# \[Ann\] elasticsearch-security-plugin: Updated for ES 1.x.x and latest EA 0.90.x releases

**URL:** <https://discuss.elastic.co/t/ann-elasticsearch-security-plugin-updated-for-es-1-x-x-and-latest-ea-0-90-x-releases/16694>\
**Category:** Elasticsearch\
**Created:** [March 29, 2014, 2:16pm UTC](https://discuss.elastic.co/t/ann-elasticsearch-security-plugin-updated-for-es-1-x-x-and-latest-ea-0-90-x-releases/16694 "2014-03-29T14:16:48Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hendrik](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@Hendrik](https://discuss.elastic.co/u/Hendrik)\
**Post date:** [March 29, 2014, 2:16pm UTC](https://discuss.elastic.co/t/ann-elasticsearch-security-plugin-updated-for-es-1-x-x-and-latest-ea-0-90-x-releases/16694/1 "2014-03-29T14:16:48Z")

</div>

Hi,

i'd like to announce a update of the Elasticsearch Security Plugin which  
now also works for ES 1.x.x and latest EA 0.90.x releases

It can be found here:  
[https://github.com/salyh/elasticsearch-security-plugin](https://github.com/salyh/elasticsearch-security-plugin) (early development  
stage, not for production yet)

This plugin adds http/rest security functionality to Elasticsearch in kind  
of separate modules. Instead of Netty a embedded Tomcat 7 is used to  
process http/rest requests.

Currently for user based authentication and authorization Kerberos/SPNEGO  
and NTLM are supported through 3rd party library waffle (only on windows  
servers). For UNIX servers Kerberos/SPNEGO is supported through tomcat  
build in SPNEGO Valve (Works with any Kerberos implementation. For  
authorization either Active Directory and generic LDAP is supported).  
PKI/SSL client certificate authentication is also supported (CLIENT-CERT  
method). SSL/TLS is also supported without client authentication.

You can use this plugin also without Kerberos/NTLM/PKI but then only host  
based authentication is available.

As of now two security modules are implemented:  
Actionpathfilter: Restrict actions against Elasticsearch on a  
coarse-grained level like who is allowed to to READ, WRITE or even ADMIN  
rest api calls  
Document level security (dls): Restrict actions on document level like who  
is allowed to query for which fields within a document

Suggestions, corrections, improvements are very welcome!  
Thanks and best regards  
Hendrik

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/85b4d3f9-dda4-4cdd-8b0d-552416b41d7d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/85b4d3f9-dda4-4cdd-8b0d-552416b41d7d%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:39am UTC](https://discuss.elastic.co/t/ann-elasticsearch-security-plugin-updated-for-es-1-x-x-and-latest-ea-0-90-x-releases/16694/2 "2017-07-06T01:39:45Z")

</div>


