# Shield AD authentication error: peer not authenticated

**URL:** <https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 7, 2016, 5:47pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012 "2016-09-07T17:47:36Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Speedman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/speedman/32/37066_2.png) [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Post date:** [September 7, 2016, 5:47pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/1 "2016-09-07T17:47:36Z")

</div>

First, the error:

[2016-09-07 13:38:32,362][WARN][shield.authc.activedirectory] [node\_test01] authentication failed for user [KibanaTest]: failed to connect to any active directory servers  
cause: com.unboundid.ldap.sdk.LDAPException: An error occurred while attempting to connect to server [mydomain.com:389](http://mydomain.com:389): java.io.IOException: Unable to verify an attempt to to establish a secure connection to '[mydomain.com:389](http://mydomain.com:389)' because an unexpected error was encountered during validation processing: javax.net.ssl.SSLPeerUnverifiedException: peer not authenticated

This is what the config looks like in elasticsearch.yml:

shield.authc.realms:  
active\_directory:  
type: active\_directory  
domain\_name: [mydomain.com](http://mydomain.com)  
url: ldaps://mydomain.com:389  
unmapped\_groups\_as\_roles: true

# Set the keystore path:

shield.ssl.keystore.path: E:\Apps\Elasticsearch\config\shield\node\_test01.jks  
shield.ssl.keystore.password: mypassword

It's running on a Windows Server 2012 R2 machine. In order to create the keystore, I exported the Root CA from the cert manager on the server and copied it into a .pem file to import. I did not include anything else because the Intermediate CA cert was identical. Our infrastructure admins confirmed that the URL and port are correct, and the Kibana credentials I entered in its config file are also correct. What else could I check? Did I miss something?

Thanks in advance for any advice.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [September 7, 2016, 5:58pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/2 "2016-09-07T17:58:34Z")

</div>

Try using port 636. Port 389 is usually plaintext

---

<div class="post-metadata">

**Author:** ![Speedman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/speedman/32/37066_2.png) [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Post date:** [September 7, 2016, 7:33pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/3 "2016-09-07T19:33:51Z")

</div>

That helped somewhat. It got me to a new error:

[2016-09-07 14:58:52,726][WARN][shield.authc.activedirectory] [node\_test01] authentication failed for user [KibanaTest]: failed to connect to any active directory servers  
cause: com.unboundid.ldap.sdk.LDAPException: An error occurred while attempting to connect to server [mydomain.com:636](http://mydomain.com:636): java.io.IOException: Hostname verification failed because the expected hostname '[mydomain.com](http://mydomain.com)' was not found in peer certificate 'subject='[CN=domaincontroller.mydomain.com](http://CN=domaincontroller.mydomain.com)' dNSName='[domaincontroller.mydomain.com](http://domaincontroller.mydomain.com)''.

Our domain is load-balanced between three DCs, and the DC that was indicated in the error message was one of them. Is this indicative of me needing to add load-balancing settings to the configuration, more information in the keystore, both, or something else? I read through the information in another question posted here ([link](https://discuss.elastic.co/t/shield-ldaps-integration-error/26451)). I tried hostname\_verification: false, but that produced read timeout errors on the socket. Any ideas?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [September 7, 2016, 8:27pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/4 "2016-09-07T20:27:02Z")

</div>

I think disabling hostname verification is the easiest solution if you would like to use the load balanced url. Otherwise maintaining a list of servers could get get out of sync. Can you share the socket exception and stracktrace?

---

<div class="post-metadata">

**Author:** ![Speedman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/speedman/32/37066_2.png) [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Post date:** [September 8, 2016, 2:01pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/5 "2016-09-08T14:01:18Z")

</div>

That error might have been transient; not sure at this point. This morning when I set it to "false" again, I am no longer seeing that error. It's a little stranger, though: it appears to be accepting my credentials, but Kibana just refreshes back to the login screen (with no messages) when I hit "Log In". I came to that conclusion because if I enter the wrong password, it gives me the invalid password message.

I will keep digging but if you have any suggestions, I would appreciate them.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [September 8, 2016, 2:22pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/6 "2016-09-08T14:22:31Z")

</div>

It could be a role mapping issue. Can you execute the following:

```
curl -u username 'http://localhost:9200/_shield/authenticate'

```

This should return the information about the user you authenticated as.

---

<div class="post-metadata">

**Author:** ![Speedman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/speedman/32/37066_2.png) [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Post date:** [September 8, 2016, 7:30pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/7 "2016-09-08T19:30:15Z")

</div>

I'm working on getting curl set up, but in the meantime, I started troubleshooting Kibana from the command line, and I'm seeing this exception on startup:

[error][status][plugin:elasticsearch] Status changed from yellow to red - [security\_exception] action [cluster:monitor/nodes/info] is unauthorized for user [KibanaTest]

edit: This is what I have in the role\_mapping.yml file and in the kibana.yml file:

role\_mapping.yml -  
kibana4\_server:

- "cn=KibanaTest,dc=mydomain,dc=com"

kibana.yml -  
elasticsearch.username: "KibanaTest"  
elasticsearch.password: "password"

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [September 9, 2016, 12:57pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/8 "2016-09-09T12:57:26Z")

</div>

I think this is a role mapping issue. There should usually be more between the `cn` and `dc` entries in the `dn` like an `ou`. If you set `shield.authc: TRACE` in the `logger` section in `config/logging.yml` file, then you should be able to see the DN of the user and groups retrieved.

