# Custom Realm only for Authorization

**URL:** <https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 19, 2015, 5:24pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074 "2015-11-19T17:24:13Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![vinoth4v](https://avatars.discourse-cdn.com/v4/letter/v/4da419/32.png) [@vinoth4v](https://discuss.elastic.co/u/vinoth4v)\
**Post date:** [November 19, 2015, 5:24pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/1 "2015-11-19T17:24:13Z")

</div>

Hello Experts,

I am trying to implement a Custom Realm without Authentication and only for authorisation against AD. Is this possible?

My use case is, I have a Third party authentication system implemented in a webserver which sits before Kibana. The user should use "only" this authentication system to login. On successful login, the username information needs to be extracted from the header (the header will have no details of Password or Groups) and looked up again the AD for the group details which needs to be mapped against Shield roles. I have a bind user and password for querying the AD.

I am using this example : [https://github.com/elastic/shield-custom-realm-example](https://github.com/elastic/shield-custom-realm-example)

But I am stuck at extracting the token with no password.

Any pointers how to approach this will be very helpful.

Cheers!

Vinoth

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [November 19, 2015, 5:41pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/2 "2015-11-19T17:41:59Z")

</div>

With ES/Shield 2.0, we now have the ability to "run as" another user, which is what it seems you might want here. If this is what you want, it's great, because it means you don't need a custom realm.

I'm on my mobile, so I cannot post links to the docs, but I expect it to be fairly straightforward.

---

<div class="post-metadata">

**Author:** ![vinoth4v](https://avatars.discourse-cdn.com/v4/letter/v/4da419/32.png) [@vinoth4v](https://discuss.elastic.co/u/vinoth4v)\
**Post date:** [November 19, 2015, 5:50pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/3 "2015-11-19T17:50:11Z")

</div>

Will be great if you can share some links.

The idea is, We dont want to have 2 logins pages when a user tries to access the ELK. We want to have a single sign-on with our "thrid party Idp" and the authorisation should be done with AD(without user password) by extracting username from the http response header which we got from the Idp login.

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [November 19, 2015, 6:02pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/4 "2015-11-19T18:02:18Z")

</div>

[https://www.elastic.co/guide/en/shield/current/submitting-requests-for-other-users.html](https://www.elastic.co/guide/en/shield/current/submitting-requests-for-other-users.html)

^^ that is the section of the docs that describes how to use the user impersonation feature. I checked, and it doesn't work with the AD realm today, so you will have to configure the LDAP realm to talk to AD to use this feature.

---

<div class="post-metadata">

**Author:** ![vinoth4v](https://avatars.discourse-cdn.com/v4/letter/v/4da419/32.png) [@vinoth4v](https://discuss.elastic.co/u/vinoth4v)\
**Post date:** [November 19, 2015, 6:14pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/5 "2015-11-19T18:14:48Z")

</div>

Thanks for the link.

Just to make sure I understood correctly, in this case shields lets every authenticated user to view the data by impersonating an existing user in the realm.

But we have very specific requirement for authorization, where users belonging to certain AD groups should not be allowed to view certain indices.

How can we enforce this? Is this possible with Sheild 2.0?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [November 19, 2015, 7:01pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/6 "2015-11-19T19:01:35Z")

</div>

Shield will still enforce authorization. What happens is:

1. Search Request (or another request) comes in with authentication and run as information defined in a header
2. The user making the requested is authenticated
3. The run as user is "looked up" to see if it can be found by a realm (esusers or LDAP)
4. The authenticated user undergoes authorization to ensure they are allowed to run as the specified user in the header. This is defined in the roles.yml file. If they are not authorized to run as another user, an authorization exception will occur
5. The run as user that was looked up undergoes authorization based on their roles to ensure they are allowed to perform request, which in this example is a search request
6. If the run as user is authorized, the request is executed on their behalf

You will just need to configure roles and role mapping for your users properly so that they only have access to the data they should have access to.

