Isso será possível até o final de maio, quando o componente LDAP for lançado, veja o link . O sg_config.yml ficará assim:
searchguard: dynamic: http: xff: enabled: true internalProxies: 192\.168\.0\.10|192\.168\.0\.11 remoteIpHeader: "x-forwarded-for" proxiesHeader: "x-forwarded-by" trustedProxies: "proxy1|proxy2" authenticator: type: proxy config: user_header: "x-proxy-user" roles_header: "x-proxy-roles" authcz: authentication_domain_proxy: enabled: true order: 0 authentication_backend: type: ldap config: host: "ldapserver:389" usersearch: "(uid={0})" authorization_backend: type: ldap config: host: "ldapserver:389" rolesearch: "(uniqueMember={0})" resolve_nested_roles: true rolebase: "ou=groups,o=TEST" rolename: cn
Pls. siga o link