# Unable to use sAMA login account name for authentication

**URL:** <https://discuss.elastic.co/t/unable-to-use-sama-login-account-name-for-authentication/83271>\
**Category:** Elasticsearch\
**Created:** [April 22, 2017, 9:33am UTC](https://discuss.elastic.co/t/unable-to-use-sama-login-account-name-for-authentication/83271 "2017-04-22T09:33:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![YuWatanabe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuwatanabe/32/13259_2.png) [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Post date:** [April 22, 2017, 9:33am UTC](https://discuss.elastic.co/t/unable-to-use-sama-login-account-name-for-authentication/83271/1 "2017-04-22T09:33:30Z")

</div>

Hello.

I am trying to work out active directory authentication but looks like x-pack security fails to find the user name.

```
[2017-04-22T18:20:41,937][INFO][o.e.x.s.a.l.LdapRealm] [development] authenticate failed for user [example\y-watanabe]: search for user [example\y-watanabe] by principle name yielded no results
[2017-04-22T18:20:48,315][INFO][o.e.x.s.a.l.LdapRealm] [development] authenticate failed for user [example.com\y-watanabe]: 80090308: LdapErr: DSID-0C0903D9, comment: AcceptSecurityContext error, data 52e, v2580
[2017-04-22T18:22:54,610][INFO][o.e.x.s.a.l.LdapRealm] [development] authenticate failed for user [example\\y-watanabe]: 80090308: LdapErr: DSID-0C0903D9, comment: AcceptSecurityContext error, data 52e, v2580

```

I have my AMA account configured fine like below.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/c/7/c761b4ae123dd191dbfb97bb8fcea0e194ffc706.PNG)

Authentication works fine with _UPN_ . Below is my _elasticsearch.yml_.

```
# AD authentication
xpack.security.authc.realms:
  active_directory:
    type: active_directory
    order: 0
    domain_name: ad.example.com
    url: ldap://ad.example.com:389
    user_search.base_dn: cn=Users,dc=example,dc=com
    group_search.base_dn: cn=Users,dc=example,dc=com
    unmapped_groups_as_roles: true
    follow_referrals: false
  native1:
    type: native
    order: 1

```

I am using _x-pack 5.3.0_ .

Am I missing any setting to use sAMAccountName ?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 23, 2017, 11:59pm UTC](https://discuss.elastic.co/t/unable-to-use-sama-login-account-name-for-authentication/83271/2 "2017-04-23T23:59:23Z")

</div>

The process of converting a legacy (NetBIOS) name into the necessary values for bind+search is fairly complex, so there's a few places it could go wrong. It's hard to tell whether your configuration is correct since you've redacted so many of the settings (which is fine, it's just harder to diagnose).

Please turn on TRACE [logging](https://www.elastic.co/guide/en/elasticsearch/reference/5.3/misc-cluster.html#cluster-logger) for `org.elasticsearch.xpack.security.authc.ldap.support`, try and login, and then check for messages in the log file for "LdapUtils".  
If you're uncomfortable posting the logs here, you can send me the details in a private message.

```auto
curl -XPUT 'localhost:9200/_cluster/settings?pretty' -H 'Content-Type: application/json' -d'
{
  "transient": {
    "logger.org.elasticsearch.xpack.security.authc.ldap.support": "TRACE"
  }
}
'

```

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [April 25, 2017, 1:05pm UTC](https://discuss.elastic.co/t/unable-to-use-sama-login-account-name-for-authentication/83271/3 "2017-04-25T13:05:48Z")

</div>

> [@YuWatanabe](#):
>
> user [example\y-watanabe]  
> user [[example.com](http://example.com)\y-watanabe]  
> user [example\y-watanabe]

It looks like you are trying to use the down level login name and not just the sAMAccountName. What happens when you try using just `y-watanbe`? Also in your configuration you have the domain as `ad.example.com` but in your screenshot the domain is `example.com`; are you sure that your configuration is correct?

---

<div class="post-metadata">

**Author:** ![YuWatanabe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuwatanabe/32/13259_2.png) [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Post date:** [May 18, 2017, 8:32am UTC](https://discuss.elastic.co/t/unable-to-use-sama-login-account-name-for-authentication/83271/4 "2017-05-18T08:32:55Z")

</div>

I was able to achieve this by setting sAMAccountName in **user\_search.attribute** for [LDAP realm](https://www.elastic.co/guide/en/x-pack/current/ldap-realm.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2017, 8:32am UTC](https://discuss.elastic.co/t/unable-to-use-sama-login-account-name-for-authentication/83271/5 "2017-06-15T08:32:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
