# Ldap Authorization failure

**URL:** https://forum.search-guard.com/t/ldap-authorization-failure/501
**Category:** Search Guard
**Created:** [July 1, 2017, 7:08am UTC](https://forum.search-guard.com/t/ldap-authorization-failure/501 "2017-07-01T07:08:30Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![Swamy\_Karampuri](https://avatars.discourse-cdn.com/v4/letter/s/d07c76/32.png) [@Swamy\_Karampuri](https://forum.search-guard.com/u/Swamy_Karampuri)
#### Post date: [July 1, 2017, 7:08am UTC](https://forum.search-guard.com/t/ldap-authorization-failure/501/1 "2017-07-01T07:08:30Z")

</div>

Hello Team,

I would like to Integrate search guard with LDAP, I able to authenticate users in searchguard but unable to authorize with the roles I have configured in the LDAP. I don’t see any errors in the logs.

Here is the scenario that I am trying to achieve.

I have two roles configured in my LDAP.

Level1 - Users under this role should have access to only perticular indexes.

Level2 - Users under this role should have access to all the indexes.

Below is the maping that I have specified in the sg\_roles\_mapping.yml

globalrole:

backend\_role:

- ‘Level1’

- ‘cn=globalrole,dc=test,dc=com’

hosts:

- xxx.xxx.x.xx:xxx

Below is the configuration that I have specified in the sg\_roles.yml

globalrole:

cluster:

- CLUSTER\_COMPOSITE\_OPS\_RO

indices:

‘abc\*’:

‘\*’:

- CRUD

‘xyz’:

‘\*’:

- READ

‘?kibana’:

‘\*’:

- ALL

Also attaching the LDAP configurationt that I have specified in sg\_config.yml

Please suggest me where I am going wrong.

Thanks

Swamy

[LDAP config](https://forum.search-guard.com/uploads/short-url/oriWuS4He62KkG7iRB2UBxtVsKO) (1.5 KB)

---

<div class="post-metadata">

### Author: ![Swamy\_Karampuri](https://avatars.discourse-cdn.com/v4/letter/s/d07c76/32.png) [@Swamy\_Karampuri](https://forum.search-guard.com/u/Swamy_Karampuri)
#### Post date: [July 11, 2017, 3:21pm UTC](https://forum.search-guard.com/t/ldap-authorization-failure/501/2 "2017-07-11T15:21:14Z")

</div>

Hello Team,

Please let me know if you have any updates on my issue.

---

<div class="post-metadata">

### Author: ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)
#### Post date: [July 11, 2017, 4:09pm UTC](https://forum.search-guard.com/t/ldap-authorization-failure/501/3 "2017-07-11T16:09:02Z")

</div>

we are already working on it ...

> **···**
>
> > Am 11.07.2017 um 17:21 schrieb Swamy Karampuri \<swamykarampuri610@gmail.com\>:
> > 
> > Hello Team,
> > 
> > Please let me know if you have any updates on my issue.
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/4c3a8a83-ce6a-40a0-81ec-5076902efb14%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/4c3a8a83-ce6a-40a0-81ec-5076902efb14%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).

---

<div class="post-metadata">

### Author: ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)
#### Post date: [July 11, 2017, 6:51pm UTC](https://forum.search-guard.com/t/ldap-authorization-failure/501/4 "2017-07-11T18:51:55Z")

</div>

pls. send you complete sg\_role.yml and sg\_roles\_mapping.yml (as attachments)  
Seems like you yml is not indented correctly.

How does the DN for your Level1 role look like?

> **···**
>
> On Tuesday, 11 July 2017 17:21:14 UTC+2, Swamy Karampuri wrote:
> 
> > Hello Team,
> 
> > Please let me know if you have any updates on my issue.

---

<div class="post-metadata">

### Author: ![Swamy\_Karampuri](https://avatars.discourse-cdn.com/v4/letter/s/d07c76/32.png) [@Swamy\_Karampuri](https://forum.search-guard.com/u/Swamy_Karampuri)
#### Post date: [July 12, 2017, 8:28am UTC](https://forum.search-guard.com/t/ldap-authorization-failure/501/5 "2017-07-12T08:28:12Z")

</div>

Hello Team,

Here i am attaching sg\_config.yml ,sg\_roles\_mapping.yml and sg\_roles.yml.

please suggest me where i am going wrong.

