# Role\_mapping file not able to point users if it does not have full DN

**URL:** <https://discuss.elastic.co/t/role-mapping-file-not-able-to-point-users-if-it-does-not-have-full-dn/207812>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 14, 2019, 5:44am UTC](https://discuss.elastic.co/t/role-mapping-file-not-able-to-point-users-if-it-does-not-have-full-dn/207812 "2019-11-14T05:44:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksarkar](https://avatars.discourse-cdn.com/v4/letter/k/ee7513/32.png) [@ksarkar](https://discuss.elastic.co/u/ksarkar)\
**Post date:** [November 14, 2019, 5:44am UTC](https://discuss.elastic.co/t/role-mapping-file-not-able-to-point-users-if-it-does-not-have-full-dn/207812/1 "2019-11-14T05:44:17Z")

</div>

While configuring Elastcsearch with LDAP authentication, I am able to connect LDAP users and getting authenticated as per following configuration.

# elasticsearch.yml ,

```auto
xpack:
  security:
    authc:
      realms:
        ldap:
          ldap1:
            order: 0
            url: "ldap://192.168.56.101:389"
            user_dn_templates:
              - "uid={0},ou=People,dc=example,dc=com"
              - "uid={0},cn=guiusers,dc=example,dc=com"
            group_search:
              base_dn: "dc=example,dc=com"

```

# and below is role\_mapping.yml entry,

```auto
monitoring: 
  - "ou=People,dc=example,dc=com"
  - "uid=engineer,ou=People,dc=example,dc=com"

```

now, I have 2 users (ksarkar,engineer) under LDAP location cn=guiusers,dc=example,dc=com.  
but both the user not present locally in Kibana users.

using above configuration,  
I can connect "engineer" but not getting connected "ksarkar". Having received the same below error in browser for ksarkar (not present in role\_mapping.yml),

`{"statusCode":403,"error":"Forbidden","message":"Forbidden"}`

Is that mandatory to map every user in "role\_mapping.yml" file ?

If not then what would be the correct configuration which will facilitate log-in from Kibana GUI, where,

1. Users only present in LDAP.
2. Role \<\> group mapped in role\_mapping.yml file till gorup not user.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 14, 2019, 6:35am UTC](https://discuss.elastic.co/t/role-mapping-file-not-able-to-point-users-if-it-does-not-have-full-dn/207812/2 "2019-11-14T06:35:05Z")

</div>

You can either use user DNs or group DNs in the role mapping file. `engineer` works because you mention that user DN explicitly (`"uid=engineer,ou=People,dc=example,dc=com"`)  
`ou=People,dc=example,dc=com` is an Organizational Unit and not a Group though and you can't use an OU to say "everyone under this OU should get the role"

> [@ksarkar](#):
>
> If not then what would be the correct configuration which will facilitate log-in from Kibana GUI, where,
> 
> 1. Users only present in LDAP.
> 2. Role \<\> group mapped in role\_mapping.yml file till gorup not user.

Add all the users you want to an LDAP Group and reference that group DN in the role mapping file

---

<div class="post-metadata">

**Author:** ![ksarkar](https://avatars.discourse-cdn.com/v4/letter/k/ee7513/32.png) [@ksarkar](https://discuss.elastic.co/u/ksarkar)\
**Post date:** [November 14, 2019, 2:20pm UTC](https://discuss.elastic.co/t/role-mapping-file-not-able-to-point-users-if-it-does-not-have-full-dn/207812/3 "2019-11-14T14:20:32Z")

</div>

Thank you. Let me try this.

