# Can I use ES roles with security disabled?

**URL:** <https://discuss.elastic.co/t/can-i-use-es-roles-with-security-disabled/318861>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, docker\
**Created:** [November 14, 2022, 10:51am UTC](https://discuss.elastic.co/t/can-i-use-es-roles-with-security-disabled/318861 "2022-11-14T10:51:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![powerful\_clouds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/powerful_clouds/32/113213_2.png) [@powerful\_clouds](https://discuss.elastic.co/u/powerful_clouds)\
**Post date:** [November 14, 2022, 10:51am UTC](https://discuss.elastic.co/t/can-i-use-es-roles-with-security-disabled/318861/1 "2022-11-14T10:51:23Z")

</div>

I'm trying to use field-level security with ES. I have successfully created an index and populated it with some data. I have also defined a `roles.yml` file:

```auto
regular:
  cluster: all
  indices:
    - names: ['log-index']
      privileges: ['read']
      field_security:
        grant: ['redacted_log']      

```

and a `role-mapping.yml` file:

```auto
regular:
  - "cn=john"

```

In the `Dockerfile`, I've added `RUN elasticsearch-users useradd john -p 123456 -r regular` in order to create the user `john` when the container starts.  
What I would like to achieve is that the user `john` can only access the `redacted_log` field, since that user has a `regular` role.

Because of [this](https://discuss.elastic.co/t/cant-start-elasticsearch-8-5-with-docker/318029/9) issue, I have security disabled in the `elasticsearch.yml` file. Can I even use roles when security is disabled?

If yes, how can I test that `john` only has access to the `redacted_log` field in documents that are present in `log_index`?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 14, 2022, 11:14am UTC](https://discuss.elastic.co/t/can-i-use-es-roles-with-security-disabled/318861/2 "2022-11-14T11:14:22Z")

</div>

> [@powerful\_clouds](#):
>
> Because of [this](https://discuss.elastic.co/t/cant-start-elasticsearch-8-5-with-docker/318029/9) issue, I have security disabled in the `elasticsearch.yml` file. Can I even use roles when security is disabled?

No, you need to enable security and use a suitable license to get access to field level security.

---

<div class="post-metadata">

**Author:** ![powerful\_clouds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/powerful_clouds/32/113213_2.png) [@powerful\_clouds](https://discuss.elastic.co/u/powerful_clouds)\
**Post date:** [November 14, 2022, 11:15am UTC](https://discuss.elastic.co/t/can-i-use-es-roles-with-security-disabled/318861/3 "2022-11-14T11:15:35Z")

</div>

Thanks for letting me know. I would appreciate it if you could have a look at the issue I linked.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 14, 2022, 11:18am UTC](https://discuss.elastic.co/t/can-i-use-es-roles-with-security-disabled/318861/4 "2022-11-14T11:18:47Z")

</div>

That is not my area so I will not be able to help with that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2022, 11:19am UTC](https://discuss.elastic.co/t/can-i-use-es-roles-with-security-disabled/318861/5 "2022-12-12T11:19:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
