# Shield unable to authenticate user to active directory domain

**URL:** <https://discuss.elastic.co/t/shield-unable-to-authenticate-user-to-active-directory-domain/57184>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 4, 2016, 7:26am UTC](https://discuss.elastic.co/t/shield-unable-to-authenticate-user-to-active-directory-domain/57184 "2016-08-04T07:26:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sivashankar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sivashankar/32/10421_2.png) [@Sivashankar](https://discuss.elastic.co/u/Sivashankar)\
**Post date:** [August 4, 2016, 7:26am UTC](https://discuss.elastic.co/t/shield-unable-to-authenticate-user-to-active-directory-domain/57184/1 "2016-08-04T07:26:11Z")

</div>

I have elasticsearch installed and running , i wanted to install the shield and authenticate via active directory  
i followed all the step given here --\>[https://www.elastic.co/guide/en/shield/current/active-directory-realm.html](https://www.elastic.co/guide/en/shield/current/active-directory-realm.html)

Basically i did the following  
-have setup a Elasticsearch administrative user in Active Directory Users  
-updated the elasticsearch.yml

#-----SHIELD CONFIG------  
shield:  
authc:  
realms:  
active\_directory:  
type: active\_directory  
order: 0  
domain\_name: \<[domain.name](http://domain.name)\>  
url: ldap://\<[domain.name](http://domain.name)\>:5601  
unmapped\_groups\_as\_roles: true

--updated the role\_mapping.yml  
--restarted the elasticsearch

getting the following error:  
Aug 4 19:24:34 wlielastict01 elasticsearch: [2016-08-04 19:24:34,543][WARN][shield.authc.activedirectory] [cignanz-elk-test-wlielastict01] authentication failed for user [admin]: unable to authenticate user [admin] to active directory domain [[asia.intl.cigna.com](http://asia.intl.cigna.com)]  
Aug 4 19:24:34 wlielastict01 elasticsearch: cause: com.unboundid.ldap.sdk.LDAPException: A client-side timeout was encountered while waiting 5000ms for a response to simple bind request with message ID 1 for user 'admin@asia.intl.cigna.com' from server wlielastict01.asi

Can anyone suggest me if i am missing something here?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![tanguy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanguy/32/6030_2.png) [@tanguy](https://discuss.elastic.co/u/tanguy)\
**Post date:** [August 4, 2016, 2:44pm UTC](https://discuss.elastic.co/t/shield-unable-to-authenticate-user-to-active-directory-domain/57184/2 "2016-08-04T14:44:55Z")

</div>

Hi,

> [@Sivashankar](#):
>
> Aug 4 19:24:34 wlielastict01 elasticsearch: cause: com.unboundid.ldap.sdk.LDAPException: A client-side timeout was encountered while waiting 5000ms

It seems your LDAP server is not responding. You should check the connection between your elasticsearch nodes and the LDAP server.

---

<div class="post-metadata">

**Author:** ![Sivashankar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sivashankar/32/10421_2.png) [@Sivashankar](https://discuss.elastic.co/u/Sivashankar)\
**Post date:** [August 5, 2016, 1:21am UTC](https://discuss.elastic.co/t/shield-unable-to-authenticate-user-to-active-directory-domain/57184/3 "2016-08-05T01:21:24Z")

</div>

Thanks for the response tanguy.  
When you say connection issue between elasticsearch nodes and the LDAP server does it mean the shield config is not correct? or is it to do something with the active directory setup?

---

<div class="post-metadata">

**Author:** ![tanguy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanguy/32/6030_2.png) [@tanguy](https://discuss.elastic.co/u/tanguy)\
**Post date:** [August 5, 2016, 7:20am UTC](https://discuss.elastic.co/t/shield-unable-to-authenticate-user-to-active-directory-domain/57184/4 "2016-08-05T07:20:59Z")

</div>

Maybe both. I suggest you check the connectivity between your elasticsearch nodes and your LDAP server. Once it is done, check again your Shield configurations (see [https://www.elastic.co/guide/en/shield/2.3/ldap-realm.html](https://www.elastic.co/guide/en/shield/2.3/ldap-realm.html)) you might need to configure `bind_dn`, `bind_password`, `user_search` etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/shield-unable-to-authenticate-user-to-active-directory-domain/57184/5 "2017-07-06T13:42:29Z")

</div>


