# Unable to login to Kibana by using LDAP user who is having a superuser role

**URL:** <https://discuss.elastic.co/t/unable-to-login-to-kibana-by-using-ldap-user-who-is-having-a-superuser-role/242218>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 22, 2020, 2:46pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-by-using-ldap-user-who-is-having-a-superuser-role/242218 "2020-07-22T14:46:32Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![elkusergrr](https://avatars.discourse-cdn.com/v4/letter/e/c57346/32.png) [@elkusergrr](https://discuss.elastic.co/u/elkusergrr)\
**Post date:** [July 22, 2020, 2:46pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-by-using-ldap-user-who-is-having-a-superuser-role/242218/1 "2020-07-22T14:46:32Z")

</div>

Hi,

I am unable to login to Kibana by using an LDAP user who is having a superuser role. Getting below the exception.

{"statusCode":401,"error":"Unauthorized","message":"[security\_exception] unable to authenticate user [\*\*\*\*\*\*] for REST request [/\_xpack/security/user/\_has\_privileges], with { header={ WWW-Authenticate="Basic realm=\"security\" charset=\"UTF-8\"" } }"}

When trying to authenticate the same user using API getting below output.

curl -XGET -u \*\*\*\*\*\* http://_**:9200/\_xpack/security/\_authenticate  
Enter host password for user '':  
{"username":"**_\*\*\*","roles":["superuser"],"full\_name":null,"email":null,"metadata":{},"enabled":true,"authentication\_realm":{"name":"ldap1","type":"ldap"},"lookup\_realm":{"name":"ldap1","type":"ldap"}}

GET /\_security/role/superuser

{  
"superuser" : {  
"cluster" : [  
"all"  
],  
"indices" : [  
{  
"names" : [  
"_"  
],  
"privileges" : [  
"all"  
],  
"allow\_restricted\_indices" : true  
}  
],  
"applications" : [  
{  
"application" : "_",  
"privileges" : [  
"_"  
],  
"resources" : [  
"_"  
]  
}  
],  
"run\_as" : [  
"\*"  
],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : { }  
}  
}

Assigned a role to a user by using below API

POST /\_xpack/security/role\_mapping/mapping1  
{  
"roles": ["superuser"],  
"enabled": true,  
"rules": {  
"field" : { "username" : "\*" }  
},  
"metadata" : {  
"version" : 1  
}  
}

Looks like I am missing something here, can someone help me.

Thanks  
GRR

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [July 23, 2020, 6:18am UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-by-using-ldap-user-who-is-having-a-superuser-role/242218/2 "2020-07-23T06:18:04Z")

</div>

> [@elkusergrr](#):
>
> {"statusCode":401,"error":"Unauthorized","message":"[security\_exception] unable to authenticate user [\*\*\*\*\*\*] for REST request [/\_xpack/security/user/\_has\_privileges], with { header={ WWW-Authenticate="Basic realm="security" charset="UTF-8"" } }"}

This error might be for the kibana user. Could you please double check the user Kibana uses for connecting elasticsearch and whether it has sufficient roles? You can also perform the same API authentication with the kibana user and see what it gives.

---

<div class="post-metadata">

**Author:** ![elkusergrr](https://avatars.discourse-cdn.com/v4/letter/e/c57346/32.png) [@elkusergrr](https://discuss.elastic.co/u/elkusergrr)\
**Post date:** [July 23, 2020, 6:32am UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-by-using-ldap-user-who-is-having-a-superuser-role/242218/3 "2020-07-23T06:32:11Z")

</div>

Hi Yang,

Getting the below successful response.

curl -XGET -u kibana http://\*\*\*\*\*\*\*\*\*\*:9200/\_xpack/security/\_authenticate  
Enter host password for user 'kibana':  
{"username":"kibana","roles":["kibana\_system"],"full\_name":null,"email":null,"metadata":{"\_reserved":true},"enabled":true,"authentication\_realm":{"name":"reserved","type":"reserved"},"lookup\_realm":{"name":"reserved","type":"reserved"}}

Thanks  
GRR

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [July 23, 2020, 11:33am UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-by-using-ldap-user-who-is-having-a-superuser-role/242218/4 "2020-07-23T11:33:49Z")

</div>

What are the versions of Kibana and Elasticsearch? Could you share the configuraiton for theml? Could you also enable trace logging and provide the logs?

```auto
PUT _cluster/settings
{"transient":{"logger.org.elasticsearch.xpack.security.authc":"trace"}}

```

---

<div class="post-metadata">

**Author:** ![elkusergrr](https://avatars.discourse-cdn.com/v4/letter/e/c57346/32.png) [@elkusergrr](https://discuss.elastic.co/u/elkusergrr)\
**Post date:** [July 23, 2020, 12:58pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-by-using-ldap-user-who-is-having-a-superuser-role/242218/5 "2020-07-23T12:58:21Z")

</div>

Hi Yang,

I am using 6.8.4 version Kibana and Elasticsearch.

Getting below error in kibana log.