---

<div class="post-metadata">

**Author:** ![ksarkar](https://avatars.discourse-cdn.com/v4/letter/k/ee7513/32.png) [@ksarkar](https://discuss.elastic.co/u/ksarkar)\
**Post date:** [November 18, 2019, 8:35am UTC](https://discuss.elastic.co/t/role-mapping-file-not-able-to-point-users-if-it-does-not-have-full-dn/207812/4 "2019-11-18T08:35:15Z")

</div>

as mentioned above, I created two user in my LDAP server as below,

> uid=maxdev,cn=Users,ou=Group,dc=example,dc=com  
> uid=techdev,cn=Users,ou=Group,dc=example,dc=com

role mapping table entry is,

> monitoring:
> 
> - "cn=Users,ou=Group,dc=example,dc=com"
> - "uid=techdev,cn=Users,ou=Group,dc=example,dc=com"
> - "uid=ksarkar,cn=guiusers,dc=example,dc=com"

elasticsearch.yml x-paxk conf entry,

> xpack:  
> security:  
> authc:  
> realms:  
> ldap:  
> ldap1:  
> order: 0  
> url: "ldap://192.168.56.101:389"  
> user\_dn\_templates:  
> - "uid={0},cn=Users,ou=Group,dc=example,dc=com"  
> - "cn={0},cn=Admins,ou=Group,dc=example,dc=com"  
> - "cn={0},cn=Manager,ou=Group,dc=example,dc=com"  
> - "uid={0},ou=People,dc=example,dc=com"  
> group\_search:  
> base\_dn: "dc=example,dc=com"

When I mention user full DN it elasticsearch can map group but in case of uid under group (not mentioning full DN) it cant relate the group.

```
engineer@~ $ > curl -u techdev:techdev -X GET "http://192.168.56.101:9200/_xpack/security/_authenticate"
{"username":"techdev","roles":["monitoring"],"full_name":null,"email":null,"metadata":{"ldap_dn":"uid=techdev,cn=Users,ou=Group,dc=example,dc=com","ldap_groups":[]},"enabled":true,"authentication_realm":{"name":"ldap1","type":"ldap"},"lookup_realm":{"name":"ldap1","type":"ldap"}}

engineer@~ $ > curl -u maxdev:maxdev -X GET "http://192.168.56.101:9200/_xpack/security/_authenticate" {"username":"maxdev","roles":[],"full_name":null,"email":null,"metadata":{"ldap_dn":"uid=maxdev,cn=Users,ou=Group,dc=example,dc=com","ldap_groups":[]},"enabled":true,"authentication_realm":{"name":"ldap1","type":"ldap"},"lookup_realm":{"name":"ldap1","type":"ldap"}}

```

Can anyone please help on this ?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 18, 2019, 11:12am UTC](https://discuss.elastic.co/t/role-mapping-file-not-able-to-point-users-if-it-does-not-have-full-dn/207812/5 "2019-11-18T11:12:37Z")

</div>

> [@ksarkar](#):
>
> as mentioned above, I created two user in my LDAP server as below,
> 
> > uid=maxdev,cn=Users,ou=Group,dc=example,dc=com  
> > uid=techdev,cn=Users,ou=Group,dc=example,dc=com

This is not how LDAP groups work , you just created an Organizational Unit that you named `Group` and you put your users under it.

This is basically a question of how to setup your LDAP directory and LDAP internals are slightly outside the scope of these forums. I'd start from here: [https://ldapwiki.com/wiki/LDAP%20Group](https://ldapwiki.com/wiki/LDAP%20Group) and read through to gain some basic understanding.

---

<div class="post-metadata">

**Author:** ![ksarkar](https://avatars.discourse-cdn.com/v4/letter/k/ee7513/32.png) [@ksarkar](https://discuss.elastic.co/u/ksarkar)\
**Post date:** [November 18, 2019, 1:39pm UTC](https://discuss.elastic.co/t/role-mapping-file-not-able-to-point-users-if-it-does-not-have-full-dn/207812/6 "2019-11-18T13:39:33Z")

</div>

Thanks you loannis for pointing out the issue.

Setting top level one as group in LDAP resolves the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 16, 2019, 1:39pm UTC](https://discuss.elastic.co/t/role-mapping-file-not-able-to-point-users-if-it-does-not-have-full-dn/207812/7 "2019-12-16T13:39:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
