# SOLVED:Issue in LDAP group authentication (shield):

**URL:** <https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 26, 2016, 9:46am UTC](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041 "2016-05-26T09:46:27Z")\
**Posts on this page:** 9\
**Page:** 2

<div class="post-metadata">

**Author:** ![ankur.aggarwal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankur.aggarwal/32/45312_2.png) [@ankur.aggarwal](https://discuss.elastic.co/u/ankur.aggarwal)\
**Post date:** [May 27, 2016, 2:14pm UTC](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041/21 "2016-05-27T14:14:09Z")

</div>

dn: cn=,ou=group,dc=company,dc=com  
member: uid=,ou=People,dc=company,dc=com  
memberUid:   
gidNumber:   
objectClass: posixGroup  
objectClass: top  
objectClass: groupOfNames  
cn:

dn: uid=testuser,ou=People,dc=company,dc=com  
userPassword: XXXX  
loginShell: /bin/bash  
objectClass: account  
objectClass: posixAccount  
objectClass: shadowAccount  
objectClass: top  
gidNumber: xxxx  
uid: testuser  
uidNumber: xxxxxxx

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [May 27, 2016, 2:54pm UTC](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041/22 "2016-05-27T14:54:57Z")

</div>

This seems odd as the DN, objectClass, and memberUid attributes in the group search filter look correct to me.

```
group_search:
  base_dn: "ou=group,dc=company,dc=com"
  filter: "(&(objectClass=posixGroup)(memberUid={0}))"
  user_attribute: "uid"

```

Maybe you could try with member as that seems to list the DN of the user:

```
group_search:
  base_dn: "ou=group,dc=company,dc=com"
  filter: "(&(objectClass=posixGroup)(member={0}))"
```

---

<div class="post-metadata">

**Author:** ![ankur.aggarwal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankur.aggarwal/32/45312_2.png) [@ankur.aggarwal](https://discuss.elastic.co/u/ankur.aggarwal)\
**Post date:** [May 27, 2016, 3:32pm UTC](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041/23 "2016-05-27T15:32:10Z")

</div>

Same error for group added in role\_mapping : `- "cn=SuperUsers,ou=group,dc=company,dc=com"`

[2016-05-27 15:20:55,913][DEBUG][shield.authc.support] the roles [[]], are mapped from these [ldap] groups [[]] for realm [ldap/ldap1]  
[2016-05-27 15:20:55,913][DEBUG][shield.authc.support] the roles [[]], are mapped from the user [ldap] for realm [uid=testuser,ou=People,dc=company,dc=com/ldap]

One more thing, if i add user in role\_mapping and use first config , then user is not able to authenticate, But if i remove `user_attribute` from config then user works  
`- "uid=testuser,ou=People,dc=company,dc=com"`

Although, user authentication is working for 2nd config , but not for group ☹

---

<div class="post-metadata">

**Author:** ![ankur.aggarwal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankur.aggarwal/32/45312_2.png) [@ankur.aggarwal](https://discuss.elastic.co/u/ankur.aggarwal)\
**Post date:** [May 29, 2016, 10:39am UTC](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041/24 "2016-05-29T10:39:15Z")

</div>

Issue resolved using usersearch key.

---

<div class="post-metadata">

**Author:** ![tingking23](https://avatars.discourse-cdn.com/v4/letter/t/e68b1a/32.png) [@tingking23](https://discuss.elastic.co/u/tingking23)\
**Post date:** [June 22, 2016, 7:31am UTC](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041/25 "2016-06-22T07:31:31Z")

</div>

i have the same erro, can you tall me what the usersearch key? and how to solved that problem.  
thanks!

---

<div class="post-metadata">

**Author:** ![tingking23](https://avatars.discourse-cdn.com/v4/letter/t/e68b1a/32.png) [@tingking23](https://discuss.elastic.co/u/tingking23)\
**Post date:** [June 27, 2016, 1:37am UTC](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041/26 "2016-06-27T01:37:42Z")

</div>

i am the same version v2.3.2, can you tall me how you to solved this issue? could you giveme your elasticsearch.yml role\_mapping or other conf's text usefull,thank you very much

---

<div class="post-metadata">

**Author:** ![ankur.aggarwal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankur.aggarwal/32/45312_2.png) [@ankur.aggarwal](https://discuss.elastic.co/u/ankur.aggarwal)\
**Post date:** [June 27, 2016, 7:27am UTC](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041/27 "2016-06-27T07:27:26Z")

</div>

Used below ldap configurations to fix this:

shield.ssl.keystore.path:  
shield.ssl.keystore.password:

shield:  
authc:  
realms:  
esusers:  
type: esusers  
order: 0  
ldap1:  
type: ldap  
order: 1  
url: ""  
bind\_dn: ""  
bind\_password:  
user\_search:  
base\_dn: ""  
group\_search:  
base\_dn: ""  
files:  
role\_mapping: ""

---

<div class="post-metadata">

**Author:** ![tingking23](https://avatars.discourse-cdn.com/v4/letter/t/e68b1a/32.png) [@tingking23](https://discuss.elastic.co/u/tingking23)\
**Post date:** [June 27, 2016, 7:42am UTC](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041/28 "2016-06-27T07:42:19Z")

</div>

i used the same thing ,but the LDAP group can't work ,only LDAP user can login to ES. IS the Setting Up SSL must be setting? or anythins i missed?

there have the logs with waring : com.unboundid.ldap.sdk.LDAPExpection: invalid credentials ,but i am sure the bind\_dn: amind and the password is right to connect LDAP server

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041/29 "2017-07-06T13:43:24Z")

</div>



[Previous page](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041.md?page=1)