---

<div class="post-metadata">

**Author:** ![vinoth4v](https://avatars.discourse-cdn.com/v4/letter/v/4da419/32.png) [@vinoth4v](https://discuss.elastic.co/u/vinoth4v)\
**Post date:** [November 19, 2015, 7:13pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/7 "2015-11-19T19:13:44Z")

</div>

Thanks Jay,

But we are implementing an ELK stack, where the only place the user is allowed to query ElasticSearch is through Kibana.(no head plugin or command-line access)

How can we do the mapping between the "authenticated" user (from a thrid party idP) with the "run as" user in this case?

---

<div class="post-metadata">

**Author:** ![vinoth4v](https://avatars.discourse-cdn.com/v4/letter/v/4da419/32.png) [@vinoth4v](https://discuss.elastic.co/u/vinoth4v)\
**Post date:** [November 19, 2015, 7:28pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/8 "2015-11-19T19:28:24Z")

</div>

My understanding for this problem is to

1.Create a AD custom realm.  
2. Get the actual username from the response header of the third party IdP  
3. Authenticate the custom AD realm with a bind user/password for every request  
4. Do a ldapquery and get all the group names the user belongs  
5. Map the user & roles credentials to shield.

Is my approach correct?

Any inputs if this can work? Has anybody already done this before?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [November 19, 2015, 8:20pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/9 "2015-11-19T20:20:19Z")

</div>

That sounds like it will work. Kibana should forward the headers with your request to elasticsearch and your custom realm should be able to lookup the user in the header.

---

<div class="post-metadata">

**Author:** ![furqan](https://avatars.discourse-cdn.com/v4/letter/f/4491bb/32.png) [@furqan](https://discuss.elastic.co/u/furqan)\
**Post date:** [March 14, 2016, 11:49am UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/10 "2016-03-14T11:49:56Z")

</div>

Can any one let me know how we can build the custom plugin which skip the authentication part from LDAP.

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [March 17, 2016, 9:19pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/11 "2016-03-17T21:19:43Z")

</div>

You could get this effect today, if you use PKI to authenticate your request, and grant the PKI user the appropriate run-as capabilities.

This way, you're making the request from an authorized user, but _running the request_ as a different user.

---

<div class="post-metadata">

**Author:** ![Chandan\_PR](https://avatars.discourse-cdn.com/v4/letter/c/c37758/32.png) [@Chandan\_PR](https://discuss.elastic.co/u/Chandan_PR)\
**Post date:** [April 26, 2016, 2:05pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/12 "2016-04-26T14:05:51Z")

</div>

HI Vinoth,

Were you able to implement this successfully? How did you configure the elasticsearch.url for Kibana in this case?

---

<div class="post-metadata">

**Author:** ![vinoth4v](https://avatars.discourse-cdn.com/v4/letter/v/4da419/32.png) [@vinoth4v](https://discuss.elastic.co/u/vinoth4v)\
**Post date:** [April 27, 2016, 7:39am UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/13 "2016-04-27T07:39:45Z")

</div>

Hi Chandan,

Yes, I was able to implement this successfully. There is no Special configuration regquired for kibana. I followed this github example [https://github.com/elastic/shield-custom-realm-example](https://github.com/elastic/shield-custom-realm-example)

---

<div class="post-metadata">

**Author:** ![Yasho](https://avatars.discourse-cdn.com/v4/letter/y/c2a13f/32.png) [@Yasho](https://discuss.elastic.co/u/Yasho)\
**Post date:** [July 19, 2016, 10:48am UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/14 "2016-07-19T10:48:34Z")

</div>

Hi Vinoth,

I do not have an AD so can i still go ahead and use ldap for custom realm to interact with?

Is der any way you can share the code here? it will be really helpful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/custom-realm-only-for-authorization/35074/15 "2017-07-06T13:42:47Z")

</div>


