# X-Pack 5.2.1: Role mappings never get applied to LDAP groups

**URL:** <https://discuss.elastic.co/t/x-pack-5-2-1-role-mappings-never-get-applied-to-ldap-groups/76127>\
**Category:** Elasticsearch\
**Created:** [February 23, 2017, 12:49am UTC](https://discuss.elastic.co/t/x-pack-5-2-1-role-mappings-never-get-applied-to-ldap-groups/76127 "2017-02-23T00:49:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mojogitoverhere](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@mojogitoverhere](https://discuss.elastic.co/u/mojogitoverhere)\
**Post date:** [February 23, 2017, 12:49am UTC](https://discuss.elastic.co/t/x-pack-5-2-1-role-mappings-never-get-applied-to-ldap-groups/76127/1 "2017-02-23T00:49:03Z")

</div>

I am trying to setup X-Pack 5.2.1 with LDAP. The users are able to be authenticated and its groups are retrieved, but the roles defined in role\_mapping.yml never get applied to the user. I tried a simple test by adding all the groups associated with a user to the superuser role. I also double checked that the spelling of the groups in the elasticsearch.log output and role\_mapping.yml is identical.

Is there something I am missing or is this a bug in X-Pack 5.2.1?  
Any help is appreciated!

###Debug output from elasticsearch.log

> [2017-02-22T23:54:40,499][DEBUG][o.e.x.s.a.s.DnRoleMapper] [RuChlI3] the roles [], are mapped from these [ldap] groups [[**group\_dn\_1, group\_dn\_2,...,group\_dn\_n**]] for realm [ldap/ldap1]  
> [2017-02-22T23:54:40,499][DEBUG][o.e.x.s.a.s.DnRoleMapper] [RuChlI3] the roles [], are mapped from the user [**user\_dn**] for realm [ldap/ldap1]  
> [2017-02-22T23:54:41,954][DEBUG][o.e.x.s.a.l.LdapRealm] [RuChlI3] authenticated user [**user\_cn**], with roles []

###role\_mapping.yml  
superuser:  
- group\_dn\_1  
- group\_dn\_2  
- ...  
- group\_dn\_n

###elasticsearch.yml  
xpack:  
security:  
audit:  
enabled: true  
authc:  
realms:  
ldap1:  
type: ldap  
order: 0  
url: "ldap://ldap.company.net:389"  
bind\_dn: "bind\_dn"  
bind\_password: "bind\_password"  
user\_search:  
base\_dn: "base\_dn"  
attribute: CN  
user\_group\_attribute: memberOf  
files:  
role\_mapping: "/etc/elasticsearch/x-pack/role\_mapping.xml"

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 23, 2017, 1:25am UTC](https://discuss.elastic.co/t/x-pack-5-2-1-role-mappings-never-get-applied-to-ldap-groups/76127/2 "2017-02-23T01:25:38Z")

</div>

> [@mojogitoverhere](#):
>
> Is there something I am missing or is this a bug in X-Pack 5.2.1?

I suspect the answer is somewhere in between.

For unfortunate historical reasons, if the `role_mapping` file doesn't exist, then elasticsearch starts up fine, but acts as if the role-mappings are empty, and doesn't provide much in the way of logging. ☹

> [@mojogitoverhere](#):
>
> role\_mapping: "/etc/elasticsearch/x-pack/role\_mapping.xml"

Double check that you've got the name of that file correct - I assume it should actually be `.yml` not `.xml`

---

<div class="post-metadata">

**Author:** ![mojogitoverhere](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@mojogitoverhere](https://discuss.elastic.co/u/mojogitoverhere)\
**Post date:** [February 23, 2017, 7:37pm UTC](https://discuss.elastic.co/t/x-pack-5-2-1-role-mappings-never-get-applied-to-ldap-groups/76127/3 "2017-02-23T19:37:54Z")

</div>

Thanks Tim! Using the right path to role\_mapping.yml did the trick!  
It's unfortunate that elasticsearch doesn't complain about anything but hopefully this post can point some people in the right direction.

---

<div class="post-metadata">

**Author:** ![Nautilus](https://avatars.discourse-cdn.com/v4/letter/n/b5ac83/32.png) [@Nautilus](https://discuss.elastic.co/u/Nautilus)\
**Post date:** [March 10, 2017, 5:11am UTC](https://discuss.elastic.co/t/x-pack-5-2-1-role-mappings-never-get-applied-to-ldap-groups/76127/4 "2017-03-10T05:11:55Z")

</div>

How did you get debug information?  
"[2017-02-22T23:54:40,499][DEBUG][o.e.x.s.a.s.DnRoleMapper] [RuChlI3] the roles [[]], are mapped from these [ldap] groups [[group\_dn\_1, group\_dn\_2,...,group\_dn\_n]] for realm [ldap/ldap1]"

I have similar situation with version 5.2.2.  
I can login to kibana, but I can not see superuser views.

[2017-03-08T10:13:21,587] [transport] [access\_granted] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[my\_account], action=[cluster:admin/xpack/security/user/authenticate], request=[AuthenticateReq  
uest]  
[2017-03-08T10:13:21,589] [transport] [access\_denied] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[my\_account], action=[indices:data/read/search], indices=[.reporting-\*], request=[SearchRequest  
]

---

<div class="post-metadata">

**Author:** ![mojogitoverhere](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@mojogitoverhere](https://discuss.elastic.co/u/mojogitoverhere)\
**Post date:** [March 10, 2017, 5:38am UTC](https://discuss.elastic.co/t/x-pack-5-2-1-role-mappings-never-get-applied-to-ldap-groups/76127/5 "2017-03-10T05:38:16Z")

</div>

From the [LDAP docs](https://www.elastic.co/guide/en/x-pack/current/security-troubleshooting.html#_ldap):

> To help track down these possibilities, add the following lines to the end of the log4j2.properties configuration file in the CONFIG\_DIR:

> logger.authc.name = org.elasticsearch.xpack.security.authc  
> logger.authc.level = DEBUG

The Debian and RPM packages set the config directory location to /etc/elasticsearch/.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2017, 5:38am UTC](https://discuss.elastic.co/t/x-pack-5-2-1-role-mappings-never-get-applied-to-ldap-groups/76127/6 "2017-04-07T05:38:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
