# Setting up Active Directory Authentication Realm in 6.3

**URL:** <https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167>\
**Category:** Elasticsearch\
**Created:** [August 13, 2018, 12:18pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167 "2018-08-13T12:18:36Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![bigdamhero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigdamhero/32/34478_2.png) [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Post date:** [August 13, 2018, 12:18pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/1 "2018-08-13T12:18:36Z")

</div>

I have realm settings in my elasticsearch.yml, elasticsearch is working without errors (so I think) as a single node.  
I have the realms configured as follows:

```
xpack.security.authc.realms:
  realm1:
    type: native
    order: 0

  realm2:
    type: active_directory
    order: 1
    domain_name: domain.name
    url: ldaps://ad.ldap.server:636
    bind_dn: bind_dn, which works in another app.
    bind_password: thepassword
    ssl:
      certificate_authorities: ["config/ldapcert/dhp-ldap-chain.pem"]

```

: actual settings changed to protect the innocent

I am unsure how to verify that an ad/ldap login would work other than trying several things and then the only error I get is "Oops! Error. Try again." Any help would be appreciated. We are so close to getting our Platinum support set up, so I hope that will be the savior I need.

Thank you for your time and patience.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 13, 2018, 12:44pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/2 "2018-08-13T12:44:43Z")

</div>

Hi

You can try the `_authenticate` API , see [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-authenticate.html). For example, assuming you are testing on localhost and Elasticsearch is listening on 9200 (default port) you can try :

```auto
curl -uUSERNAME -X GET "http://localhost:9200/_xpack/security/_authenticate"

```

where `USERNAME` should be the `sAMAccountName` of the AD user you want to authenticate as. You should be prompted for the password and upon entering it you would either get a successful response or you can use the output/log file to get a glimpse as to what failed.

A couple of things:

- We deprecated `bind_password` in 6.3 in favor of `secure_bind_password` ( see also [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html#ref-ad-settings) ), you might want to change to this after the rest of your issues have been resolved.
- You can enable debug logging to get more insights as to what fails by adding

```auto
logger.authcldap.name = org.elasticsearch.xpack.security.authc.ldap
logger.authcldap.level = debug

```

in your `log4j2.properties` or setting a transient cluster setting with

```auto
curl -H "Content-Type: application/json" -XPUT -uelastic 'http://localhost:9200/_cluster/settings' -d'
{
  "transient" : {
      "logger.org.elasticsearch.xpack.security.authc.ldap" : "DEBUG"
   }
}'

```

```auto

```

---

<div class="post-metadata">

**Author:** ![bigdamhero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigdamhero/32/34478_2.png) [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Post date:** [August 13, 2018, 1:00pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/3 "2018-08-13T13:00:46Z")

</div>

😀😀

---

<div class="post-metadata">

**Author:** ![bigdamhero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigdamhero/32/34478_2.png) [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Post date:** [August 13, 2018, 1:18pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/4 "2018-08-13T13:18:54Z")

</div>

I am trying to work through some of these commands. It looks like I cannot use localhost and the direct IP gives this error  
:~$ curl -X GET "IPADDRESS:9200/\_xpack"  
{"error":{"root\_cause":[{"type":"security\_exception","reason":"missing authentication token for REST request [/\_xpack]","header":{"WWW-Authenticate":"Basic realm="security" charset="UTF-8""}}],"type":"security\_exception","reason":"missing authentication token for REST request [/\_xpack]","header":{"WWW-Authenticate":"Basic realm="security" charset="UTF-8""}},"status":401}user@server1:~$

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 13, 2018, 1:26pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/5 "2018-08-13T13:26:57Z")

</div>

You are missing the `-uUSERNAME` part where you actually pass the username for authenticating.

---

<div class="post-metadata">

**Author:** ![bigdamhero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigdamhero/32/34478_2.png) [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Post date:** [August 13, 2018, 3:06pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/6 "2018-08-13T15:06:19Z")

</div>

Thank you - I was trying to execute a more basic command without a username. I am checking now to see if we even have the sAMAccountName property set up on our AD. If that is NOT, then I am assuming I will need to look at the LDAP authentication setup in X-Pack.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 13, 2018, 3:11pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/7 "2018-08-13T15:11:28Z")

</div>

> sAMAccountName property set up on our AD

This is not a property. It's an [attribute in Active Directory](https://docs.microsoft.com/en-us/windows/desktop/adschema/a-samaccountname) and usually contains the username of a given user.

> [@bigdamhero](#):
>
> then I am assuming I will need to look at the LDAP authentication setup in X-Pack.

This is a good idea nevertheless. We will be here to assist, but you'd have to share a little more detail on how your AD is setup and the attributes that are available for your users.

---

<div class="post-metadata">

**Author:** ![bigdamhero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigdamhero/32/34478_2.png) [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Post date:** [August 13, 2018, 3:14pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/8 "2018-08-13T15:14:31Z")

</div>

I am trying to figure out the AD structure myself. I have a meeting with my security team soon to sort this out. Thanks.

