# PKI realm rolemapping

**URL:** <https://discuss.elastic.co/t/pki-realm-rolemapping/201481>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 28, 2019, 7:07am UTC](https://discuss.elastic.co/t/pki-realm-rolemapping/201481 "2019-09-28T07:07:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rnataraja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rnataraja/32/26255_2.png) [@rnataraja](https://discuss.elastic.co/u/rnataraja)\
**Post date:** [September 28, 2019, 7:07am UTC](https://discuss.elastic.co/t/pki-realm-rolemapping/201481/1 "2019-09-28T07:07:00Z")

</div>

Hello:

Iam trying to use the PKI realm and derive roles and mappings from the CN as follows. Is it possible to do this? This is with ES 6.8.3.

In the role\_mapping.yaml

power\_user:

- "cn=power\_\*,ou=example,o=com"

And in the roles.yaml specify as follows

power\_user:  
cluster: ['monitor', 'manage\_index\_templates']  
indices:  
- names: ['power\_\*']  
privileges: ['all']

Thanks in Advance  
Rajesh

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 29, 2019, 10:38am UTC](https://discuss.elastic.co/t/pki-realm-rolemapping/201481/2 "2019-09-29T10:38:21Z")

</div>

> [@rnataraja](#):
>
> In the role\_mapping.yaml
> 
> power\_user:
> 
> - "cn=power\_\*,ou=example,o=com"

You can't do this with the role mapping file as it doesn't support wildcards, but you can do this with the [Role Mapping API](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/security-api-put-role-mapping.html) which is also the preferred way to manage role mappings.

```auto
POST /_security/role_mapping/power_user_mapping
{
  "roles": ["power_user"],
  "enabled": true,
  "rules": {
    "field" : { "dn": "cn=power_*,ou=example,o=com" }
  }
}

```

> [@rnataraja](#):
>
> And in the roles.yaml specify as follows
> 
> power\_user:  
> cluster: ['monitor', 'manage\_index\_templates']  
> indices:
> 
> - names: ['power\_\*']  
> privileges: ['all']

yes, you can do that, but you could also use the [Create Roles API](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/security-api-put-role.html) that is the preferred way to manage roles.

---

<div class="post-metadata">

**Author:** ![rnataraja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rnataraja/32/26255_2.png) [@rnataraja](https://discuss.elastic.co/u/rnataraja)\
**Post date:** [September 30, 2019, 3:11am UTC](https://discuss.elastic.co/t/pki-realm-rolemapping/201481/3 "2019-09-30T03:11:53Z")

</div>

Thanks @ikakavas , Will try it out.

---

<div class="post-metadata">

**Author:** ![rnataraja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rnataraja/32/26255_2.png) [@rnataraja](https://discuss.elastic.co/u/rnataraja)\
**Post date:** [October 2, 2019, 7:21am UTC](https://discuss.elastic.co/t/pki-realm-rolemapping/201481/4 "2019-10-02T07:21:34Z")

</div>

@ikakavas  
I cant seem to get around this message, what am I doing wrong? This is ES 6.8.3.

"error" : {  
"root\_cause" : [  
{  
"type" : "security\_exception",  
"reason" : "missing authentication token for REST request [/\_cat/indices?pretty]",  
"header" : {  
"WWW-Authenticate" : [  
"Bearer realm="security"",  
"ApiKey",  
"Basic realm="security" charset="UTF-8""  
]  
}  
}  
],  
"type" : "security\_exception",  
"reason" : "missing authentication token for REST request [/\_cat/indices?pretty]",  
"header" : {  
"WWW-Authenticate" : [  
"Bearer realm="security"",  
"ApiKey",  
"Basic realm="security" charset="UTF-8""  
]  
}  
}

My Subject in certificiate is

Subject: O=ApplicationServer, O=TEST, CN=power\_testserver

And My roles.yaml file is

power\_infra\_user:  
cluster: ['monitor', 'manage\_index\_templates']  
indices:  
- names: ['power\_\*']  
privileges: ['all']

And Role Mapping invoked through the API is  
curl -k -u 'test:iamsuperuser' [https://127.0.0.1:9200/\_security/role\_mapping/power\_infra\_role\_mapping](https://127.0.0.1:9200/_security/role_mapping/power_infra_role_mapping)  
{"power\_infra\_role\_mapping":{"enabled":true,"roles":["power\_infra\_user"],"rules":{"field":{"dn":"cn=power\_testserver,ou=ApplicationServer,o=TEST"}},"metadata":{}}}

And I have the following xpack config

xpack.security.enabled: true  
xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.key: /usr/share/elasticsearch/config/certs/service/server.key  
xpack.security.transport.ssl.certificate: /usr/share/elasticsearch/config/certs/service/server.crt  
xpack.security.transport.ssl.certificate\_authorities: ["/usr/share/elasticsearch/config/certs/service/ca.crt"]  
xpack.security.http.ssl.enabled: true  
xpack.security.http.ssl.key: /usr/share/elasticsearch/config/certs/service/server.key  
xpack.security.http.ssl.certificate: /usr/share/elasticsearch/config/certs/service/server.crt  
xpack.security.http.ssl.certificate\_authorities: ["/usr/share/elasticsearch/config/certs/service/ca.crt"]

xpack:  
security:  
authc:  
realms:  
pki1:  
type: pki  
order: 0  
file1:  
type: file  
order: 1

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 2, 2019, 7:44am UTC](https://discuss.elastic.co/t/pki-realm-rolemapping/201481/5 "2019-10-02T07:44:44Z")

</div>

a) PKI Realm is not available in basic, you need a trial license or a gold/platinum one.  
b) Please read through our docs [https://www.elastic.co/guide/en/elasticsearch/reference/6.8/configuring-pki-realm.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/configuring-pki-realm.html) . There are definitely things you have missed, including setting `client_authentication` for http.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 30, 2019, 7:44am UTC](https://discuss.elastic.co/t/pki-realm-rolemapping/201481/6 "2019-10-30T07:44:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
