# Problem adding AD users to roles

**URL:** <https://discuss.elastic.co/t/problem-adding-ad-users-to-roles/50895>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 24, 2016, 11:57pm UTC](https://discuss.elastic.co/t/problem-adding-ad-users-to-roles/50895 "2016-05-24T23:57:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dave\_G](https://avatars.discourse-cdn.com/v4/letter/d/c68b51/32.png) [@Dave\_G](https://discuss.elastic.co/u/Dave_G)\
**Post date:** [May 24, 2016, 11:57pm UTC](https://discuss.elastic.co/t/problem-adding-ad-users-to-roles/50895/1 "2016-05-24T23:57:40Z")

</div>

I'm trying to a new Shield installation going on our ES (2.2.1) cluster, and am running into a problem with Active Directory users that has me stumped. I have successfully added a single AD group to a Shield role with the following role\_mapping.yml file:

> admin:
> 
> - "cn=Domain Admins,cn=Builtin,dc=example,dc=com"

That's the entire file, and anyone in the Domain Admins group is authorized with admin access. So far, so good.

But the problem comes when I add an additional user to the admin role:

> admin:
> 
> - "cn=Domain Admins,cn=Builtin,dc=example,dc=com"
> - "cn=Smith, John Q.,cn=Users,dc=example,dc=com"

Not only is the new user not authorized, but none of the Domain Admins are authorized any more either:

> curl -u admin -XGET 'localhost:9200/\_cluster/health?pretty'

> "error" : {  
> "root\_cause" : [ {  
> "type" : "security\_exception",  
> "reason" : "action [cluster:monitor/health] is unauthorized for user [admin]"

So what's wrong with the additional line, and why is it breaking authorization for other users?

Dave

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [May 25, 2016, 11:35am UTC](https://discuss.elastic.co/t/problem-adding-ad-users-to-roles/50895/2 "2016-05-25T11:35:30Z")

</div>

Hi Dave,

That is really odd. The escaping looks correct to me. Do you see any log messages in your log file like the ones below?

```
failed to parse role mappings file [/path/to/role_mapping.yml]. skipping/removing all mappings...

invalid DN [...] found in [active_directory] role mappings [/path/to/role_mapping.yml] for realm [...]. skipping... 

```

Jay

---

<div class="post-metadata">

**Author:** ![Dave\_G](https://avatars.discourse-cdn.com/v4/letter/d/c68b51/32.png) [@Dave\_G](https://discuss.elastic.co/u/Dave_G)\
**Post date:** [May 25, 2016, 12:59pm UTC](https://discuss.elastic.co/t/problem-adding-ad-users-to-roles/50895/3 "2016-05-25T12:59:46Z")

</div>

I figured it out. The log file contained the following:

> failed to parse role mappings file [/etc/elasticsearch/shield/role\_mapping.yml]. skipping/removing all mappings...  
> SettingsException[Failed to load settings from [/etc/elasticsearch/shield/role\_mapping.yml]]; nested: ScannerException[while scanning a double-quoted scalar  
> in 'reader', line 17, column 5:  
> - "cn=Smith, John Q.,cn=Users, ...
> 
> found unknown escape character ,(44)  
> in 'reader', line 17, column 17:  
> - "cn=Smith, John Q.,cn=Users,dc=example ...

I had wondered if the escaped comma might have been causing problems, but I hadn't considered that it might only occur in a double-quoted string. So I converted them to single-quoted strings:

> admin:
> 
> - 'cn=Domain Admins,cn=Builtin,dc=example,dc=com'
> - 'cn=Smith, John Q.,cn=Users,dc=example,dc=com'

And now everything is working as expected. So it seems that the "" escape character is interpreted in a single-quoted string, but not in a double-quoted string. I would have expected it to be the other way around.

Dave

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/problem-adding-ad-users-to-roles/50895/4 "2017-07-06T13:44:34Z")

</div>


