# Can I use role based authentication for free?

**URL:** <https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968>\
**Category:** Elasticsearch\
**Tags:** license\
**Created:** [June 3, 2019, 12:58pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968 "2019-06-03T12:58:48Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Martin\_H\_Andersen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martin_h_andersen/32/37348_2.png) [@Martin\_H\_Andersen](https://discuss.elastic.co/u/Martin_H_Andersen)\
**Post date:** [June 3, 2019, 12:58pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/1 "2019-06-03T12:58:48Z")

</div>

In this link [https://www.elastic.co/subscriptions](https://www.elastic.co/subscriptions) I can see that x-pack basic has role-based access control.

How do I set it up? I have read the documentation but I am very confused.  
Can I with the basic license setup users and roles in kibana?

If I set "xpack.security.enabled: true" in ES then I can see that I am using a trial version and not the basic license.

Any help will be much appreciated

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 3, 2019, 2:39pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/2 "2019-06-03T14:39:18Z")

</div>

Make sure you have at least 6.8.0 or 7.1.0.

---

<div class="post-metadata">

**Author:** ![Martin\_H\_Andersen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martin_h_andersen/32/37348_2.png) [@Martin\_H\_Andersen](https://discuss.elastic.co/u/Martin_H_Andersen)\
**Post date:** [June 3, 2019, 2:56pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/3 "2019-06-03T14:56:28Z")

</div>

I am using version 7.1.1

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 3, 2019, 3:13pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/4 "2019-06-03T15:13:54Z")

</div>

Setting `xpack.security.enabled: true` should not change the license.  
Most likely you activated a trial already and you are still using it?

In Kibana you can stop the trial and revert to a basic license.

---

<div class="post-metadata">

**Author:** ![Martin\_H\_Andersen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martin_h_andersen/32/37348_2.png) [@Martin\_H\_Andersen](https://discuss.elastic.co/u/Martin_H_Andersen)\
**Post date:** [June 3, 2019, 5:09pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/5 "2019-06-03T17:09:21Z")

</div>

This is from the latest [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/7.1/security-settings.html#general-security-settings)

``  
xpack.security.enabled  
Set to `true` to enable Elasticsearch security features on the node.

If set to `false` , which is the default value for basic and trial licenses, security features are disabled. It also affects all Kibana instances that connect to this Elasticsearch instance; you do not need to disable security features in those `kibana.yml` files. For more information about disabling security features in specific Kibana instances, see[Kibana security settings](https://www.elastic.co/guide/en/kibana/7.1/security-settings-kb.html).

![Tip](https://www.elastic.co/guide/en/elasticsearch/reference/7.1/images/icons/tip.png)

If you have gold or higher licenses, the default value is `true` ; we recommend that you explicitly add this setting to avoid confusion.

``

How should I interpret that?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 3, 2019, 5:22pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/6 "2019-06-03T17:22:22Z")

</div>

I read it as "By default security is disabled for basic and trial licenses". It does not mean that you can't use it. Just that it's not turned on by default. I'm sure this will change in the future.

---

<div class="post-metadata">

**Author:** ![Martin\_H\_Andersen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martin_h_andersen/32/37348_2.png) [@Martin\_H\_Andersen](https://discuss.elastic.co/u/Martin_H_Andersen)\
**Post date:** [June 6, 2019, 12:19pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/7 "2019-06-06T12:19:47Z")

</div>

I have no wasted some more time trying to get security to work with basic license.  
If I use trial mode I can run "bin/elasticsearch-setup-passwords interactive" if I use "basic" license the same commands prompt me to install the correct licens or x-pack.

> Unexpected response code [403] from calling GET [http://172.27.0.2:9200/\_security/\_authenticate?pretty](http://172.27.0.2:9200/_security/_authenticate?pretty)  
> It doesn't look like the X-Pack security feature is available on this Elasticsearch node.  
> Please check if you have installed a license that allows access to X-Pack Security feature.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 6, 2019, 1:16pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/8 "2019-06-06T13:16:34Z")

</div>

What is the output of:

```auto
GET /
GET /_cat/nodes?v
GET /_cat/health?v
GET /_cat/plugins?v

```

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 6, 2019, 1:24pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/9 "2019-06-06T13:24:01Z")

</div>

Can you try running in verbose mode?

```
bin/elasticsearch-setup-passwords interactive --verbose

```

That will tell us exactly what response the tool is receiving from Elasticsearch and why that looks like security is not available.

---

<div class="post-metadata">

**Author:** ![Martin\_H\_Andersen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martin_h_andersen/32/37348_2.png) [@Martin\_H\_Andersen](https://discuss.elastic.co/u/Martin_H_Andersen)\
**Post date:** [June 6, 2019, 2:05pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/10 "2019-06-06T14:05:28Z")

</div>

> [@TimV](#):
>
> bin/elasticsearch-setup-passwords interactive --verbose

Testing if bootstrap password is valid for [http://172.28.0.2:9200/\_security/\_authenticate?pretty](http://172.28.0.2:9200/_security/_authenticate?pretty)  
{  
"error" : {  
"root\_cause" : [  
{  
"type" : "security\_exception",  
"reason" : "current license is non-compliant for [security]",  
"license.expired.feature" : "security"  
}  
],  
"type" : "security\_exception",  
"reason" : "current license is non-compliant for [security]",  
"license.expired.feature" : "security"  
},  
"status" : 403  
}

Unexpected response code [403] from calling GET [http://172.28.0.2:9200/\_security/\_authenticate?pretty](http://172.28.0.2:9200/_security/_authenticate?pretty)  
{  
"features" : {  
"ccr" : {  
"available" : false,  
"enabled" : true  
},  
"graph" : {  
"available" : false,  
"enabled" : true  
},  
"ilm" : {  
"available" : true,  
"enabled" : true  
},  
"logstash" : {  
"available" : false,  
"enabled" : true  
},  
"ml" : {  
"available" : false,  
"enabled" : true  
},  
"monitoring" : {  
"available" : true,  
"enabled" : true  
},  
"rollup" : {  
"available" : true,  
"enabled" : true  
},  
"security" : {  
"available" : false,  
"enabled" : true  
},  
"sql" : {  
"available" : true,  
"enabled" : true  
},  
"watcher" : {  
"available" : false,  
"enabled" : true  
}  
}  
}

It doesn't look like the X-Pack security feature is available on this Elasticsearch node.  
Please check if you have installed a license that allows access to X-Pack Security feature.

