles=[monitor\_jobs], action=[cluster:monitor/main], request=[MainRequest]  
\> \> [2018-02-18T19:33:21,952] [transport] [access\_denied] origin\_type=[rest], origin\_address=[10.158.4.5], principal=[[filebeat.int.myorg.com](http://filebeat.int.myorg.com)], roles=[monitor\_jobs], action=[indices:admin/template/get], request=[GetIndexTemplatesRequest]  
\> \> [2018-02-18T19:33:22,613] [transport] [access\_denied] origin\_type=[rest], origin\_address=[10.158.4.5], principal=[[filebeat.int.myorg.com](http://filebeat.int.myorg.com)], roles=[monitor\_jobs], action=[indices:admin/template/put], indices=[filebeat-6.2.1-_], request=[PutIndexTemplateRequest]  
\> \> [2018-02-18T19:34:22,802] [transport] [access\_granted] origin\_type=[rest], origin\_address=[10.158.4.5], principal=[[filebeat.int.myorg.com](http://filebeat.int.myorg.com)], roles=[monitor\_jobs], action=[cluster:monitor/main], request=[MainRequest]  
\> \> [2018-02-18T19:34:23,028] [transport] [access\_denied] origin\_type=[rest], origin\_address=[10.158.4.5], principal=[[filebeat.int.myorg.com](http://filebeat.int.myorg.com)], roles=[monitor\_jobs], action=[indices:admin/template/get], request=[GetIndexTemplatesRequest]  
\> \> [2018-02-18T19:34:23,977] [transport] [access\_denied] origin\_type=[rest], origin\_address=[10.158.4.5], principal=[[filebeat.int.myorg.com](http://filebeat.int.myorg.com)], roles=[monitor\_jobs], action=[indices:admin/template/put], indices=[filebeat-6.2.1-_], request=[PutIndexTemplateRequest]

Please help.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 19, 2018, 2:57am UTC](https://discuss.elastic.co/t/pki-authentication-cant-map-users/120385/4 "2018-02-19T02:57:01Z")

</div>

It is helpful if you tell us what version if Elasticsearch you are running as the details can vary quite significantly between releases.

There's a note at the bottom of the PKI realm documentation that will be helpful for resolving this problem:

> **[PKI User Authentication | X-Pack for the Elastic Stack \[6.2\] | Elastic](https://www.elastic.co/guide/en/x-pack/6.2/pki-realm.html#assigning-roles-pki)**

> The disinguished name for a PKI user follows X.500 naming conventions which place the most specific fields (like `cn` or `uid`) at the beginning of the name, and the most general fields (like `o` or `dc`) at the end of the name. Some tools, such as `openssl`, may print out the subject name in a different format.
> 
> One way that you can determine the correct DN for a certificate is to use the [authenticate API](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/security-api-authenticate.html) (use the relevant PKI certificate as the means of authentication) and inspect the metadata field in the result. The user’s distinguished name will be populated under the `pki_dn` key. You can also use the authenticate API to validate your role mapping.

> [@koebane](#):
>
> [2018-02-18T19:31:19,863][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [i-0c583529e070fb2e9] The security index is not yet available - no role mappings can be loaded

That implies you have no security index, which also means you have not set the password for the builtin users, and you should do that as a matter of priority. The steps for that are dependent on the version of Elasticsearch you are running.

---

<div class="post-metadata">

**Author:** ![koebane](https://avatars.discourse-cdn.com/v4/letter/k/eb9ed0/32.png) [@koebane](https://discuss.elastic.co/u/koebane)\
**Post date:** [February 19, 2018, 2:50pm UTC](https://discuss.elastic.co/t/pki-authentication-cant-map-users/120385/5 "2018-02-19T14:50:11Z")

</div>

TimV,  
It looks like the default password not being set was my entire problem. Thank you very much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2018, 2:50pm UTC](https://discuss.elastic.co/t/pki-authentication-cant-map-users/120385/6 "2018-03-19T14:50:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
