# User lost permissions after LDAP connection error

**URL:** <https://forum.opensearch.org/t/user-lost-permissions-after-ldap-connection-error/3079>\
**Category:** Security\
**Created:** [June 16, 2020, 1:21pm UTC](https://forum.opensearch.org/t/user-lost-permissions-after-ldap-connection-error/3079 "2020-06-16T13:21:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![gferrette](https://avatars.discourse-cdn.com/v4/letter/g/bbce88/32.png) [@gferrette](https://forum.opensearch.org/u/gferrette)\
**Post date:** [June 16, 2020, 1:21pm UTC](https://forum.opensearch.org/t/user-lost-permissions-after-ldap-connection-error/3079/1 "2020-06-16T13:21:37Z")

</div>

Hello!

We are currently using OpenDistro 1.0.2 with LDAP authentication, and after an LDAP comunication error, the user lost his privileges on the next logins as the error below:  
The only way that i found to restore his privileges was restarting kibana.

Fisrt login error:  
[2020-06-15T17:46:36,166][WARN][c.a.o.s.a.BackendRegistry] [machine] Authentication finally failed for user1 from IP:PORT

Next errors (user1 loses privileges on the next login)  
[2020-06-15T17:47:04,886][ERROR][c.a.o.s.a.BackendRegistry] [machine] Cannot retrieve roles for User [name=user1, roles=, requestedTenant=null] from ldap due to ElasticsearchSecurityException[[org.ldaptive.LdapException@1928995427::resultCode=null, matchedDn=null, responseControls=null, referralURLs=null, messageId=-1, message=Unable to connect to any of those ldap servers [machine:port] due to [org.ldaptive.provider.ConnectionException@785886331::resultCode=PROTOCOL\_ERROR, matchedDn=null, responseControls=null, referralURLs=null, messageId=-1, message=javax.naming.CommunicationException:

[2020-06-15T17:47:13,513][INFO][c.a.o.s.p.PrivilegesEvaluator] [machine] No index-level perm match for User [name=user1, roles=, requestedTenant=null]

Do you guys know how to solve this issue? The user1 was able to login even with those privileges errors

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Anthony](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/anthony/32/9939_2.png) [@Anthony](https://forum.opensearch.org/u/Anthony)\
**Post date:** [April 12, 2021, 12:12pm UTC](https://forum.opensearch.org/t/user-lost-permissions-after-ldap-connection-error/3079/2 "2021-04-12T12:12:38Z")

</div>

@gferrette Did you manage to resolve this issue? Have you tried newer version of odfe? Does the issue still persist?