{"type":"error","@timestamp":"2020-07-23T12:47:25Z","tags":["error","authentication"],"pid":91590,"level":"error","error":{"message":"[security\_exception] unable to authenticate user [**] for REST request [/\_xpack/security/user/\_has\_privileges], with { header={ WWW-Authenticate="Basic realm=\"security\" charset=\"UTF-8\"" } }","name":"Error","stack":"[security\_exception] unable to authenticate user [**] for REST request [/\_xpack/security/user/\_has\_privileges], with { header={ WWW-Authenticate="Basic realm=\"security\" charset=\"UTF-8\"" } } :: {"path":"/\_xpack/security/user/\_has\_privileges","query":{},"body":"{\"applications\":[{\"application\":\"kibana-.kibana\",\"resources\":[\"space:default\"],\"privileges\":[\"version:6.8.4\",\"action:login\",\"action:saved\_objects/config/get\"]}]}","statusCode":401,"response":"{\"error\":{\"root\_cause\":[{\"type\":\"security\_exception\",\"reason\":\"unable to authenticate user [**] for REST request [/\_xpack/security/user/\_has\_privileges]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}}],\"type\":\"security\_exception\",\"reason\":\"unable to authenticate user [**] for REST request [/\_xpack/security/user/\_has\_privileges]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}},\"status\":401}","wwwAuthenticateDirective":"Basic realm=\"security\" charset=\"UTF-8\""}\n at respond (/home/release/release\_independent/elk/kibana/kibana-6.8.4-linux-x86\_64/node\_modules/elasticsearch/src/lib/transport.js:308:15)\n at checkRespForFailure (/home/release/release\_independent/elk/kibana/kibana-6.8.4-linux-x86\_64/node\_modules/elasticsearch/src/lib/transport.js:267:7)\n at HttpConnector. (/home/release/release\_independent/elk/kibana/kibana-6.8.4-linux-x86\_64/node\_modules/elasticsearch/src/lib/connectors/http.js:166:7)\n at IncomingMessage.wrapper (/home/release/release\_independent/elk/kibana/kibana-6.8.4-linux-x86\_64/node\_modules/elasticsearch/node\_modules/lodash/lodash.js:4929:19)\n at IncomingMessage.emit (events.js:194:15)\n at endReadableNT (\_stream\_readable.js:1103:12)\n at process.\_tickCallback (internal/process/next\_tick.js:63:19)"},"message":"[security\_exception] unable to authenticate user [\*\*\*\*\*\*] for REST request [/\_xpack/security/user/\_has\_privileges], with { header={ WWW-Authenticate="Basic realm=\"security\" charset=\"UTF-8\"" } }"}

Getting the below exception at client ( browser).

{"statusCode":401,"error":"Unauthorized","message":"[security\_exception] unable to authenticate user [\*\*\*\*\*\*] for REST request [/\_xpack/security/user/\_has\_privileges], with { header={ WWW-Authenticate="Basic realm=\"security\" charset=\"UTF-8\"" } }"}

Thanks  
GRR

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [July 24, 2020, 1:09am UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-by-using-ldap-user-who-is-having-a-superuser-role/242218/6 "2020-07-24T01:09:31Z")

</div>

Could you please share the logs from Elasticsearch? I understand the need of redacting logs. But could you please do it consistently? From the logs I cannot tell whether the errors are all related to the same user since sometimes it is `[]` and other times it is `[******]`.

---

<div class="post-metadata">

**Author:** ![elkusergrr](https://avatars.discourse-cdn.com/v4/letter/e/c57346/32.png) [@elkusergrr](https://discuss.elastic.co/u/elkusergrr)\
**Post date:** [July 24, 2020, 1:59am UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-by-using-ldap-user-who-is-having-a-superuser-role/242218/7 "2020-07-24T01:59:39Z")

</div>

Hi Yang,

I am using the same LDAP user for testing. While submitting the topic it got changed from [\*\*\*\*\*\*] to at some places.

Getting the below output from elasticsearch log

[2020-07-23T21:41:42,727][DEBUG][o.e.x.s.a.s.DnRoleMapper] [localhost] the roles [], are mapped from the user [cn= **Full Name of the User** ,ou=users02,ou=users,ou=adm01,ou=at,ou=corp,dc=mydomain,dc=com] using file [role\_mapping.yml] for realm [ldap/ldap1]

[2020-07-23T21:41:42,735][TRACE][o.e.x.s.a.s.m.NativeRoleMappingStore] [gi2p1xrlgs021.gi02.bpty] User [**employeeID**] matches role-mapping [mapping1]  
with roles [[superuser]]

role\_mapping.yml contains below data.  
superuser:

- "OU=Users,OU=ADM01,OU=AT,OU=CORP,DC=mydomain,DC=com"

I am getting the superuser role from NativeRoleMappingStore and getting the no roles (null) from DnRoleMapper, is there any issue the way I configured the role\_mapping.yml?

Note: Bold text replaced with dummy data to secure the personal data.

Thanks  
GRR

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [July 24, 2020, 1:36pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-by-using-ldap-user-who-is-having-a-superuser-role/242218/8 "2020-07-24T13:36:24Z")

</div>

For `role_mapping.yml`, you need use the full DN, the configuration you currently have misses the `CN=xxx` part of the full DN. That is why it did not pick and fell through to the native mapping.

Based on the logs, the authentication was successful because the roles are mapped and I am not seeing any errors. So there is no login issue anymore?

If the problem persists, could you please share the full logs or at least enough logs to cover the whole faild authentication attempt to help better understand of the context. Also, please use forum formatting features for pasting logs so they are easier to read. For logs, you can put them inside a pair of triple backquotes:

````auto
    ```
    log text here ...
    ```

````

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2020, 1:36pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-by-using-ldap-user-who-is-having-a-superuser-role/242218/9 "2020-08-21T13:36:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
