# Shield and LDAP error

**URL:** <https://discuss.elastic.co/t/shield-and-ldap-error/60156>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 9, 2016, 10:03am UTC](https://discuss.elastic.co/t/shield-and-ldap-error/60156 "2016-09-09T10:03:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![matrocker](https://avatars.discourse-cdn.com/v4/letter/m/9de053/32.png) [@matrocker](https://discuss.elastic.co/u/matrocker)\
**Post date:** [September 9, 2016, 10:03am UTC](https://discuss.elastic.co/t/shield-and-ldap-error/60156/1 "2016-09-09T10:03:35Z")

</div>

Hello,

I have integrated shield and LDAP. Both of these components are on the same machine (Windows 10) . I'm doing this exercise before implementing it on production. Below is the the ldap realm:

```
 shield:
  authc:
    realms:
      ldap1:
        type: ldap
        order: 0
        url: "ldaps://localhost:636"
        bind_dn: "cn=Manager,dc=maxcrc,dc=com"
        bind_password: secret
        user_search:
          base_dn: "dc=maxcrc,dc=com"
          attribute: cn
        group_search:
          base_dn: "dc=maxcrc,dc=com"
        files:
          role_mapping: "E:/elasticsearch/elasticsearch-2.4.0/config/shield/role_mapping.yml"
        unmapped_groups_as_roles: false

```

I'm not using SSL between LDAP and Shield.

I'm getting this error in the startup logs:

[2016-09-09 15:29:04,403][ERROR][shield.authc.ldap] [Elysius] unable to create connection pool for realm [ldap1]: An error occurred while attempting to connect to server localhost:636: java.io.IOException: Unable to verify an attempt to to establish a secure connection to 'localhost:636' because an unexpected error was encountered during validation processing: javax.net.ssl.SSLPeerUnverifiedException: peer not authenticated

And ultimately it's not getting authenticated from the browser too.

**Edit:** I changed the realm to this:

```
shield:
  authc:
    realms:
      ldap1:
        type: ldap
        order: 0
        url: "ldaps://localhost:636"
        user_dn_templates:
          - "cn={0}, ou=users, cn=Manager,dc=maxcrc,dc=com"
        group_search:
          base_dn: "dc=maxcrc,dc=com"
        files:
          role_mapping: "E:/elasticsearch/elasticsearch-2.4.0/config/shield/role_mapping.yml"
        unmapped_groups_as_roles: false

```

It starts up without any errors but when I give the LDAP user credentials in the browser, Manager/secret(password), it doesn't authenticate.  
Please help.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [September 9, 2016, 11:46am UTC](https://discuss.elastic.co/t/shield-and-ldap-error/60156/2 "2016-09-09T11:46:45Z")

</div>

> [@matrocker](#):
>
> I'm not using SSL between LDAP and Shield

The configuration you use does indicate that you want to use ssl. `ldaps` is the scheme for LDAP with ssl; port 636 is the typical port for an LDAP server to listen using ssl.

If you do not want to use ssl, use:

```
url: "ldap://localhost:389"

```

---

<div class="post-metadata">

**Author:** ![matrocker](https://avatars.discourse-cdn.com/v4/letter/m/9de053/32.png) [@matrocker](https://discuss.elastic.co/u/matrocker)\
**Post date:** [September 9, 2016, 12:50pm UTC](https://discuss.elastic.co/t/shield-and-ldap-error/60156/3 "2016-09-09T12:50:04Z")

</div>

Thanks a lot, Jay. It worked. Totally forgot to change that ldap uri. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:41pm UTC](https://discuss.elastic.co/t/shield-and-ldap-error/60156/4 "2017-07-06T13:41:54Z")

</div>


