# Elasticsearch-security-plugin : Kerberos, NTLM and host/ip based coarse-grained and document level security for elasticsearch

**URL:** <https://discuss.elastic.co/t/elasticsearch-security-plugin-kerberos-ntlm-and-host-ip-based-coarse-grained-and-document-level-security-for-elasticsearch/14477>\
**Category:** Elasticsearch\
**Created:** [November 19, 2013, 11:43pm UTC](https://discuss.elastic.co/t/elasticsearch-security-plugin-kerberos-ntlm-and-host-ip-based-coarse-grained-and-document-level-security-for-elasticsearch/14477 "2013-11-19T23:43:43Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hendrik](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@Hendrik](https://discuss.elastic.co/u/Hendrik)\
**Post date:** [November 19, 2013, 11:43pm UTC](https://discuss.elastic.co/t/elasticsearch-security-plugin-kerberos-ntlm-and-host-ip-based-coarse-grained-and-document-level-security-for-elasticsearch/14477/1 "2013-11-19T23:43:43Z")

</div>

Hi,

i am working on Kerberos/NTLM and host/ip based coarse-grained and document  
level security for elasticsearch (early dev stage but roughly working)

> **[salyh/elasticsearch-security-plugin](https://github.com/salyh/elasticsearch-security-plugin)**
>
> elasticsearch-security-plugin - Kerberos, LDAP, Active Directory, PKI/SSL/TLS and host/ip based ACL coarse-grained and document level security for elasticsearch (Authentication, Authorization, Auth...

_This plugin adds http/rest security functionality to Elasticsearch in kind  
of separate modules. Instead of Netty a embedded Tomcat 7 is used to  
process http/rest requests._

\*Currently for user based authentication and authorization Kerberos and  
NTLM are supported through 3rd party library waffle (only on windows  
servers). \*  
_For UNIX servers Kerberos is supported through 3rd party library  
tomcatspnegoad (Works with any kerberos implementation. For authorization  
either Active Directory and generic LDAP is supported)._

_You can use this plugin also without Kerberos/NTLM but then only host  
based authentication is available._

_As of now two security modules are implemented:_

- _Actionpathfilter: Restrict actions against Elasticsearch on a  
coarse-grained level like who is allowed to to READ, WRITE or even ADMIN  
rest api calls_
- _Document level security (dls): Restrict actions on document level  
like who is allowed to query for which fields within a document_

Suggestions, corrections, improvements are very welcome!  
Thanks and best regards  
Hendrik

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Hendrik](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@Hendrik](https://discuss.elastic.co/u/Hendrik)\
**Post date:** [December 7, 2013, 10:37pm UTC](https://discuss.elastic.co/t/elasticsearch-security-plugin-kerberos-ntlm-and-host-ip-based-coarse-grained-and-document-level-security-for-elasticsearch/14477/2 "2013-12-07T22:37:37Z")

</div>

Now the elasticsearch-security-plugin[https://github.com/salyh/elasticsearch-security-plugin](https://github.com/salyh/elasticsearch-security-plugin) also  
support SSL/TLS and SSL client authentication (mutual client  
authentication).

Download the preview release 0.0.2.Beta3 here:

> **[Release 0.0.2.Beta3 · salyh/elasticsearch-security-plugin](https://github.com/salyh/elasticsearch-security-plugin/releases/tag/0.0.2.Beta3)**
>
> Kerberos, LDAP, Active Directory, PKI/SSL/TLS and host/ip based ACL coarse-grained and document level security for elasticsearch (Authentication, Authorization, Auth, Spnego, ACL, Mutual authentication) - Release 0.0.2.Beta3 ·...

Suggestions, corrections, improvements are very welcome!  
Thanks and best regards  
Hendrik

Am Mittwoch, 20. November 2013 00:43:43 UTC+1 schrieb Hendrik:

> Hi,
> 
> i am working on Kerberos/NTLM and host/ip based coarse-grained and  
> document level security for elasticsearch (early dev stage but roughly  
> working)
> 
> [GitHub - salyh/elasticsearch-security-plugin: Kerberos, LDAP, Active Directory, PKI/SSL/TLS and host/ip based ACL coarse-grained and document level security for elasticsearch (Authentication, Authorization, Auth, Spnego, ACL, Mutual authentication)](https://github.com/salyh/elasticsearch-security-plugin)
> 
> _This plugin adds http/rest security functionality to Elasticsearch in  
> kind of separate modules. Instead of Netty a embedded Tomcat 7 is used to  
> process http/rest requests._
> 
> \*Currently for user based authentication and authorization Kerberos and  
> NTLM are supported through 3rd party library waffle (only on windows  
> servers). \*  
> _For UNIX servers Kerberos is supported through 3rd party library  
> tomcatspnegoad (Works with any kerberos implementation. For authorization  
> either Active Directory and generic LDAP is supported)._
> 
> _You can use this plugin also without Kerberos/NTLM but then only host  
> based authentication is available._
> 
> _As of now two security modules are implemented:_
> 
> - _Actionpathfilter: Restrict actions against Elasticsearch on a  
> coarse-grained level like who is allowed to to READ, WRITE or even ADMIN  
> rest api calls_
> - _Document level security (dls): Restrict actions on document level  
> like who is allowed to query for which fields within a document_
> 
> Suggestions, corrections, improvements are very welcome!  
> Thanks and best regards  
> Hendrik

