# Solved: Cannot Login with LDAP User and Password

**URL:** <https://forum.keycloak.org/t/solved-cannot-login-with-ldap-user-and-password/26576>\
**Category:** Getting advice\
**Created:** [June 19, 2024, 4:03pm UTC](https://forum.keycloak.org/t/solved-cannot-login-with-ldap-user-and-password/26576 "2024-06-19T16:03:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![gareththered](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/gareththered/32/10568_2.png) [@gareththered](https://forum.keycloak.org/u/gareththered)\
**Post date:** [June 19, 2024, 4:03pm UTC](https://forum.keycloak.org/t/solved-cannot-login-with-ldap-user-and-password/26576/1 "2024-06-19T16:03:16Z")

</div>

I’ve just installed OpenLDAP to store user info. I’ve added it as a User Federation source in Keycloak and it seems to work. It syncs, and if I set the password in Keycloak I can verify that it’s changed in OpenLDAP by using Apache Directory Studio to verify the password. So far, so good.

However, when I try to login at the security admin console of the realm using the sameLDAP user, it point blank refuses to accept the password. The Keycloak logs don’t say much - “invalid\_user\_credentials” and OpenLDAP logs say nothing at all.

Does anyone have any advice on how to debug this? Or am I missing something obvious?

Thanks, Gareth

---

<div class="post-metadata">

**Author:** ![gareththered](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/gareththered/32/10568_2.png) [@gareththered](https://forum.keycloak.org/u/gareththered)\
**Post date:** [June 19, 2024, 8:08pm UTC](https://forum.keycloak.org/t/solved-cannot-login-with-ldap-user-and-password/26576/2 "2024-06-19T20:08:16Z")

</div>

It was down to the ACLs in the end - `anonymous auth` ACL was blocked as I’d added an new ACL at the top of the list `{0}` which gave `manage` permission to a manager account, but forgot to add `* break` to the end.

Apache Directory Studio was connecting with this manager account, so that was working.