---

<div class="post-metadata">

**Author:** ![bigdamhero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigdamhero/32/34478_2.png) [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Post date:** [August 13, 2018, 6:23pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/9 "2018-08-13T18:23:54Z")

</div>

Looks like I got it working. Now I just need to be able to add multiple LDAP Servers. What is the correct format for the load\_ballance.type setting in the yml.

realm2:  
type: active\_directory  
order: 1  
domain\_name: [somead.company.com](http://somead.company.com)  
load\_balance.type:  
dns\_round\_robin:  
ldaps://machine1.somead.company.com:636  
ldaps://machine2.somead.company.com:636  
ldaps://machine3.somead.company.com:636  
bind\_dn: CN=working\_bind DN  
bind\_password: password  
ssl:  
certificate\_authorities: ["path-to/cert.pem"]

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 14, 2018, 3:51am UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/10 "2018-08-14T03:51:39Z")

</div>

Sorry, the documentation isn't very clear here.

You want

```auto
realm2:
  type: active_directory
  order: 1
  url:
    - ldaps://machine1.somead.company.com:636
    - ldaps://machine2.somead.company.com:636
    - ldaps://machine3.somead.company.com:636
  load_balance.type: dns_round_robin
  # etc

```

---

<div class="post-metadata">

**Author:** ![bigdamhero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigdamhero/32/34478_2.png) [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Post date:** [August 14, 2018, 12:35pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/11 "2018-08-14T12:35:00Z")

</div>

I set this up, got an error, removed the "domain name:" setting. restarted and still have an error.

progne@dhpxtlmd1:~$ sudo systemctl status elasticsearch  
● elasticsearch.service - Elasticsearch  
Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled)  
Active: failed (Result: exit-code) since Tue 2018-08-14 07:22:55 CDT; 4min 12s ago  
Docs: [http://www.elastic.co](http://www.elastic.co)  
Process: 1155 ExecStart=/usr/share/elasticsearch/bin/elasticsearch -p ${PID\_DIR}/elasticsearch.pid --quiet (  
Main PID: 1155 (code=exited, status=1/FAILURE)

I cant seem to find a good mention of it in the java or app logs tho.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 14, 2018, 1:05pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/12 "2018-08-14T13:05:40Z")

</div>

You'll need to check the log file in `/var/log/elasticsearch/`

---

<div class="post-metadata">

**Author:** ![bigdamhero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigdamhero/32/34478_2.png) [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Post date:** [August 14, 2018, 5:00pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/13 "2018-08-14T17:00:47Z")

</div>

I'm not really noticing anything in that log, you meant the elasticsearch.log correct? I do see that resources are allocating to ML and I specifically have ML disabled in this Dev environment.

---

<div class="post-metadata">

**Author:** ![bigdamhero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigdamhero/32/34478_2.png) [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Post date:** [August 14, 2018, 5:02pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/14 "2018-08-14T17:02:02Z")

</div>

```
[2018-07-05T14:40:24,016][INFO][o.e.t.TransportService] [FzZRGfk] publish_address {127.0.0.1:9300}, bound_addresses {[::1]:9300}, {127.0.0.1:9300}
[2018-07-05T14:40:27,102][INFO][o.e.c.s.MasterService] [FzZRGfk] zen-disco-elected-as-master ([0] nodes joined)[,], reason: new_master {FzZRGfk}{FzZRGfkPSWaCesnexez76Q}{6u1Ye9mdS0iiSb8I_Dyf4A}{127.0.0.1}{127.0.0.1:9300}{ml.machine_memory=4124766208, xpack.installed=true, ml.max_open_jobs=20, ml.enabled=true}

```

The address seems to be wrong too? I do not have anything (that I know of) set to localhost.

---

<div class="post-metadata">

**Author:** ![bigdamhero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigdamhero/32/34478_2.png) [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Post date:** [August 14, 2018, 7:29pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/15 "2018-08-14T19:29:00Z")

</div>

Ok I can get it to work with

realm2:  
type: active\_directory  
order: 1  
domain\_name: [some.ad.comany.com](http://some.ad.comany.com)  
url:  
- ldaps://machine1.somead.company.com:636

# - ldaps://machine2.somead.company.com:636

# - ldaps://machine3.somead.company.com:636

# load\_balance.type: dns\_round\_robin

# etc

But there seems to be something wrong with the load\_ballance variable still.  
I have tried  
load\_balance:  
type: dns\_round\_robin

AND  
load\_balance.type: dns\_round\_robin

Am I missing some detail? I have gone over the .yml protocol spacing a couple of times but maybe some error?

---

<div class="post-metadata">

**Author:** ![bigdamhero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigdamhero/32/34478_2.png) [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Post date:** [August 14, 2018, 7:54pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/16 "2018-08-14T19:54:45Z")

</div>

Figured it out....  
dns\_round\_robin did not work.  
round\_robin is what I wanted.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 11, 2018, 7:54pm UTC](https://discuss.elastic.co/t/setting-up-active-directory-authentication-realm-in-6-3/144167/17 "2018-09-11T19:54:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
