# LDAP/AD authentication

**URL:** <https://forum.search-guard.com/t/ldap-ad-authentication/2218>\
**Category:** Search Guard\
**Created:** [September 21, 2021, 2:21pm UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218 "2021-09-21T14:21:05Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![geetha](https://avatars.discourse-cdn.com/v4/letter/g/f08c70/32.png) [@geetha](https://forum.search-guard.com/u/geetha)\
**Post date:** [September 21, 2021, 2:21pm UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218/1 "2021-09-21T14:21:05Z")

</div>

Need help to setup authentication for Kibana.  
\*\*Elasticsearch version: 6.8.6

\*\*Server OS version: REHL 7

\*\*Kibana version (if relevant): 6.8.6

\*\*Describe the issue: Need to setup LDAP/AD/SAML for Kibana authentication. We have TLS and JWT authentication setup already for Elasticsearch. Kibana authentication is basic with self signed certs. Please let me know any suggestions or documentation.

---

<div class="post-metadata">

**Author:** ![sirHusky](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sirHusky](https://forum.search-guard.com/u/sirHusky)\
**Post date:** [September 22, 2021, 4:01pm UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218/2 "2021-09-22T16:01:26Z")

</div>

@geetha SearchGuard 25.5 (ES 6.8.6) is EOL, I would recommend to upgrade to a newer version.

The documentation for [LDAP](https://docs.search-guard.com/6.x-25/active-directory-ldap-connection) and [SAML](https://docs.search-guard.com/6.x-25/saml-authentication)

Hope this helps

---

<div class="post-metadata">

**Author:** ![geetha](https://avatars.discourse-cdn.com/v4/letter/g/f08c70/32.png) [@geetha](https://forum.search-guard.com/u/geetha)\
**Post date:** [September 27, 2021, 2:24pm UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218/3 "2021-09-27T14:24:03Z")

</div>

Thank you for the reply. I did setup LDAP/AD with in the documentation which you have provided. but still Kibana is authenticating with self signed certs. is there any other changes I should make in the kibana.yml file? can you please share any other information where I need to change other congig files. I am looking for only Kibana authentication with LDAP/AD not Elasticsearch.

Thanks,  
Geetha

---

<div class="post-metadata">

**Author:** ![sirHusky](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sirHusky](https://forum.search-guard.com/u/sirHusky)\
**Post date:** [September 27, 2021, 4:22pm UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218/4 "2021-09-27T16:22:39Z")

</div>

Hi @geetha  
I’m not fully following your question.

Can you please elaborate on the current behaviour and the expected behaviour.

Also could you please retrieve currently security config from security index using command below and provide these (redact any sensitive details)

`./sgadmin.sh -icl -key .../config/kirk-key.pem -cert .../config/kirk.pem -cacert .../config/root-ca.pem -nhnv -r`

Also, kibana.yml config please

---

<div class="post-metadata">

**Author:** ![geetha](https://avatars.discourse-cdn.com/v4/letter/g/f08c70/32.png) [@geetha](https://forum.search-guard.com/u/geetha)\
**Post date:** [September 27, 2021, 8:25pm UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218/5 "2021-09-27T20:25:32Z")

</div>

I have taken out all teh sensitive information. Kibana authentication is working completly fine with self signed certs. After enabling Ldap still it is signing with certs not with LDAP integration. I am getting error as "Authentication finally failed: when I test it with sudo curl -Ss -k “[https://host:9200/\_cluster/health](https://host:9200/_cluster/health)”

kibana.yml  
server.port: 5601  
server.host: “hostcom”  
server.name: “[host.com](http://host.com)”

elasticsearch.url: “[https://eshost.com:9200](https://eshost.com:9200)”

elasticsearch.preserveHost: true

kibana.index: “.kibana”

searchguard.basicauth.enabled: false  
searchguard.cookie.name: searchguard\_authentication  
searchguard.cookie.secure: true

elasticsearch.requestHeadersWhitelist: [“Authorization”, “sgtenant”, “x-forwarded-for”, “x-forwarded-by”]  
elasticsearch.username: user  
elasticsearch.password: pw

elasticsearch.ssl.alwaysPresentCertificate: true  
searchguard.allow\_client\_certificates: true

server.ssl.enabled: true  
server.ssl.certificate: keystore.pem  
server.ssl.key: key.pem

elasticsearch.ssl.certificateAuthorities: “cert.pem”