ERROR: X-Pack Security is not available.

elasticsearch.yml:

> xpack.license.self\_generated.type: basic  
> xpack.security.enabled: true  
> xpack.security.audit.enabled: false  
> xpack.monitoring.collection.enabled: false

---

<div class="post-metadata">

**Author:** ![Martin\_H\_Andersen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martin_h_andersen/32/37348_2.png) [@Martin\_H\_Andersen](https://discuss.elastic.co/u/Martin_H_Andersen)\
**Post date:** [June 6, 2019, 2:11pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/11 "2019-06-06T14:11:54Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/8/d8fa420105e6ae4ad6a91a6dc5c66503f37936f3.png)

Dockerfile:

ARG ELK\_VERSION  
FROM [docker.elastic.co/elasticsearch/elasticsearch:${ELK\_VERSION}](http://docker.elastic.co/elasticsearch/elasticsearch:%24%7BELK_VERSION%7D)  
RUN elasticsearch-plugin install x-pack

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 6, 2019, 2:51pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/12 "2019-06-06T14:51:54Z")

</div>

That output looks exactly like what you'd get on a version from before security was included in the basic license.

Are you positive that the node listening on `172.28.0.2:9200` is running 7.1.1? It really looks more like 7.0

Can you provide the output of `/` that @dadoonet requested?

```auto
curl "http://172.28.0.2:9200/"

```

---

<div class="post-metadata">

**Author:** ![Martin\_H\_Andersen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martin_h_andersen/32/37348_2.png) [@Martin\_H\_Andersen](https://discuss.elastic.co/u/Martin_H_Andersen)\
**Post date:** [June 6, 2019, 3:24pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/13 "2019-06-06T15:24:59Z")

</div>

You are right! looks like .env are not read  
FROM [docker.elastic.co/elasticsearch/elasticsearch:${ELK\_VERSION}](http://docker.elastic.co/elasticsearch/elasticsearch:$%7BELK_VERSION%7D)  
I then tried with  
FROM [docker.elastic.co/elasticsearch/elasticsearch:7.1.1](http://docker.elastic.co/elasticsearch/elasticsearch:7.1.1)

and the output was

> [root@9271e2938fa8 elasticsearch]# curl "[http://172.29.0.2:9200/](http://172.29.0.2:9200/)"  
> {  
> "name" : "9271e2938fa8",  
> "cluster\_name" : "docker-cluster",  
> "cluster\_uuid" : "Z9EG7uCUQtWIbXN0OTB1Hg",  
> "version" : {  
> "number" : "7.0.1",  
> "build\_flavor" : "default",  
> "build\_type" : "docker",  
> "build\_hash" : "e4efcb5",  
> "build\_date" : "2019-04-29T12:56:03.145736Z",  
> "build\_snapshot" : false,  
> "lucene\_version" : "8.0.0",  
> "minimum\_wire\_compatibility\_version" : "6.7.0",  
> "minimum\_index\_compatibility\_version" : "6.0.0-beta1"  
> },  
> "tagline" : "You Know, for Search"  
> }

---

<div class="post-metadata">

**Author:** ![Martin\_H\_Andersen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martin_h_andersen/32/37348_2.png) [@Martin\_H\_Andersen](https://discuss.elastic.co/u/Martin_H_Andersen)\
**Post date:** [June 6, 2019, 3:36pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/14 "2019-06-06T15:36:06Z")

</div>

First thanks for helping me out. I am new to docker-compose and I needed to make a clean build after changing version from 7.0 to 7.1.1. It was not enough with up / down

\*\*\*\*\*\* SUCCESS \*\*\*\*\*\*\*\*\*

```
Testing if bootstrap password is valid for http://172.30.0.2:9200/_security/_authenticate?pretty
{
  "username" : "elastic",
  "roles" : [
    "superuser"
  ],
  "full_name" : null,
  "email" : null,
  "metadata" : {
    "_reserved" : true
  },
  "enabled" : true,
  "authentication_realm" : {
    "name" : "reserved",
    "type" : "reserved"
  },
  "lookup_realm" : {
    "name" : "reserved",
    "type" : "reserved"
  }
}

Checking cluster health: http://172.30.0.2:9200/_cluster/health?pretty
{
  "cluster_name" : "docker-cluster",
  "status" : "green",
  "timed_out" : false,
  "number_of_nodes" : 1,
  "number_of_data_nodes" : 1,
  "active_primary_shards" : 0,
  "active_shards" : 0,
  "relocating_shards" : 0,
  "initializing_shards" : 0,
  "unassigned_shards" : 0,
  "delayed_unassigned_shards" : 0,
  "number_of_pending_tasks" : 0,
  "number_of_in_flight_fetch" : 0,
  "task_max_waiting_in_queue_millis" : 0,
  "active_shards_percent_as_number" : 100.0
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2019, 3:36pm UTC](https://discuss.elastic.co/t/can-i-use-role-based-authentication-for-free/183968/15 "2019-07-04T15:36:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
