# Shield and LDAP configuration

**URL:** <https://discuss.elastic.co/t/shield-and-ldap-configuration/34114>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 8, 2015, 5:03pm UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114 "2015-11-08T17:03:39Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![gustav](https://avatars.discourse-cdn.com/v4/letter/g/919ad9/32.png) [@gustav](https://discuss.elastic.co/u/gustav)\
**Post date:** [November 8, 2015, 5:03pm UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/1 "2015-11-08T17:03:39Z")

</div>

Hello. I'm trying to configure Shield to authenticate ES users via LDAP. Our company has a domain, for example: [company.com](http://company.com). And we have groups like "IT", "Finance", "Tech". But I need authenticate users only from IT. We have the LDAP server on the address [ldap.company.com:389](http://ldap.company.com:389).

Trying something like this:

> shield.authc:  
> realms:  
> ldap1:  
> type: ldap  
> order: 0  
> url: "ldaps://ldap.company.com:389"  
> bind\_dn: "cn=reader,ou=company,dc=company,dc=com"  
> group\_search:  
> base\_dn: "dc=company,dc=com"  
> filter: "(memberOf=cn=IT,ou=company,dc=company,dc=com)'"  
> files:  
> role\_mapping: "/elasticsearch/config/shield/role\_mapping.yml"  
> unmapped\_groups\_as\_roles: false

But it is not working. Shield version: 1.3.2

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 8, 2015, 11:08pm UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/2 "2015-11-08T23:08:06Z")

</div>

> [@gustav](#):
>
> But it is not working

Can you elaborate more here, what is not working?  
Have you turned on lower logging levels?

---

<div class="post-metadata">

**Author:** ![gustav](https://avatars.discourse-cdn.com/v4/letter/g/919ad9/32.png) [@gustav](https://discuss.elastic.co/u/gustav)\
**Post date:** [November 9, 2015, 1:57am UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/3 "2015-11-09T01:57:35Z")

</div>

@warkolm I have this config from our another project:

> host: '[ldap.company.com](http://ldap.company.com)'  
> base: 'dc=company,dc=com'  
> port: 389  
> uid: 'SAMAccountName'  
> bind\_dn: 'cn=reader,ou=company,dc=company,dc=com'  
> user\_filter: '(memberOf=cn=IT,ou=company,dc=company,dc=com)'

I'm failing at "filter" step. How to add uid to shield config?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [November 10, 2015, 4:26pm UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/4 "2015-11-10T16:26:48Z")

</div>

Hi @gustav,

The LDAP realms do no support a user specified filter for looking up users. Are you connecting to Active Directory? If you are using active directory, then there is a way that we could possibly limit the users who can authenticate.

If not, could you rely on authorization failing (ie only the IT group is mapped to a role)?

-Jay

---

<div class="post-metadata">

**Author:** ![gustav](https://avatars.discourse-cdn.com/v4/letter/g/919ad9/32.png) [@gustav](https://discuss.elastic.co/u/gustav)\
**Post date:** [November 11, 2015, 8:12am UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/5 "2015-11-11T08:12:42Z")

</div>

@jaymode thank you for answer. I am connecting to corporate LDAP server. I don't need to authenticate a specific user. Can you give me an example of ldap realm config? For example, how to authenticate all users that are members of IT group and .company.com domain? I have stucked here.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [November 11, 2015, 11:07am UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/6 "2015-11-11T11:07:26Z")

</div>

@gustav I know you said LDAP, but it looks like you may be connecting to an AD schema since you have `SAMAccountName` as the uid value in your other configuration, which is typically associated with active directory.

Can you try the following configuration:

```
shield.authc.realms:
  ad1:
    type: active_directory
    order: 0
    url: "ldaps://ldap.company.com:389"
    domain_name: company.com
    user_search:
      filter: (&(objectClass=user)(sAMAccountName={0})(memberOf=cn=IT,ou=company,dc=company,dc=com))

```

If the above configuration does not work, then currently we cannot support limiting the users allowed to authenticate via a filter, but we can work on adding an enhancement for this.

---

<div class="post-metadata">

**Author:** ![gustav](https://avatars.discourse-cdn.com/v4/letter/g/919ad9/32.png) [@gustav](https://discuss.elastic.co/u/gustav)\
**Post date:** [November 11, 2015, 12:15pm UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/7 "2015-11-11T12:15:55Z")

</div>

@jaymode thank you. I will test it as soon as possible.

