# Unable to authenticate with LDAP/AD

**URL:** <https://discuss.elastic.co/t/unable-to-authenticate-with-ldap-ad/40146>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 26, 2016, 6:03pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-with-ldap-ad/40146 "2016-01-26T18:03:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vrodrigo](https://avatars.discourse-cdn.com/v4/letter/v/59ef9b/32.png) [@vrodrigo](https://discuss.elastic.co/u/vrodrigo)\
**Post date:** [January 26, 2016, 6:03pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-with-ldap-ad/40146/1 "2016-01-26T18:03:30Z")

</div>

I keep getting a failed auth attempt when trying to authenticate with LDAP. Here is a snippet from the logs

[2016-01-26 11:55:24,039][WARN][shield.authc.ldap] [DataGrid-1] failed LDAP authentication with user template [cn=Users, ou=builtin, dc=testing, dc=corp] and DN [cn=Users, ou=builtin, dc=testing, dc=corp]: 80090308: LdapErr: DSID-0C0903C8, comment: AcceptSecurityContext error, data 52e, v2580  
2016-01-26 11:55:24,061][WARN][shield.authc.ldap] [DataGrid-1] authentication failed for user [administrator]: failed LDAP authentication  
cause: com.unboundid.ldap.sdk.LDAPException: 80090308: LdapErr: DSID-0C0903C8, comment: AcceptSecurityContext error, data 52e, v2580  
[2016-01-26 11:55:24,085][INFO][rest.suppressed] / Params: {}  
ElasticsearchSecurityException[unable to authenticate user [administrator] for REST request [/]]  
at org.elasticsearch.shield.support.Exceptions.authenticationError(Exceptions.java:39)

elasticsearch.yml setting  
shield.authc.realms:

# esusers1:

# type: esusers

# order: 1

ldap1:  
type: ldap  
order: 1  
url: "LDAP://Test.testing.corp:389"  
user\_dn\_templates:

- "cn=Users, ou=builtin, dc=testing, dc=corp"  
group\_search:  
base\_dn: "dc=mycompany,dc=corp"

role\_mapping.yml  
admin:

- "cn=Users,dc=testing,dc=corp"
- "cn=Administrators,dc=testing,dc=corp

I dont have SSL/TLS set up, but am assuming that is not a requirement.

Not sure what else I'm missing here.. any help is appreciated

Thanks

---

<div class="post-metadata">

**Author:** ![vrodrigo](https://avatars.discourse-cdn.com/v4/letter/v/59ef9b/32.png) [@vrodrigo](https://discuss.elastic.co/u/vrodrigo)\
**Post date:** [February 1, 2016, 7:14pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-with-ldap-ad/40146/2 "2016-02-01T19:14:02Z")

</div>

I wanted to close the loop on this. I resolved the issue by copying the DN as is from the LDAP server. but mainly the cn, ou, dc were capitalized and no spaces after the ","

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:47pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-with-ldap-ad/40146/3 "2017-07-06T13:47:04Z")

</div>


