# Using PKI realms with email role\_mapping

**URL:** <https://discuss.elastic.co/t/using-pki-realms-with-email-role-mapping/131525>\
**Category:** Elasticsearch\
**Created:** [May 11, 2018, 6:01pm UTC](https://discuss.elastic.co/t/using-pki-realms-with-email-role-mapping/131525 "2018-05-11T18:01:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rezie](https://avatars.discourse-cdn.com/v4/letter/r/c37758/32.png) [@rezie](https://discuss.elastic.co/u/rezie)\
**Post date:** [May 11, 2018, 6:01pm UTC](https://discuss.elastic.co/t/using-pki-realms-with-email-role-mapping/131525/1 "2018-05-11T18:01:53Z")

</div>

I'm currently using ES 5.5 and am trying to enable client authentication via PKI and so far everything seems to work if the certificates I use only contain a common name (or email address by itself), but if I try to also include an emailAddress field, the role\_mapping configuration doesn't seem to be coming into effect.

The relevant elasticsearch.yaml config:

```auto
xpack:
  security:
    authc:
      realms:
        realm1:
          type: pki
          order: 0
          username_pattern: "EMAILADDRESS=(.*?)(?:,|$)"
          certificate_authorities:
          - /usr/share/elasticsearch/config/certs/ca.crt
          files:
            role_mapping: /usr/share/elasticsearch/config/certs/role_mapping.yaml

```

And role\_mapping.yaml contains something similar to:

```auto
superuser:
  - "emailAddress=admin@example.com"

```

I can see that `username_pattern` worked properly if I try to make any sort of curl requests against the instance, as the error message I receive is able to parse the email address:

```auto
[2018-05-11T18:04:31,735][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [node1] The security index is not yet available - no role mappings can be loaded

[2018-05-11T18:04:31,744][INFO][o.e.x.s.a.l.LoggingAuditTrail] [transport] [access_denied]	origin_type=[rest], origin_address=[172.17.0.2], principal=[admin@example.com], action=[cluster:monitor/main], request=[MainRequest]

```

The certificate's subject line appears like this:  
`Subject: emailAddress=admin@example.com, CN=node1`

Same with the "mangled" version (i.e. when the email address is not specified first using openssl's `-subj` flag):  
`Subject: CN=node1/emailAddress=admin@example.com`

The [role mapping file](https://www.elastic.co/guide/en/x-pack/5.5/mapping-roles.html#mapping-roles-file) documentation doesn't mention specifications for using email addresses - could the issue simply be a syntax-related one?

---

<div class="post-metadata">

**Author:** ![rezie](https://avatars.discourse-cdn.com/v4/letter/r/c37758/32.png) [@rezie](https://discuss.elastic.co/u/rezie)\
**Post date:** [May 11, 2018, 7:31pm UTC](https://discuss.elastic.co/t/using-pki-realms-with-email-role-mapping/131525/2 "2018-05-11T19:31:40Z")

</div>

Was able to resolve this issue - I missed the suggestion in the documentation to use the authentication API endpoint to verify the DN. Once I grabbed the return value and used it in the role\_mapping file, I was able to make curl commands regardless of how many fields I have set in the DN.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2018, 7:31pm UTC](https://discuss.elastic.co/t/using-pki-realms-with-email-role-mapping/131525/3 "2018-06-08T19:31:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
