# Unable to negotiate with kerberos keytab file

**URL:** <https://discuss.elastic.co/t/unable-to-negotiate-with-kerberos-keytab-file/233633>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 20, 2020, 11:49pm UTC](https://discuss.elastic.co/t/unable-to-negotiate-with-kerberos-keytab-file/233633 "2020-05-20T23:49:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![lnitin12](https://avatars.discourse-cdn.com/v4/letter/l/b5e925/32.png) [@lnitin12](https://discuss.elastic.co/u/lnitin12)\
**Post date:** [May 20, 2020, 11:49pm UTC](https://discuss.elastic.co/t/unable-to-negotiate-with-kerberos-keytab-file/233633/1 "2020-05-20T23:49:57Z")

</div>

I'm unable to negotiate a user with kerberos keytab to URL i'm testing is  
curl --negotiate -u : [https://localhost:9200/\_security/\_authenticate](https://localhost:9200/_security/_authenticate) --verbose  
Although keytab user has superuser access it still shows Unauthorized. all other api calls are going though.  
Does this need any other additional privilege to call this API..?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 21, 2020, 5:44am UTC](https://discuss.elastic.co/t/unable-to-negotiate-with-kerberos-keytab-file/233633/2 "2020-05-21T05:44:04Z")

</div>

Hi

- Please share the exact error messages you get and not your interpretation of them.
- share your elasticsearch.yml configuration
- share the exact output of that curl command
- share the exact output of a curl calling an API that "is going through"
- what do you mean that the user in keytab is a superuser ? Can you share the role mapping that you have in place that makes that happen ?
- have you `kinit` your user before executing the curl command ?

---

<div class="post-metadata">

**Author:** ![lnitin12](https://avatars.discourse-cdn.com/v4/letter/l/b5e925/32.png) [@lnitin12](https://discuss.elastic.co/u/lnitin12)\
**Post date:** [May 21, 2020, 3:45pm UTC](https://discuss.elastic.co/t/unable-to-negotiate-with-kerberos-keytab-file/233633/3 "2020-05-21T15:45:17Z")

</div>

curl --negotiate -u : [https://localhost:9200/\_security/\_authenticate](https://localhost:9200/_security/_authenticate) --verbose

- About to connect () to [sdev.fre.com](http://sdev.fre.com) port 9200 (#0)
- 

```
 Trying 10.200.60.3

```

- Connected to [sdev.fre.com](http://sdev.fre.com) (10.200.60.3) port 9200 (#0)  
\*Initializing NSS with certpath: sql:/etc/pki/nssdb
- CAfile: /etc/elasticsearch/certs.ca.crt  
CApath: none
- SSL connection using TLS\_ECDHE\_RSA\_WITH\_AES\_256\_GCM\_SHA 384
- Server certificate:
- 

```
        subject: CN=sdev.fre.com,OU=Software,O=fre,L=Farmington,ST=Michigan,C=US

```

- 

```
        start date: May 20 15:57:37 2020 EDT

```

- 

```
        expire date: May 20 15:58:03 2021 EDT

```

- 

```
        common name: sdev.fre.com

```

- 

```
        issuer: CN=vault.fre.com,O=fre,L=Farmington,ST=Michigan,C=US

```

> GET /\_security/\_authenticate HTTP/1.1  
> User-Agent: curl/7.29.0  
> Host: [sdev.fre.com:9200](http://sdev.fre.com:9200)  
> Accept: _/_

\< HTTP/1.1 401 Unauthorized  
\< WWW-Authenticate: Negotiate  
\< WWW-Authenticate: Bearer realm="security"  
\< WWW-Authenticate: Apikey  
\< WWW-Authenticate: Basic realm="security" charset="UTF-8"  
\< content-type: application/json; charset=UTF-8  
\< content-length: 529  
\<

