Hello.
I am trying to work out active directory authentication but looks like x-pack security fails to find the user name.
[2017-04-22T18:20:41,937][INFO ][o.e.x.s.a.l.LdapRealm ] [development] authenticate failed for user [example\y-watanabe]: search for user [example\y-watanabe] by principle name yielded no results
[2017-04-22T18:20:48,315][INFO ][o.e.x.s.a.l.LdapRealm ] [development] authenticate failed for user [example.com\y-watanabe]: 80090308: LdapErr: DSID-0C0903D9, comment: AcceptSecurityContext error, data 52e, v2580
[2017-04-22T18:22:54,610][INFO ][o.e.x.s.a.l.LdapRealm ] [development] authenticate failed for user [example\\y-watanabe]: 80090308: LdapErr: DSID-0C0903D9, comment: AcceptSecurityContext error, data 52e, v2580
I have my AMA account configured fine like below.
Authentication works fine with UPN . Below is my elasticsearch.yml.
# AD authentication
xpack.security.authc.realms:
active_directory:
type: active_directory
order: 0
domain_name: ad.example.com
url: ldap://ad.example.com:389
user_search.base_dn: cn=Users,dc=example,dc=com
group_search.base_dn: cn=Users,dc=example,dc=com
unmapped_groups_as_roles: true
follow_referrals: false
native1:
type: native
order: 1
I am using x-pack 5.3.0 .
Am I missing any setting to use sAMAccountName ?