# {"statusCode":403,"error":"Forbidden","message":"Forbidden"}to open kibana with AD authentication

**URL:** https://discuss.elastic.co/t/statuscode-403-error-forbidden-message-forbidden-to-open-kibana-with-ad-authentication/220326
**Category:** Elasticsearch
**Tags:** elastic-stack-security
**Created:** [February 21, 2020, 9:56am UTC](https://discuss.elastic.co/t/statuscode-403-error-forbidden-message-forbidden-to-open-kibana-with-ad-authentication/220326 "2020-02-21T09:56:34Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Jhansi](https://avatars.discourse-cdn.com/v4/letter/j/7cd45c/32.png) [@Jhansi](https://discuss.elastic.co/u/Jhansi)
#### Post date: [February 21, 2020, 9:56am UTC](https://discuss.elastic.co/t/statuscode-403-error-forbidden-message-forbidden-to-open-kibana-with-ad-authentication/220326/1 "2020-02-21T09:56:35Z")

</div>

I am trying to login kibana by using Active Directory users.I am done with settings in elasticsearch.yml file and I am able to login kibana page by using Ad users but it shows the {"statusCode":403,"error":"Forbidden","message":"Forbidden"} error but can't open the kibana page.  
Here is my configuration file elasticsearch.yml

xpack:  
security:  
authc:  
realms:  
active\_directory:  
my\_ad:  
order: 1  
domain\_name: [sgpltech.com](http://sgpltech.com)  
url: ldap://sgplad.sgpltech.com:389  
user\_search:  
base\_dn: "dc=sgpltech,dc=com"  
group\_search:  
base\_dn: "dc=sgpltech,dc=com"  
files:  
role\_mapping: "/etc/elasticsearch-7.4.0/config/role\_mapping.yml"

and my role\_mapping.yml file is

user:

- "cn=Users,dc=sgpltech,dc=com"
- "cn=hr086,cn=hr082,ou=Users,ou=SGPL-Production,dc=sgpltech,dc=com"

Please help me to fix this issue.  
Thank you

---

<div class="post-metadata">

### Author: ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)
#### Post date: [February 21, 2020, 3:20pm UTC](https://discuss.elastic.co/t/statuscode-403-error-forbidden-message-forbidden-to-open-kibana-with-ad-authentication/220326/2 "2020-02-21T15:20:38Z")

</div>

> [@Jhansi](#):
>
> ```auto
> user:
> - "cn=Users,dc=sgpltech,dc=com"
> 
> ```

`"cn=Users,dc=sgpltech,dc=com"` is most probably an Organizational Unit in your AD and not a group . Our role mapping works with groups only so you need to figure out what AD Security group your users will be under and set the DN for that group here.

---

<div class="post-metadata">

### Author: ![Jhansi](https://avatars.discourse-cdn.com/v4/letter/j/7cd45c/32.png) [@Jhansi](https://discuss.elastic.co/u/Jhansi)
#### Post date: [February 21, 2020, 3:41pm UTC](https://discuss.elastic.co/t/statuscode-403-error-forbidden-message-forbidden-to-open-kibana-with-ad-authentication/220326/3 "2020-02-21T15:41:09Z")

</div>

```
User DN: CN=glpi admin,OU=Users,OU=SGPL-Production,DC=sgpltech,DC=com
this is the user DN for AD here group is SGPL-Production but still it shows same error

I modified my role_mapping.file as below:

```

user:

- "cn=Users,ou=SGPL-Production,dc=sgpltech,dc=com"
- "CN=hr086,OU=Users,OU=SGPL-Production,DC=sgpltech,DC=com"

Is there any thing I need to change ?

---

<div class="post-metadata">

### Author: ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)
#### Post date: [February 21, 2020, 6:46pm UTC](https://discuss.elastic.co/t/statuscode-403-error-forbidden-message-forbidden-to-open-kibana-with-ad-authentication/220326/4 "2020-02-21T18:46:42Z")

</div>

your role mapping needs to match a group DN or a user DN .Neither of the ones you use are either a group DN or a user DN. You need to change that.

---

<div class="post-metadata">

### Author: ![Jhansi](https://avatars.discourse-cdn.com/v4/letter/j/7cd45c/32.png) [@Jhansi](https://discuss.elastic.co/u/Jhansi)
#### Post date: [February 25, 2020, 12:34pm UTC](https://discuss.elastic.co/t/statuscode-403-error-forbidden-message-forbidden-to-open-kibana-with-ad-authentication/220326/5 "2020-02-25T12:34:28Z")

</div>

`I tried but still no luck. Can you send one example please.`

---

<div class="post-metadata">

### Author: ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)
#### Post date: [February 25, 2020, 1:02pm UTC](https://discuss.elastic.co/t/statuscode-403-error-forbidden-message-forbidden-to-open-kibana-with-ad-authentication/220326/6 "2020-02-25T13:02:28Z")

</div>

> I tried but still no luck.

What _exactly_ did you try and how _exactly_ did it fail ?

> Can you send one example please

I don't know what example to give you, I have no clue how your AD structure looks like, what are the DNs of your users and of the security groups you have.

For a user that you want to login with AD, you need to figure out

a) What their DN is in AD . i.e `CN=somethinghere,OU=Users,OU=SGPL-Production,DC=sgpltech,DC=com`

OR

b) The DN of a group they belong to ,i.e. `CN=somegroupname,OU=Groups,OU=SGPL-Production,DC=sgpltech,DC=com`

NOTE: both the above are _examples_, you can't use them as-is, you need to figure out the correct values from your AD.

Then you either need to set

```auto
user:
- "CN=somethinghere,OU=Users,OU=SGPL-Production,DC=sgpltech,DC=com"

```

so only that user gets the `user` role

or

```auto
user:
- "CN=somegroupname,OU=Groups,OU=SGPL-Production,DC=sgpltech,DC=com"

```

so that all users that belong in that group in AD get that role.

Also note that you need to [define the `user` role](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-put-role.html) and make sure this gives access to the indices you want it to give, and you haven't mentioned if you have done that yet .

I would **urge** you to read the documentation that relates to security, i.e. start from : [Secure the Elastic Stack | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/secure-cluster.html). The more you understand, the easier it will be for you to configure the environment in a secure way.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 24, 2020, 1:02pm UTC](https://discuss.elastic.co/t/statuscode-403-error-forbidden-message-forbidden-to-open-kibana-with-ad-authentication/220326/7 "2020-03-24T13:02:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
