# Mongodb rs cluster ldap configuration

**URL:** <https://forums.percona.com/t/mongodb-rs-cluster-ldap-configuration/7781>\
**Category:** Percona Server for MongoDB\
**Tags:** community, troubleshooting, percona, mongodb\
**Created:** [July 17, 2020, 1:53am UTC](https://forums.percona.com/t/mongodb-rs-cluster-ldap-configuration/7781 "2020-07-17T01:53:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bsiara](https://avatars.discourse-cdn.com/v4/letter/b/c89c15/32.png) [@bsiara](https://forums.percona.com/u/bsiara)\
**Post date:** [July 17, 2020, 1:53am UTC](https://forums.percona.com/t/mongodb-rs-cluster-ldap-configuration/7781/1 "2020-07-17T01:53:29Z")

</div>

Hi, I want to swich my rs cluster from sasl-ldap to direct ldap conection, this is my configuration:

```auto
systemLog:
destination: file
path: /data/mongod.log
logAppend: true
logRotate: reopen
component:
accessControl:
verbosity: 5
storage:
engine: wiredTiger
dbPath: /data/db
directoryPerDB: true
journal:
enabled: true
wiredTiger:
engineConfig:
cacheSizeGB: 1
directoryForIndexes: true
processManagement:
fork: true
net:
bindIp: 127.0.0.1,192.168.0.20
port: 27017
operationProfiling:
slowOpThresholdMs: 100
replication:
replSetName: rs1
oplogSizeMB: 256
security:
keyFile: /data/keyfile
clusterAuthMode: keyFile
authorization: enabled
ldap:
servers: 'ldap.domain.com:10389'
transportSecurity: 'none'
bind:
method: 'simple'
queryUser: 'uid=nobody,ou=people,dc=domain,dc=com'
queryPassword: 'pass123'
userToDNMapping:
'[
{
match: "(.+)",
ldapQuery: "ou=people,dc=domain,dc=com??sub?(&amp;(uid={0})(!(pwdAccountLockedTime=*))(!(description=tech)))"
}
]'
authz:
queryTemplate: 'ou=groups,dc=domain,dc=com??sub?(&amp;(objectClass=groupOfUniqueNames)(description=mongo)(uniqueMember={USER}))'
setParameter:
authenticationMechanisms: "PLAIN,SCRAM-SHA-1,SCRAM-SHA-256"

```

next create user in $external database:

```auto
&gt; db.createUser({"user": "user", "roles": [{"role": "read", "db": "db1"}], "mechanisms": ["PLAIN"] })
Successfully added user: {
	"user" : "user",
	"roles" : [
		{
			"role" : "read",
			"db" : "db1"
		}
	],
	"mechanisms" : [
		"PLAIN"
	]
}

```

during connection to mongo I get error:

```auto
&gt; db.auth({"mechanism": "PLAIN", "user": "user", "pwd": passwordPrompt(), "digestPassword ": false})
Enter password: 
Error: SASL(-4): no mechanism available: No worthy mechs found
0

```

In my ldap I store passwords in two hash:

```auto
sambaNTPassword
userPassword: ssha hash

```

Please help me, what I’m doing wrong?

---

<div class="post-metadata">

**Author:** ![Igor\_Solodovnikov](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/igor_solodovnikov/32/1265_2.png) [@Igor\_Solodovnikov](https://forums.percona.com/u/Igor_Solodovnikov)\
**Post date:** [July 17, 2020, 6:27am UTC](https://forums.percona.com/t/mongodb-rs-cluster-ldap-configuration/7781/2 "2020-07-17T06:27:27Z")

</div>

Hello @bsiara   
have you tried to authorize from the command line like this:

```auto
mongo -u "user" -p --authenticationDatabase '$external' --authenticationMechanism 'PLAIN'

```

Does it return the same error?  
What LDAP server do you use?  
One note: you don’t need to add LDAP user to the $external database. With native LDAP authentication this is not necessary. (But this is not the reason of the issue).

---

<div class="post-metadata">

**Author:** ![bsiara](https://avatars.discourse-cdn.com/v4/letter/b/c89c15/32.png) [@bsiara](https://forums.percona.com/u/bsiara)\
**Post date:** [July 17, 2020, 2:18pm UTC](https://forums.percona.com/t/mongodb-rs-cluster-ldap-configuration/7781/3 "2020-07-17T14:18:26Z")

</div>

Thanks for your reply, using mongo cmd I get the same error:

```auto
mongo -u "user" -p --authenticationDatabase '$external' --authenticationMechanism 'PLAIN'
Percona Server for MongoDB shell version v4.2.8-8
Enter password: 
connecting to: mongodb://127.0.0.1:27017/?authMechanism=PLAIN&amp;authSource=%24external&amp;compressors=disabled&amp;gssapiServiceName=mongodb
2020-07-17T19:41:52.396+0000 E QUERY [js] Error: SASL(-4): no mechanism available: No worthy mechs found :
connect@src/mongo/shell/mongo.js:341:17
@(connect):3:6
2020-07-17T19:41:52.401+0000 F - [main] exception: connect failed
2020-07-17T19:41:52.401+0000 E - [main] exiting with code 1

```

As ldap server I use Apache Directory Server. Ok, I deleted user on $external database, but the same error occur.

---

<div class="post-metadata">

**Author:** ![Igor\_Solodovnikov](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/igor_solodovnikov/32/1265_2.png) [@Igor\_Solodovnikov](https://forums.percona.com/u/Igor_Solodovnikov)\
**Post date:** [August 11, 2020, 6:25am UTC](https://forums.percona.com/t/mongodb-rs-cluster-ldap-configuration/7781/4 "2020-08-11T06:25:03Z")

</div>

Hello @bsiara,  
Your configuration looks good. I don’t know exactly what is going wrong. To debug it I would try to execute LDAP query using ‘ldapsearch’ utility from the openldap package. Something like this:

```auto
ldapsearch -h ldap.domain.com -p 10389 -v -w pass123 -D uid=nobody,ou=people,dc=domain,dc=com -L -b ou=people,dc=domain,dc=com -s sub

```

With this command you can ensure that your LDAP server accepts connections.  
Also you can try to switch bind mode from ‘simple’ to ‘sasl’.