- Ignoring the response-body
- Connection #0 to host [sdev.fre.com](http://sdev.fre.com) left intact
- Issue another request to this URL: '[https://sdev.fre.com:9200/\_security/\_authenticate](https://sdev.fre.com:9200/_security/_authenticate)
- Found bundle to host [sdev.fre.com](http://sdev.fre.com): 0x1448de0
- Re-using existing connection! (#0) with host [sdev.fre.com](http://sdev.fre.com)
- Connected to [sdev.fre.com](http://sdev.fre.com) (10.200.60.3) port 9200 (#0)
- Server auth using GSS-Negotiate with user ' '

> GET /\_security/\_authenticate HTTP/1.1  
> Authorization: Negotiate YiBDQTEjMCEGCSqGSIb3DQEJARYUc3VwcG9ydEBmcmFuazRkZC5jb20wHhcNMTIwODIyMDUyNj0WhcNMTcwODIxMDUyNjU0WjBKMQswCQYDVQQGEwJKUDEOMAwGA1UECAwFVG9reW8xETAPBgNVBAoMCEZyYW5rNEREMRgwFgYDVQQDDA93d3cuZXhhbXBs=  
> User-Agent: curl/7.29.0  
> Host: [sdev.fre.com:9200](http://sdev.fre.com:9200)  
> Accept: _/_

\< HTTP/1.1 200 OK  
\< WWW-Authenticate: Negotiate YDIyMDUyNjU0WhcNMTcwODIxMDUyNjU0WjBKMQswCQYDVQQGEwJKUDEOMAwGA1UECAwFG9reW8xETAPBgNVBAoMCEZyYW5rNEREMRgwFgYDVQQDDA93d3cuZXhhbXBs  
\< content-type: application/json; charset=UTF-8  
\< content-length: 316  
\<

- Closing connection 0  
{"username": "HTTP/sdev.fre.com","roles": ["superuser"], "full\_name":null,"email":null,"metadata":{"kerberos\_user\_principal\_name":"HTTP/sdev.fre.com@FRE.COM ","kerberos\_realm":"[FRE.COM](http://FRE.COM)"},"enabled":true,"authentication\_realm":{"name":"kerb1","type":"kerberos"},"lookup\_relam":{"name":"kerb1","type":"kerberos"}

Elasticsearch.yml  
xpack.security.authc.realms.kerberos.kerb1.order: "3"  
xpack.security.authc.realms.kerberos.kerb1.keytab.path: /etc/elasticsearch/elastic.keytab  
xpack.security.authc.realms.kerberos.kerb1.remove\_realm\_name: true

Role\_mapping:  
curl --cacert /etc/elasticsearch/certs/sdev.fre.com.ca.crt -u elastic -H "content-Type: appplication/json" -X POST "[https://sdev.fre.com:9200/\_security/role\_mapping/adm:](https://sdev.fre.com:9200/_security/role_mapping/adm:) --data "@data.json"

data.json:  
{  
"roles": ["superuser"],  
"rules": {  
"field": { "username" : "HTTP/sdev.fre.com@FRE.COM" }  
},  
"enabled": true  
}

---

<div class="post-metadata">

**Author:** ![lnitin12](https://avatars.discourse-cdn.com/v4/letter/l/b5e925/32.png) [@lnitin12](https://discuss.elastic.co/u/lnitin12)\
**Post date:** [May 21, 2020, 3:46pm UTC](https://discuss.elastic.co/t/unable-to-negotiate-with-kerberos-keytab-file/233633/4 "2020-05-21T15:46:26Z")

</div>

Yes, user is able to kinit and klist the ticket.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 21, 2020, 4:02pm UTC](https://discuss.elastic.co/t/unable-to-negotiate-with-kerberos-keytab-file/233633/5 "2020-05-21T16:02:02Z")

</div>

Please use ``` blocks to format your output, it's really hard to go through this as is. Use the preview panel on the right as you edit to see if the formatting is ok. Thanks

Also, this looks like a successful response where your user is authenticated and has the superuser role, so I don't see what the problem is.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 18, 2020, 4:02pm UTC](https://discuss.elastic.co/t/unable-to-negotiate-with-kerberos-keytab-file/233633/6 "2020-06-18T16:02:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