elasticsearch.ssl.verificationMode: none

elasticsearch.ssl.certificate: cert.pem

elasticsearch.ssl.key: key.pem

logging.dest: /var/log/kibana/kibana.log

logging.verbose: true

* * *

## /sg\_config.yml

searchguard:  
dynamic:  
kibana:  
do\_not\_fail\_on\_forbidden: true  
license: “LS”  
http:  
anonymous\_auth\_enabled: false  
xff:  
enabled: false  
internalProxies: "._"  
remoteIpHeader: “x-forwarded-for”  
proxiesHeader: “x-forwarded-by”  
authc:  
jwt\_auth\_domain:  
enabled: true  
order: 0  
http\_authenticator:  
type: “jwt”  
challenge: false  
config:  
signing\_key: “MI”  
jwt\_header: “Authorization”  
jwt\_url\_parameter: null  
roles\_key: “scope”  
subject\_key: “user\_name”  
authentication\_backend:  
type: “noop”  
jwt\_auth\_domain\_app:  
enabled: true  
order: 1  
http\_authenticator:  
type: “jwt”  
challenge: false  
config:  
signing\_key: “MI”  
jwt\_header: “Authorization”  
jwt\_url\_parameter: null  
roles\_key: “scope”  
subject\_key: “client\_id”  
authentication\_backend:  
type: “noop”  
ldap:  
http\_enabled: true  
order: 1  
http\_authenticator:  
type: basic  
challenge: false  
authentication\_backend:  
type: ldap  
config:  
enable\_ssl: true  
enable\_start\_tls: false  
enable\_ssl\_client\_auth: false  
verify\_hostnames: true  
hosts:  
- [ldap.com:636](http://ldap.com:636)  
bind\_dn: CN=cn,OU=Users,OU=Fun,OU=myou,DC=mygroup,DC=com  
password: pw  
userbase: OU=myou,DC=mygroup,DC=com  
usersearch: ‘(member={0})’  
username\_attribute: memberof  
rolebase: DC=mygroup,DC=com  
rolesearch: (&(objectClass=groupOfNames)(cn=_{0}_))  
userroleattribute: null  
userrolename: memberof  
rolename: group  
resolve\_nested\_roles: true  
authz:  
ldap:  
enabled: true  
autherization\_backend:  
type: ldap  
config:  
enable\_ssl: true  
enable\_start\_tls: false  
enable\_ssl\_client\_auth: false  
verify\_hostnames: true  
hosts:  
- [ldap.com:636](http://ldap.com:636)  
bind\_dn: CN=cn,OU=Users,OU=Fun,OU=myou,DC=mygroup,DC=com  
password: pw  
userbase: [“OU=myou,DC=mygroup,DC=com”]  
usersearch: ‘(memberof={0})’  
username\_attribute: memberof  
rolebase: OU=myou,DC=mygroup,DC=com  
rolesearch: (&(objectClass=groupOfNames)(cn=_{0}\*))  
userroleattribute: null  
userrolename: memebrof  
rolename: groupof  
resolve\_nested\_roles: true

---

<div class="post-metadata">

**Author:** ![sirHusky](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sirHusky](https://forum.search-guard.com/u/sirHusky)\
**Post date:** [September 28, 2021, 9:53am UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218/6 "2021-09-28T09:53:38Z")

</div>

@geetha

Can you remove below line from kibana.yml?

`searchguard.basicauth.enabled: false`

I see in kibana.yml you are using both basic auth and cert

```auto
elasticsearch.username: user
elasticsearch.password: pw

```

and

```auto
elasticsearch.ssl.certificate: cert.pem
elasticsearch.ssl.key: key.pem

```

You should choose one method, also in sg\_config.yml the cert\_auth is not enabled, therefore I’m not sure how your kibana is authenticating via certs.

I think there is some confusion around how ldap calls work.

Kibana can authenticate with basic auth (ldap) or cert, although basic auth is highly recommended as it might be challenging to extract user from ldap, as certificate provided from kibana has its own user assigned.

Therefore the sg\_config.yml file, should have just basic\_auth and ldap enabled (I noticed you also have 2 domains enabled for JWT - are these actually needed?)

If the above is configured the flow will be as follows:

Kibana authenticates with elasticsearch using ldap (username/password),

User accesses kibana and enters username and password, which are then queried against ldap, if successful the roles are retrieved via second call (authz) and user is able to navigate in kibana.

