# Custom realm extension configuration

**URL:** <https://discuss.elastic.co/t/custom-realm-extension-configuration/192403>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 26, 2019, 10:29am UTC](https://discuss.elastic.co/t/custom-realm-extension-configuration/192403 "2019-07-26T10:29:24Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![iainardo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iainardo/32/50997_2.png) [@iainardo](https://discuss.elastic.co/u/iainardo)\
**Post date:** [July 26, 2019, 10:29am UTC](https://discuss.elastic.co/t/custom-realm-extension-configuration/192403/1 "2019-07-26T10:29:25Z")

</div>

Hi,

I'm having trouble with custom realm configuration when upgrading from Elasticsearch from 6.8.0 to 7.2.0 with custom realm configuration. I can't see what the problem is... Could anyone help me here please - thanks! ~ Iain

- I'm performing an upgrade of a legacy ELK deployment and currently hitting issues an elasticsearch node from 6.8.1 to 7.2.0 (using [Rolling upgrade](https://www.elastic.co/guide/en/elasticsearch/reference/current/rolling-upgrades.html))
- The deployment uses a custom realm extension - `acme-abc-realm`. I've installed a custom realm extension `acme-abc-realm` following the steps outlined in [Custom Realms](https://www.elastic.co/guide/en/elastic-stack-overview/7.2/custom-realms.html).

```auto
[elasticsearch-7.2.0]# bin/elasticsearch-plugin list --verbose
Plugins directory: /opt/elasticsearch-7.2.0/plugins
acme-abc-realm
- Plugin information:
Name: acme-abc-realm
Description: A ACME custom security extension
Version: 7.2.0
Elasticsearch Version: 7.2.0
Java Version: 1.8
Native Controller: false
Extended Plugins: [x-pack-security]
 * Classname: com.acme.xpack.AcmeExtensionPlugin

```

- I've configured the elasticsearch.yml `xpack.security.authc` configuration outlined in [Integrating with other authentication systems](https://www.elastic.co/guide/en/elastic-stack-overview/7.2/custom-realms.html)

```auto
xpack.security.authc:
  realms:
    custom.acme-abc-realm:
      order: 0
      maxConnections: 5
      maxConnectionsPerHost: 5
      connectionTimeout: 5000
      socketTimeout: 5000
...

```

- On startup of the ES node, I get the following error:

```auto
	Suppressed: java.lang.IllegalArgumentException: unknown setting [xpack.security.authc.realms.custom.acme-abc-realm.imsCacheExpiryInMinutes] please check that any required plugins are installed, or check the breaking changes documentation for removed settings

[2019-07-26T10:17:32,823][ERROR][o.e.b.Bootstrap] [iel-dev-rep-vm2] Exception
java.lang.IllegalArgumentException: unknown setting [xpack.security.authc.realms.custom.acme-abc-realm.maxConnections] please check that any required plugins are installed, or check the breaking changes documentation for removed settings
        at org.elasticsearch.common.settings.AbstractScopedSettings.validate(AbstractScopedSettings.java:531) ~[elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.common.settings.AbstractScopedSettings.validate(AbstractScopedSettings.java:476) ~[elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.common.settings.AbstractScopedSettings.validate(AbstractScopedSettings.java:447) ~[elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.common.settings.AbstractScopedSettings.validate(AbstractScopedSettings.java:418) ~[elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.common.settings.SettingsModule.<init>(SettingsModule.java:148) ~[elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.node.Node.<init>(Node.java:342) ~[elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.node.Node.<init>(Node.java:251) ~[elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.bootstrap.Bootstrap$5.<init>(Bootstrap.java:221) ~[elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.bootstrap.Bootstrap.setup(Bootstrap.java:221) ~[elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:349) [elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:159) [elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.bootstrap.Elasticsearch.execute(Elasticsearch.java:150) [elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:86) [elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:124) [elasticsearch-cli-7.2.0.jar:7.2.0]
        at org.elasticsearch.cli.Command.main(Command.java:90) [elasticsearch-cli-7.2.0.jar:7.2.0]
        at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:115) [elasticsearch-7.2.0.jar:7.2.0]
        at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:92) [elasticsearch-7.2.0.jar:7.2.0]
        Suppressed: java.lang.IllegalArgumentException: unknown setting [xpack.security.authc.realms.custom.acme-abc-realm.maxConnectionsPerHost] please check that any required 

```

- I've tried to resolve this myself but am getting nowhere..
- Could someone guide me here please as to what I'm doing wrong please ?
- Thanks again for your time!

---

<div class="post-metadata">

**Author:** ![Eric\_Robinson1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eric_robinson1/32/48340_2.png) [@Eric\_Robinson1](https://discuss.elastic.co/u/Eric_Robinson1)\
**Post date:** [July 26, 2019, 5:17pm UTC](https://discuss.elastic.co/t/custom-realm-extension-configuration/192403/2 "2019-07-26T17:17:44Z")

</div>

I am having the same issue trying to get a custom realm to load in 7.2 that worked in 6.7. I see that the configuration has changed so I am not sure if the following would work for you or not

```auto
xpack:
  security:
    authc:
      realms:
        acme-abc-realm:
          custom1:
            order: 0

```

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 29, 2019, 12:48am UTC](https://discuss.elastic.co/t/custom-realm-extension-configuration/192403/3 "2019-07-29T00:48:53Z")

</div>

In 7.0 and later, the `getRealmSettings` method has been removed from `SecurityExtension`.

Your plugin is now responsible for registering its own settings.  
The [sample in our GitHub repository](https://github.com/elastic/elasticsearch/blob/v7.2.0/x-pack/qa/security-example-spi-extension/src/main/java/org/elasticsearch/example/SpiExtensionPlugin.java) has an example of this.

---

<div class="post-metadata">

**Author:** ![iainardo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iainardo/32/50997_2.png) [@iainardo](https://discuss.elastic.co/u/iainardo)\
**Post date:** [July 29, 2019, 8:37am UTC](https://discuss.elastic.co/t/custom-realm-extension-configuration/192403/4 "2019-07-29T08:37:56Z")

</div>

Thanks @Eric_Robinson1, @TimV for your help.

I would suggest it may be useful to add Tim's statement to [Integrating with other authentication systems](https://www.elastic.co/guide/en/elastic-stack-overview/7.2/custom-realms.html) as a hint to others who may come across same issue.

👍

---

<div class="post-metadata">

**Author:** ![Eric\_Robinson1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eric_robinson1/32/48340_2.png) [@Eric\_Robinson1](https://discuss.elastic.co/u/Eric_Robinson1)\
**Post date:** [July 29, 2019, 12:42pm UTC](https://discuss.elastic.co/t/custom-realm-extension-configuration/192403/5 "2019-07-29T12:42:40Z")

</div>

Thanks @TimV I was able to get my plugin working as well by adding the following.

```auto
List<Setting<?>> list = new ArrayList<>(RealmSettings.getStandardSettings(CustomRealm.TYPE));

```

I agree with @iainardo adding that to the docs would be helpful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 26, 2019, 12:42pm UTC](https://discuss.elastic.co/t/custom-realm-extension-configuration/192403/6 "2019-08-26T12:42:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
