# Problems after trying to setup realms

**URL:** <https://discuss.elastic.co/t/problems-after-trying-to-setup-realms/172222>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 13, 2019, 11:17pm UTC](https://discuss.elastic.co/t/problems-after-trying-to-setup-realms/172222 "2019-03-13T23:17:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [March 13, 2019, 11:17pm UTC](https://discuss.elastic.co/t/problems-after-trying-to-setup-realms/172222/1 "2019-03-13T23:17:31Z")

</div>

On elasticsearch 6.6.1, we were trying to add a realm for our active directory environment.

We first added something similar to this:

> xpack:  
> security:  
> authc:  
> realms:  
> native1:  
> type: native  
> order: 0  
> ldap1:  
> type: ldap  
> order: 1  
> url: "ldaps://ldap.sanitized.edu:3269"  
> .....snip.....

Pretty much per the example, just changing our environment. We configured role\_mapping.yml, started elasticsearch but got this error....

> parsed [0] roles from file [/etc/elasticsearch/roles.yml]

After some stumbles, we realized we should be using the active\_directory type, so we changed the elasticsearch.yml to:

> xpack:  
> security:  
> authc:  
> realms:  
> native1:  
> type: native  
> order: 0  
> active\_directory:  
> type: active\_directory  
> order: 1  
> domain\_name: also.sanitized.edu  
> url: "ldaps://ldap.sanitized.edu:3269"  
> bind\_dn: our\_bind\_guy@sanitized.edu

Now we get errors like:

> missing realm type [xpack.security.authc.realms.ldap1.type] for realm

That is confusing, the string "ldap1" exists nowhere in /etc/elasticsearch, verified by grep. Has elasticsearch saved some of this bad realm info in it's database?

We are stuck, we're going to move to a more expendable stack and start over, but I would like to get this stack back if possible.

Thanks.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 13, 2019, 11:30pm UTC](https://discuss.elastic.co/t/problems-after-trying-to-setup-realms/172222/2 "2019-03-13T23:30:47Z")

</div>

Can you please format Yaml as a code block (the `</>` button) rather than a block quote.  
Whitespace is important in Yaml and it's impossible to know what your config looks like if the space is stripped.

> [@rugenl](#):
>
> got this error....
> 
> ```auto
> parsed [0] roles from file [/etc/elasticsearch/roles.yml]
> 
> ```

That's not an error. The bit of the log that you stripped off from the beginnning says that it is an `INFO` message.

```auto
[2019-03-13T12:34:56,789][INFO][o.e.x.s.a.s.FileRolesStore] [node01] parsed [0] roles from file [/etc/elasticsearch/roles.yml]

```

Info messages are helpful for diagnosing problems when something goes wrong, but you shouldn't read them as a sign that there's a problem.

> [@rugenl](#):
>
> missing realm type [xpack.security.authc.realms.ldap1.type] for realm

Check your keystore:

```auto
bin/elasticsearch-keystore list

```

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [March 14, 2019, 1:34am UTC](https://discuss.elastic.co/t/problems-after-trying-to-setup-realms/172222/3 "2019-03-14T01:34:21Z")

</div>

OK, this is the fix

`elasticsearch-keystore remove xpack.security.authc.realms.ldap1.secure_bind_password`

I knew we left it in there, I just guessed it wouldn't be referenced.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2019, 1:34am UTC](https://discuss.elastic.co/t/problems-after-trying-to-setup-realms/172222/4 "2019-04-11T01:34:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