---

<div class="post-metadata">

**Author:** ![Speedman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/speedman/32/37066_2.png) [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Post date:** [September 9, 2016, 3:00pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/9 "2016-09-09T15:00:09Z")

</div>

I enabled the trace and was able to pull out of that the full string for the Kibana domain user, which I swapped into the role mapping in place of what I had earlier. That seems to have mostly fixed it. I'm not getting the unauthorized error anymore, and the trace logs show a lot of "authenticated user [KibanaTest], with roles [[Log Modify Access, MyApp App Accounts, Domain Users, Users, kibana4\_server]]" entries, no errors/warnings/etc.

However, I'm still experiencing the problem with the Kibana login screen refreshing as soon as I log in. This is what I have in the role mapping file:

admin:

- "CN=My Admins,OU=My DMZ,DC=mydomain,DC=com"

This is what is shown in the trace logs:

[2016-09-09 10:47:52,072][DEBUG][shield.authc.activedirectory] [node\_test01] user not found in cache, proceeding with normal authentication  
[2016-09-09 10:47:52,197][DEBUG][shield.authc.activedirectory] [node\_test01] group SID to DN search filter: [Lots of SIDs in here]  
[2016-09-09 10:47:52,322][DEBUG][shield.authc.activedirectory] [node\_test01] found these groups [[Lots of groups in here]] for userDN [CN=My Name,OU=IT Users,DC=mydomain,DC=com]  
[2016-09-09 10:47:52,322][DEBUG][shield.authc.support] [node\_test01] the roles [[Lots of roles here]], are mapped from these [active\_directory] groups [[Same groups as above]] for realm [active\_directory/active\_directory]  
[2016-09-09 10:47:52,322][DEBUG][shield.authc.support] [node\_test01] **the roles [[]]**, are mapped from the user [active\_directory] for realm [CN=My Name,OU=IT Users,DC=mydomain,DC=com/active\_directory]  
[2016-09-09 10:47:52,338][DEBUG][shield.authc.activedirectory] [node\_test01] authenticated user [my\_user], with roles [[Same roles as above]]

The AD group that I chose to put into the role mapping file shows up in list of groups returned for my account, and the name of the group also shows up in the AD roles list as well. Why, then, does it return empty braces for the roles mapped from that? I am starting to suspect that those empty braces are why I'm not getting an "incorrect login" screen but also being kept out of the app.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [September 12, 2016, 11:33am UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/10 "2016-09-12T11:33:52Z")

</div>

> [@Speedman](#):
>
> However, I'm still experiencing the problem with the Kibana login screen refreshing as soon as I log in.

Hmm. What user are you logging into Kibana as? What roles are they given?

> [@Speedman](#):
>
> Why, then, does it return empty braces for the roles mapped from that? I am starting to suspect that those empty braces are why I'm not getting an "incorrect login" screen but also being kept out of the app.

I think the log line is a bit misleading. Roles can be mapped from group DNs and the User DN. The empty brackets is the role mapping based off of the user DN; while the one with many roles are those mapped based on the group DNs. Both sets of roles are combined when creating the user.

---

<div class="post-metadata">

**Author:** ![Speedman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/speedman/32/37066_2.png) [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Post date:** [September 12, 2016, 11:53am UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/11 "2016-09-12T11:53:30Z")

</div>

I'm logging in with my Active Directory account, which is included in the group that I mapped under the "admin" role shown in my previous post. The logs do show that, when it authenticates my account against AD, it returns that group as one of the groups assigned to my account. Ergo, it's inexplicable as to why it's not letting me in.

This is the step-by-step:

1. Update role-mapping file
2. Restart ES.
3. Start Kibana.
4. Go to localhost:5601.
5. Type in username and password.
6. Hit "Log In".
7. Page briefly flashes the Kibana startup screen ("Loading lots of code") and then displays the login screen again.

Right now I don't have SSL set up on Kibana (i.e. using http:// instead of https://); working with one of our infrastructure guys to get the CSR signed so I can install it and start using https. Is it possible that this is somehow complicit in the problem here?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [September 12, 2016, 12:22pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/12 "2016-09-12T12:22:09Z")

</div>

> [@Speedman](#):
>
> Right now I don't have SSL set up on Kibana (i.e. using http:// instead of https://); working with one of our infrastructure guys to get the CSR signed so I can install it and start using https. Is it possible that this is somehow complicit in the problem here?

That would have been my next question. Yes I believe it is the culprit here. The cookie that kibana uses has the secure flag set, which browsers will only send via a HTTPS connection.

---

<div class="post-metadata">

**Author:** ![Speedman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/speedman/32/37066_2.png) [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Post date:** [September 12, 2016, 12:33pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/13 "2016-09-12T12:33:50Z")

</div>

Okay. That makes sense. I'll post a new topic if I still have trouble after that's installed and configured; the main question here has been answered. Thanks for your help! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:41pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012/14 "2017-07-06T13:41:53Z")

</div>


