# ShieldによるAD連携

**URL:** <https://discuss.elastic.co/t/shield-ad/50104>\
**Category:** 日本語による質問・議論はこちら\
**Created:** [May 16, 2016, 9:16am UTC](https://discuss.elastic.co/t/shield-ad/50104 "2016-05-16T09:16:23Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![kurio](https://avatars.discourse-cdn.com/v4/letter/k/65b543/32.png) [@kurio](https://discuss.elastic.co/u/kurio)\
**Post date:** [May 16, 2016, 9:16am UTC](https://discuss.elastic.co/t/shield-ad/50104/1 "2016-05-16T09:16:23Z")

</div>

ご教示お願い致します。

Shieldの認証でAD連携を試みているのですが、一通り設定した後Kibanaにアクセスすると「plugin:elasticsearch Authentication Exception」と出てきます。

KibanaとElasticsearchがうまく連携できてないとは思うのですが・・・

以下、各設定ファイル名とその内容でございます。

## ----elasticsearch.yml---- shield: authc: realms: active\_directory: type: active\_directory order: 0 domain\_name: example.local url: ldaps://\*\*\*.\*\*\*.\*\*\*.\*\*\*:389 unmapped\_groups\_as\_roles: true

## --------kibana.yml-------- elasticsearch.username: "kibana4\_server" elasticsearch.password: "hoge"

--------role\_mapping.yml--------  
#roles.ymlで定義したadminユーザ  
admin:

- "cn=taro.tanaka,dc=example,dc=local"

#roles.ymlで定義した読み取り用ユーザ  
readuser:

- "cn=ziro.suzuki,dc=example,dc=local"
- "cn=tosio.satou,dc=example,dc=local"

#ElasticとKibanaを連携する用のアカウント  
kibana4\_server:

- "cn=Administrator,cn=KibanaServer,dc=example,dc=local"

* * *

------------roles.yml------------

# adminロール

admin:  
cluster:  
- all  
indices:  
- names: '\*'  
privileges:  
- all

# read only のユーザロール

readuser:  
indices:  
- names: 'active-_'  
privileges:  
- read  
- names: '.kibana_'  
privileges:  
- manage  
- read

# The required permissions for the kibana 4 server

## kibana4\_server: cluster: - monitor indices: - names: '.kibana' privileges: - all

以下、参考ドキュメント  
【Shield [2.3] \> User Authentication \> Active Directory User Authentication】  
[https://www.elastic.co/guide/en/shield/current/active-directory-realm.html](https://www.elastic.co/guide/en/shield/current/active-directory-realm.html)

【Shield [2.3] \> Configuring Clients and Integrations \> Using Kibana with Shield】  
[https://www.elastic.co/guide/en/shield/current/kibana.html](https://www.elastic.co/guide/en/shield/current/kibana.html)

今回のエラーとは関係ないと思いますが一応ELKサーバとADはPing疎通OKです。

よろしくお願い致します。

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [May 16, 2016, 9:55am UTC](https://discuss.elastic.co/t/shield-ad/50104/2 "2016-05-16T09:55:40Z")

</div>

まずは、Kibanaからではなく、Elasticsearchで連携できているかをcurlコマンドなどで確認してはどうでしょうか？

参考：  
[https://www.elastic.co/guide/en/shield/current/enable-basic-auth.html](https://www.elastic.co/guide/en/shield/current/enable-basic-auth.html)

---

<div class="post-metadata">

**Author:** ![kurio](https://avatars.discourse-cdn.com/v4/letter/k/65b543/32.png) [@kurio](https://discuss.elastic.co/u/kurio)\
**Post date:** [May 19, 2016, 1:46am UTC](https://discuss.elastic.co/t/shield-ad/50104/3 "2016-05-19T01:46:04Z")

</div>

改修点  
・AD側でkibana4\_serverというsAMAccount (ユーザ) を作成、パスワードはhoge  
・[kibana.ymlの内容でelasticsearch.name](http://kibana.xn--ymlelasticsearch-og4o3dt924euwtb.name): kibana4\_server  
elasticsearch.password: hoge に変更  
・elasticsearch.ymlの内容でunmapped\_groups\_as\_roles: trueをコメントアウト  
・role.mapping.ymlの内容でkibana4\_server  
- "cn=kibana4\_server,dc=example,dc=local" に変更