Thanks,

swamy

[sg\_config.yml](https://forum.search-guard.com/uploads/short-url/hnj6XAyAnLoD9X2JvIDLCGoQ26K.yml) (7.31 KB)

[sg\_roles.yml](https://forum.search-guard.com/uploads/short-url/cijSTIiqTFgaC72Qu97OJ8uFn1a.yml) (5.25 KB)

[sg\_roles\_mapping.yml](https://forum.search-guard.com/uploads/short-url/pkDzq75bfqEFYBgEWtaRs8Ysp3Y.yml) (1.29 KB)

---

<div class="post-metadata">

### Author: ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)
#### Post date: [July 13, 2017, 7:28am UTC](https://forum.search-guard.com/t/ldap-authorization-failure/501/6 "2017-07-13T07:28:01Z")

</div>

your sg\_roles\_mapping.yml contains invalid yml (see [http://www.yamllint.com](http://www.yamllint.com))

> **···**
>
> > Am 12.07.2017 um 10:28 schrieb Swamy Karampuri \<swamykarampuri610@gmail.com\>:
> > 
> > Hello Team,
> > 
> > Here i am attaching sg\_config.yml ,sg\_roles\_mapping.yml and sg\_roles.yml.
> > 
> > please suggest me where i am going wrong.
> > 
> > Thanks,  
> > swamy
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/9b651396-76b4-4743-8628-3c32fdd91a02%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/9b651396-76b4-4743-8628-3c32fdd91a02%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).  
> > \<sg\_config.yml\>\<sg\_roles.yml\>\<sg\_roles\_mapping.yml\>

---

<div class="post-metadata">

### Author: ![Swamy\_Karampuri](https://avatars.discourse-cdn.com/v4/letter/s/d07c76/32.png) [@Swamy\_Karampuri](https://forum.search-guard.com/u/Swamy_Karampuri)
#### Post date: [July 14, 2017, 12:26pm UTC](https://forum.search-guard.com/t/ldap-authorization-failure/501/7 "2017-07-14T12:26:06Z")

</div>

Hello Team,

I have checked for the yml syntax, i able login with that group users but unable to view all and limited indexes based on role group.

I have two roles configured in my LDAP.

xxx - Users under this role should have access to only perticular indexes.

yyy - Users under this role should have access to all the indexes.

Here i am attaching my sg\_roles\_mapping.yml

please suggest me where i am missing.

Thank you

Swamy

[sg\_roles\_mapping.yml](https://forum.search-guard.com/uploads/short-url/9NCat00NatN2FwxwxPI8RdHQsjn.yml) (899 Bytes)

---

<div class="post-metadata">

### Author: ![Swamy\_Karampuri](https://avatars.discourse-cdn.com/v4/letter/s/d07c76/32.png) [@Swamy\_Karampuri](https://forum.search-guard.com/u/Swamy_Karampuri)
#### Post date: [July 17, 2017, 9:49am UTC](https://forum.search-guard.com/t/ldap-authorization-failure/501/8 "2017-07-17T09:49:25Z")

</div>

Hello Team,

Please let me know if you have any updates on my issue.

Thanks,

Swamy

---

<div class="post-metadata">

### Author: ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)
#### Post date: [July 17, 2017, 7:15pm UTC](https://forum.search-guard.com/t/ldap-authorization-failure/501/9 "2017-07-17T19:15:06Z")

</div>

Have you checked all your config files for valid yaml? Also the sg\_config.yml you posted is invalid.

Then in sg\_config.yml you set the challenge flag to true for both the ldap and the basic\_internal\_auth\_domain domain. You can only have one challenging authenticator.

What is your use case here, do you use Kibana?

Next, with your current config, please access ES directly, and log in with one of your LDAP users when the HTTP basic dialogue pops up. Then, access the authinfo endpoint which prints out information about the currently logged in user, including the roles:

/\_searchguard/authinfo

Pls. post the output here.

> **···**
>
> On Monday, July 17, 2017 at 11:49:26 AM UTC+2, Swamy Karampuri wrote:
> 
> > Hello Team,
> 
> > 
> 
> > Please let me know if you have any updates on my issue.
> 
> > 
> 
> > 
> 
> > 
> 
> > Thanks,
> 
> > Swamy
