# Undefined roles which was refered in demo configuration

**URL:** <https://forum.search-guard.com/t/undefined-roles-which-was-refered-in-demo-configuration/1463>\
**Category:** Search Guard\
**Created:** [April 27, 2019, 11:34am UTC](https://forum.search-guard.com/t/undefined-roles-which-was-refered-in-demo-configuration/1463 "2019-04-27T11:34:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![cdeng](https://avatars.discourse-cdn.com/v4/letter/c/e79b87/32.png) [@cdeng](https://forum.search-guard.com/u/cdeng)\
**Post date:** [April 27, 2019, 11:34am UTC](https://forum.search-guard.com/t/undefined-roles-which-was-refered-in-demo-configuration/1463/1 "2019-04-27T11:34:40Z")

</div>

Hi Team,

As I have noted that the roles\_mapping\_resolution is default to MAPPING\_ONLY. but in the sg\_roles\_mapping.yml, there are roles mapping like:

```auto
sg_all_access:
  readonly: true
  backendroles:
    - admin

sg_kibana_user:
  backendroles:
    - kibanauser

sg_manage_snapshots:
  readonly: true
  backendroles:
    - snapshotrestore

```

but i also noted that the backend roles _admin_, _kibanauser_, _snapshotrestore_ have not been defined in the sg\_roles.yml. and also sg\_internal\_users.yml use those undefined roles. do those roles has been predefined by SG?

Thanks.

–Charles.

---

<div class="post-metadata">

**Author:** ![cdeng](https://avatars.discourse-cdn.com/v4/letter/c/e79b87/32.png) [@cdeng](https://forum.search-guard.com/u/cdeng)\
**Post date:** [April 27, 2019, 4:08pm UTC](https://forum.search-guard.com/t/undefined-roles-which-was-refered-in-demo-configuration/1463/2 "2019-04-27T16:08:40Z")

</div>

i eventually found the roles used by internal user database do not necessarily be defined in the roles. only those in the results of _internal user database_ \* _roles mapping_ should be defined in the roles if using internal user database as the backend.

it is something trickly…

thanks.

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [April 28, 2019, 7:13am UTC](https://forum.search-guard.com/t/undefined-roles-which-was-refered-in-demo-configuration/1463/3 "2019-04-28T07:13:41Z")

</div>

The mapping step is there to being able to map any users and backend roles to SG roles, regardless where they are coming from. Think of backend roles as roles that come from any of the configured auth/auth backends. For example, backend roles can be:

- LDAP groups
- JWT claims
- SAML assertions

It is best explained by using the LDAP case: We first authenticate the user via an LDAP search, then fetch the user’s LDAP roles, and then map the user to one or more SG role:

> **[Main concepts](https://docs.search-guard.com/latest/main-concepts#authentication-flow)**
>
> How Search Guard extracts credentials from a request and how they are mapped to users, roles and permissions.

So in that sense the configured backend roles for the internal users behave exactly like LDAP groups. After the user is authenticated, we take the username and the backend roles and map them to SG roles.

The default mappings are there to make it easier to assign users to standard roles, like a Kibana user, snapshot/restore or an admin user. If you want to give an internal user access to Kibana, you would just assign the _kibanauser_ backend role to the account in _sg\_internal\_users.yml_, and the default mapping takes care of assigning the user to the sg\_kibana\_user SG role.

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [April 28, 2019, 7:13am UTC](https://forum.search-guard.com/t/undefined-roles-which-was-refered-in-demo-configuration/1463/4 "2019-04-28T07:13:48Z")

</div>



---

<div class="post-metadata">

**Author:** ![cdeng](https://avatars.discourse-cdn.com/v4/letter/c/e79b87/32.png) [@cdeng](https://forum.search-guard.com/u/cdeng)\
**Post date:** [April 28, 2019, 7:22am UTC](https://forum.search-guard.com/t/undefined-roles-which-was-refered-in-demo-configuration/1463/5 "2019-04-28T07:22:58Z")

</div>

it is easy wrongly think the roles refered in the sg\_internal\_users as sg roles. indeed they are backend roles. and only those roles defined in the sg\_roles.yml configuration are sg roles.

–charles

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [April 28, 2019, 7:25am UTC](https://forum.search-guard.com/t/undefined-roles-which-was-refered-in-demo-configuration/1463/6 "2019-04-28T07:25:25Z")

</div>

I know this can be confusing, but we definitely need the role mapping step when working with LDAP, JWT etc. If you have an idea about how to make that concept easier / explain it better / make it more obvious I’d really like to hear! Thx!

---

<div class="post-metadata">

**Author:** ![cdeng](https://avatars.discourse-cdn.com/v4/letter/c/e79b87/32.png) [@cdeng](https://forum.search-guard.com/u/cdeng)\
**Post date:** [April 28, 2019, 7:35am UTC](https://forum.search-guard.com/t/undefined-roles-which-was-refered-in-demo-configuration/1463/7 "2019-04-28T07:35:41Z")

</div>

it maybe more straight forward if we take roles\_mapping\_resolution and sg\_roles\_mapping defined for each backend instead of take them as global configurations.

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [April 28, 2019, 8:08am UTC](https://forum.search-guard.com/t/undefined-roles-which-was-refered-in-demo-configuration/1463/8 "2019-04-28T08:08:49Z")

</div>

I actually like the idea. I’ve created a ticket in our backlog for internal discussion. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/system/32/1870_2.png) [@system](https://forum.search-guard.com/u/system)\
**Post date:** [May 19, 2019, 8:08am UTC](https://forum.search-guard.com/t/undefined-roles-which-was-refered-in-demo-configuration/1463/9 "2019-05-19T08:08:49Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