It is important to note that ldap authentication is on elasticsearch side, kibana is just a front end for users to enter details.

Is this the workflow that you are looking for?

---

<div class="post-metadata">

**Author:** ![geetha](https://avatars.discourse-cdn.com/v4/letter/g/f08c70/32.png) [@geetha](https://forum.search-guard.com/u/geetha)\
**Post date:** [September 28, 2021, 1:41pm UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218/7 "2021-09-28T13:41:43Z")

</div>

Its a little complicated environment where we need both basic auth and certs should be enabled for a reason. yes JWT is used for something else. only thing I am looking for is Kibana should authenticate with LDAP and JWT is for other apps. I tried curl -Ss -k [https://hostname:9200/\_cluster/health](https://hostname:9200/_cluster/health) and I am getting authentication failed or unauthorized when I adjust LDAP configuration.  
Thanks for your response.

Thanks,  
geetha

---

<div class="post-metadata">

**Author:** ![geetha](https://avatars.discourse-cdn.com/v4/letter/g/f08c70/32.png) [@geetha](https://forum.search-guard.com/u/geetha)\
**Post date:** [September 28, 2021, 2:13pm UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218/8 "2021-09-28T14:13:03Z")

</div>

Hello SirHusky,

Thank you for your reply and giving us the suggestions. We are using certs to talk to Elasticsearch host from Kibana host. And username is using to authenticate Kibana as basic auth. We have tried without certs using basic auth didn’t work. That’s the reason we are using both “basic auth” and “certs”. I am trying to get LDAP integration as first step to test with curl -Ss -k “hostname:9200/\_cluster/health” which is failing as authentication and sometimes error message as unauthorized. Is there any other configuration changes to be made on sg\_config.yml file. Once I get first step setup then will go back to Kibana and adjust kibana configuration file to get LDAP authentication. Please let me know if you have any other questions.

Thanks,

Geetha

---

<div class="post-metadata">

**Author:** ![sirHusky](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sirHusky](https://forum.search-guard.com/u/sirHusky)\
**Post date:** [September 28, 2021, 3:29pm UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218/9 "2021-09-28T15:29:42Z")

</div>

Hi Geetha,  
The basic auth is disabled according to your sg\_config.yml, therefore kibana would not be able to authenticate via basic auth, unless by basic auth you mean LDAP.  
The username and password that you are supplying under elasticsearch.username and password, is that user present in LDAP? Or do you want to use built in user database that comes with Search Guard plugin, in which case you will need to enable basic\_auth in sg\_config.yml. The default kibana username and password is kibanaserver/kibanaserver. If you changed the username, you will need to map it to the SGS\_KIBANA\_SERVER role via sg\_roles\_mappings.yml file and upload config via sgadmin.sh script.

The curl command you are using doesn’t provide any user credentials therefore there is no reason why it would be Authorised. You would need to supply -u {username}:{password} (of user present in LDAP - since basic auth is disabled).

I think the best way forward is to remove LDAP entirely for the time being and get kibana to connect using basic auth (without using certificate). Once that is working as expect, it should be straight forward to add LDAP integration.

I can guide you through this process if you want to proceed?

---

<div class="post-metadata">

**Author:** ![geetha](https://avatars.discourse-cdn.com/v4/letter/g/f08c70/32.png) [@geetha](https://forum.search-guard.com/u/geetha)\
**Post date:** [September 28, 2021, 3:54pm UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218/10 "2021-09-28T15:54:25Z")

</div>

Sure, Thank you so much for your input. sorry my bad I was passing my id and pw along with curl command. yes we are using custom kibana user and I did map this to sg\_roles\_mappings.yml. I would like to work with you to solve this issue. are you working with SAS support? is it possible for us to schedule a call and work on it?

Thanks,  
Geetha

---

<div class="post-metadata">

**Author:** ![geetha](https://avatars.discourse-cdn.com/v4/letter/g/f08c70/32.png) [@geetha](https://forum.search-guard.com/u/geetha)\
**Post date:** [October 4, 2021, 6:40pm UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218/11 "2021-10-04T18:40:30Z")

</div>

Is there anyway we can use certs to communicate with kibana and elasticsearch hosts and kibana authentication is with AD?

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/system/32/1870_2.png) [@system](https://forum.search-guard.com/u/system)\
**Post date:** [October 25, 2021, 6:40pm UTC](https://forum.search-guard.com/t/ldap-ad-authentication/2218/12 "2021-10-25T18:40:45Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