---

<div class="post-metadata">

**Author:** ![gustav](https://avatars.discourse-cdn.com/v4/letter/g/919ad9/32.png) [@gustav](https://discuss.elastic.co/u/gustav)\
**Post date:** [November 13, 2015, 12:08pm UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/8 "2015-11-13T12:08:46Z")

</div>

@jaymode hi. This config is not working for me. Or I am doing something wrong.  
My role\_mapping.yml:

> admin:
> 
> - "cn=IT,dc=company,dc=com"

> user:
> 
> - "cn=IT,dc=company,dc=com"

I need to authenticate all users from IT group. From domain: [company.com](http://company.com)  
When I am quering to Elasticsearch via curl:

> curl -XGET [someuser@company.com](mailto:someuser@company.com):somepassword@localhost:9200/

it tells me:

> {"error":"AuthenticationException[unable to authenticate user [someuser] for REST request [/]]","status":401}

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [November 13, 2015, 12:41pm UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/9 "2015-11-13T12:41:54Z")

</div>

Have you tried with just `someuser` instead of `someuser@company.com`? Also, can you try turning the logging up to trace and see what kind of errors are happening when you try to authenticate?

---

<div class="post-metadata">

**Author:** ![gustav](https://avatars.discourse-cdn.com/v4/letter/g/919ad9/32.png) [@gustav](https://discuss.elastic.co/u/gustav)\
**Post date:** [November 16, 2015, 4:22am UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/10 "2015-11-16T04:22:32Z")

</div>

@jaymode I have enabled Shield's auditing. elasticsearch-access.log has the following record:  
[2015-11-16 10:17:34,344] [Baron Macabre] [rest] [authentication\_failed] origin\_address=[/0:0:0:0:0:0:0:1:52136], principal=[someuser@company.com], uri=[/]

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [November 16, 2015, 2:08pm UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/11 "2015-11-16T14:08:31Z")

</div>

@gustav sorry for the confusion, can you enable trace for the regular elasticsearch log file and provide the exceptions you get there? Also, did you try with just `someuser` instead of `someuser@company.com`?

---

<div class="post-metadata">

**Author:** ![gustav](https://avatars.discourse-cdn.com/v4/letter/g/919ad9/32.png) [@gustav](https://discuss.elastic.co/u/gustav)\
**Post date:** [November 17, 2015, 12:36pm UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/12 "2015-11-17T12:36:25Z")

</div>

@jaymode hi. Yes, I have tried. I cannot set logs to TRACE mode right now. But... I have the following in the old logs from Elasticsearch:

> [2015-11-12 12:55:36,473][WARN][shield.authc.activedirectory] [She-Venom] authentication failed for user [someuser]: failed to connect to any active directory servers  
> cause: com.unboundid.ldap.sdk.LDAPException: An error occurred while attempting to connect to server [ldap.company.com:389](http://ldap.company.com:389): java.io.IOException: Unable to verify an attempt to to establish a secure connection to '[ldap.company.com:389](http://ldap.company.com:389)' because an unexpected error was encountered during validation processing: javax.net.ssl.SSLPeerUnverifiedException: peer not authenticated

Our LDAP is protected by SSL. Should I set hostname\_verification parameter to FALSE?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [November 17, 2015, 1:14pm UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/13 "2015-11-17T13:14:34Z")

</div>

Do you have the signing CA or certificates for your ldap servers imported into the truststore? Disabling hostname verification will probably not help since the exception doesn't deal with hostname verification.

---

<div class="post-metadata">

**Author:** ![gustav](https://avatars.discourse-cdn.com/v4/letter/g/919ad9/32.png) [@gustav](https://discuss.elastic.co/u/gustav)\
**Post date:** [November 19, 2015, 5:27am UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/14 "2015-11-19T05:27:31Z")

</div>

@jaymode. I have enabled TRACE for logs.  
Log is here: [http://pastebin.com/ENzhYTau](http://pastebin.com/ENzhYTau)

I am using following configuration:

> shield:  
> authc:  
> realms:  
> active\_directory:  
> type: active\_directory  
> domain\_name: [ldap.company.com](http://ldap.company.com)  
> url: "ldap://ldap.company.com:389"  
> user\_search:  
> filter: (&(objectClass=user)(sAMAccountName={0})(memberOf=cn=IT,ou=company,dc=company,dc=com))  
> group\_search:  
> base\_dn: "dc=company,dc=com"  
> files:  
> role\_mapping: "/elasticsearch/config/shield/role\_mapping.yml"  
> unmapped\_groups\_as\_roles: false

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:47pm UTC](https://discuss.elastic.co/t/shield-and-ldap-configuration/34114/15 "2017-07-06T13:47:39Z")

</div>