以下、確認内容です

[root@elk ~]# curl -u kibana4\_server:hoge -XGET '[http://localhost:9200/](http://localhost:9200/)'  
{"error":{"root\_cause":[{"type":"security\_exception","reason":"unable to authenticate user [kibana4\_server] for REST request [/]","header":{"WWW-Authenticate":"Basic realm="shield""}}],"type":"security\_exception","reason":"unable to authenticate user [kibana4\_server] for REST request [/]","header":{"WWW-Authenticate":"Basic realm="shield""}},"status":401}

ユーザを認証する事ができないという事は、ElasticSearchとADが連携できていなそうですね。  
elasticsearch.ymlのshield: 部分がおかしいのでしょうか・・・？

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [May 21, 2016, 4:28am UTC](https://discuss.elastic.co/t/shield-ad/50104/4 "2016-05-21T04:28:06Z")

</div>

Elasticsearchのログには何か出てないでしょうか？

---

<div class="post-metadata">

**Author:** ![kurio](https://avatars.discourse-cdn.com/v4/letter/k/65b543/32.png) [@kurio](https://discuss.elastic.co/u/kurio)\
**Post date:** [May 23, 2016, 11:10am UTC](https://discuss.elastic.co/t/shield-ad/50104/5 "2016-05-23T11:10:11Z")

</div>

elasticsearch.logの内容

[2016-05-23 19:45:23,573][INFO][gateway] [Lupa] recovered [3] indices into cluster\_state  
[2016-05-23 19:45:24,484][INFO][cluster.routing.allocation] [Lupa] Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[.kibana][0]] ...]).

ブラウザでIPを入力しKibanaを開くと以下エラー  
[security\_exception] action [cluster:monitor/nodes/info] is unauthorized for user [\<ユーザ名\>]

shieldを使う場合、kibanaへのアクセスをhttpsにしないとダメでしたっけ。

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [May 27, 2016, 6:31am UTC](https://discuss.elastic.co/t/shield-ad/50104/6 "2016-05-27T06:31:34Z")

</div>

> [@kurio](#):
>
> shieldを使う場合、kibanaへのアクセスをhttpsにしないとダメでしたっけ。

いえ、そんなことはありません。  
curlでアクセスした時にログは出てないでしょうか？  
ただ、curlコマンドのレスポンスを見ると、認証に失敗しているので、ADでの認証に失敗しているのではないかと。

---

<div class="post-metadata">

**Author:** ![kurio](https://avatars.discourse-cdn.com/v4/letter/k/65b543/32.png) [@kurio](https://discuss.elastic.co/u/kurio)\
**Post date:** [June 1, 2016, 3:01am UTC](https://discuss.elastic.co/t/shield-ad/50104/7 "2016-06-01T03:01:14Z")

</div>

SecurityExceptionでunable to authenticateが出ます。ADと上手く連携できていなそうです。

各種ymlとconfigがぐちゃぐちゃしているのでキレイに整理してみます。

shieldを一旦止める場合はどのような作業が必要か教えて頂けますでしょうか。

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [June 3, 2016, 2:04am UTC](https://discuss.elastic.co/t/shield-ad/50104/8 "2016-06-03T02:04:55Z")

</div>

> 

url: ldaps://_ **...** _:389

に関してですが、ドキュメントでは、`ldap`となっていますが、そこが間違っている可能性はないでしょうか？

```auto
If you don’t specify the URL, it defaults to ldap:<domain_name>:389.

```

あと、オフにする場合はAnonymousでのアクセスを設定したり、  
一旦、アンインストールしていただいたり、くのが良いかと。

- [Enabling Anonymous Access | Shield [2.4] | Elastic](https://www.elastic.co/guide/en/shield/current/anonymous-access.html)
- [Installing Shield | Shield [2.4] | Elastic](https://www.elastic.co/guide/en/shield/current/installing-shield.html#uninstalling-shield)

あと、設定ファイルやExceptionなどのログに関しては、全体（ログはExceptionの部分を全部とその前後）を提示していただかないと助言がしにくいです。  
次回からは、ログを貼り付けたりしていただけますでしょうか？

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:47pm UTC](https://discuss.elastic.co/t/shield-ad/50104/9 "2017-07-06T13:47:51Z")

</div>


