# Shield/ldap integration

**URL:** <https://discuss.elastic.co/t/shield-ldap-integration/66468>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 18, 2016, 12:27am UTC](https://discuss.elastic.co/t/shield-ldap-integration/66468 "2016-11-18T00:27:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bishaka](https://avatars.discourse-cdn.com/v4/letter/b/e480ec/32.png) [@bishaka](https://discuss.elastic.co/u/bishaka)\
**Post date:** [November 18, 2016, 12:27am UTC](https://discuss.elastic.co/t/shield-ldap-integration/66468/1 "2016-11-18T00:27:58Z")

</div>

Hi,  
I have Kibana shielded with security plugin. I have used LDAP realm as well.  
Now when I try to login with my org id and password it doesn't work.

All other credentials specified in the kibana.yml file is also failing.

![](https://us1.discourse-cdn.com/elastic/original/2X/c/c7ab632e87e1abf59c44e2c2679948597b6996ef.PNG)

Below is role\_mapping.yml file  
\> # Role mapping configuration file which has elasticsearch roles as keys  
\> # that map to one or more user or group distinguished names

```
> #roleA: this is an elasticsearch role
> # - groupA-DN this is a group distinguished name
> # - groupB-DN
> # - user1-DN this is the full user distinguished name

> #power_user:
> # - "cn=admins,dc=example,dc=com"

> #user:
> # - "cn=users,dc=example,dc=com"
> # - "cn=admins,dc=example,dc=com"
> # - "cn=John Doe,cn=other users,dc=example,dc=com"

> admin:
> cluster: all
> indices:
> '*': all

> admin:
> - "cn=es_admin,ou=Users,dc=elastic,dc=co"

> kibana4_server:
> - "cn=server,ou=Kibanas,dc=elastic,dc=co"

> kibana4:
> - "cn=es_admin,ou=Kibanas,dc=elastic,dc=co"
```

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [November 28, 2016, 4:34pm UTC](https://discuss.elastic.co/t/shield-ldap-integration/66468/2 "2016-11-28T16:34:40Z")

</div>

hi @bishaka,

what are the server logs telling you? Perhaps there is a syntax error in the config file, which would cause the configuration not to be read.

Can you also double check if the names in the config matches the LDAP distinguished names? ([https://www.elastic.co/guide/en/x-pack/current/ldap-realm.html#mapping-roles-ldap](https://www.elastic.co/guide/en/x-pack/current/ldap-realm.html#mapping-roles-ldap))

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2016, 4:34pm UTC](https://discuss.elastic.co/t/shield-ldap-integration/66468/3 "2016-12-26T16:34:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
