# Elastic Cloud 6.0 - User authentications

**URL:** <https://discuss.elastic.co/t/elastic-cloud-6-0-user-authentications/108809>\
**Category:** Elasticsearch\
**Created:** [November 23, 2017, 12:15am UTC](https://discuss.elastic.co/t/elastic-cloud-6-0-user-authentications/108809 "2017-11-23T00:15:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![shanim](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@shanim](https://discuss.elastic.co/u/shanim)\
**Post date:** [November 23, 2017, 12:15am UTC](https://discuss.elastic.co/t/elastic-cloud-6-0-user-authentications/108809/1 "2017-11-23T00:15:46Z")

</div>

Hi,

I'm a noob at Elastic Cloud 6.0 and I'm using X-Pack for the first time.

I have been attempting to add some data into a cluster I created on elastic cloud. I created a new user (as I didn't want to use the `elastic` user for my python client). I created the user and created a role with privileges for the index and assigned it to the user. However, when I attempt to add data into the cluster, I get the following HTTP 401 error:

`elasticsearch.exceptions.AuthenticationException: TransportError(401, u'security_exception', u'unable to authenticate user [some_user] for REST request [CLUSTER/INDEX]')`

When I attempt the same request with the `elastic` user, I'm able to add data to my index. What am I missing?

Here is the user:

```
"some_script": {
"username": "some_script",
"roles": [
  "events_admin"
],
"full_name": "Some Script",
"email": "something@gmail.com",
"metadata": {},
"enabled": true
}

```

And here is the role:

```
"events_admin": {
"cluster": [],
"indices": [
  {
    "names": [
      "INDEX"
    ],
    "privileges": [
      "all"
    ]
  },
  {
    "names": [
      ".kibana*"
    ],
    "privileges": [
      "manage",
      "read",
      "index"
    ]
  }
],
"run_as": [],
"metadata": {},
"transient_metadata": {
  "enabled": true
}
}
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 23, 2017, 2:06am UTC](https://discuss.elastic.co/t/elastic-cloud-6-0-user-authentications/108809/2 "2017-11-23T02:06:34Z")

</div>

I moved your question to #x-pack

It seems like the client you are using is calling a cluster level API. I guess for discovering other nodes if you activated something like sniffing.

So you need to add this api to your user.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [November 23, 2017, 2:29am UTC](https://discuss.elastic.co/t/elastic-cloud-6-0-user-authentications/108809/3 "2017-11-23T02:29:08Z")

</div>

> [@shanim](#):
>
> 'unable to authenticate user [some\_user] for REST request [CLUSTER/INDEX]'

That looks like an authentication error. Either the password for "some\_user" is not being sent correctly in your request, or the user doesn't actually exist.  
Since it's working for `elastic` it's probably a configuration problem rather than an actual bug in your code.

Check for typos, and also check that the user really was created in your cloud cluster.

---

<div class="post-metadata">

**Author:** ![shanim](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@shanim](https://discuss.elastic.co/u/shanim)\
**Post date:** [November 23, 2017, 2:37am UTC](https://discuss.elastic.co/t/elastic-cloud-6-0-user-authentications/108809/4 "2017-11-23T02:37:53Z")

</div>

I had a look at Kibana and do see it on Kibana's Management Page (following the step 4 in [https://www.elastic.co/guide/en/x-pack/current/security-getting-started.html](https://www.elastic.co/guide/en/x-pack/current/security-getting-started.html)). Is there a different method to create the user for REST API access?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [November 23, 2017, 5:13am UTC](https://discuss.elastic.co/t/elastic-cloud-6-0-user-authentications/108809/5 "2017-11-23T05:13:05Z")

</div>

The user that you created in Kibana will be able to use the API.

All I can suggest is to triple check that you have all the names and passwords correct, because that error is saying that you don't.

e.g. Your error message says `some_user` but your user JSON says `some_script`. I assume you've redacted those for public posting, but do make sure the username you are using in your code, is exactly the same as the user you created in Kibana.

---

<div class="post-metadata">

**Author:** ![shanim](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@shanim](https://discuss.elastic.co/u/shanim)\
**Post date:** [November 23, 2017, 6:07am UTC](https://discuss.elastic.co/t/elastic-cloud-6-0-user-authentications/108809/6 "2017-11-23T06:07:22Z")

</div>

🤦‍♂️

User Error! Typo in the client's username 🙂 Sorted it out now

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [November 23, 2017, 7:41am UTC](https://discuss.elastic.co/t/elastic-cloud-6-0-user-authentications/108809/7 "2017-11-23T07:41:56Z")

</div>

> User Error!

👍🏽 Glad it's sorted.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2017, 7:42am UTC](https://discuss.elastic.co/t/elastic-cloud-6-0-user-authentications/108809/8 "2017-12-21T07:42:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