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/15e5a369-b052-4d01-9f54-d4834b2a904a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/15e5a369-b052-4d01-9f54-d4834b2a904a%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![sri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sri/32/60716_2.png) [@sri](https://discuss.elastic.co/u/sri)\
**Post date:** [June 23, 2014, 5:54pm UTC](https://discuss.elastic.co/t/elasticsearch-security-plugin-kerberos-ntlm-and-host-ip-based-coarse-grained-and-document-level-security-for-elasticsearch/14477/3 "2014-06-23T17:54:01Z")

</div>

Hello,

Is the plugin compatible with elasticsearch 1.2.1, cause when i tried  
getting it running on ES 1.2.1, i was getting following error :  
java.lang.IncompatibleClassChangeError: Implementing class  
at java.lang.ClassLoader.defineClass1(Native Method)  
at java.lang.ClassLoader.defineClass(ClassLoader.java:800)  
at  
java.security.SecureClassLoader.defineClass(SecureClassLoader.java:142)  
at java.net.URLClassLoader.defineClass(URLClassLoader.java:449)  
at java.net.URLClassLoader.access$100(URLClassLoader.java:71)  
at java.net.URLClassLoader$1.run(URLClassLoader.java:361)  
at java.net.URLClassLoader$1.run(URLClassLoader.java:355)  
at java.security.AccessController.doPrivileged(Native Method)  
at java.net.URLClassLoader.findClass(URLClassLoader.java:354)  
at java.lang.ClassLoader.loadClass(ClassLoader.java:425)  
at sun.misc.Launcher$AppClassLoader.loadClass(Launcher.java:308)  
at java.lang.ClassLoader.loadClass(ClassLoader.java:358)  
at  
org.elasticsearch.plugins.security.service.SecurityService.doStart(SecurityService.java:79)  
at  
org.elasticsearch.common.component.AbstractLifecycleComponent.start(AbstractLifecycleComponent.java:85)  
at  
org.elasticsearch.node.internal.InternalNode.start(InternalNode.java:217)  
at org.elasticsearch.bootstrap.Bootstrap.start(Bootstrap.java:122)  
at org.elasticsearch.bootstrap.Bootstrap.main(Bootstrap.java:206)  
at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:32)

Thanks and Regards  
Srinath Kotu

On Tuesday, November 19, 2013 6:43:43 PM UTC-5, Hendrik wrote:

> Hi,
> 
> i am working on Kerberos/NTLM and host/ip based coarse-grained and  
> document level security for elasticsearch (early dev stage but roughly  
> working)
> 
> [GitHub - salyh/elasticsearch-security-plugin: Kerberos, LDAP, Active Directory, PKI/SSL/TLS and host/ip based ACL coarse-grained and document level security for elasticsearch (Authentication, Authorization, Auth, Spnego, ACL, Mutual authentication)](https://github.com/salyh/elasticsearch-security-plugin)
> 
> _This plugin adds http/rest security functionality to Elasticsearch in  
> kind of separate modules. Instead of Netty a embedded Tomcat 7 is used to  
> process http/rest requests._
> 
> \*Currently for user based authentication and authorization Kerberos and  
> NTLM are supported through 3rd party library waffle (only on windows  
> servers). \*  
> _For UNIX servers Kerberos is supported through 3rd party library  
> tomcatspnegoad (Works with any kerberos implementation. For authorization  
> either Active Directory and generic LDAP is supported)._
> 
> _You can use this plugin also without Kerberos/NTLM but then only host  
> based authentication is available._
> 
> _As of now two security modules are implemented:_
> 
> - _Actionpathfilter: Restrict actions against Elasticsearch on a  
> coarse-grained level like who is allowed to to READ, WRITE or even ADMIN  
> rest api calls_
> - _Document level security (dls): Restrict actions on document level  
> like who is allowed to query for which fields within a document_
> 
> Suggestions, corrections, improvements are very welcome!  
> Thanks and best regards  
> Hendrik

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/cee091bf-b01e-49ce-95d8-cf4518d474af%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/cee091bf-b01e-49ce-95d8-cf4518d474af%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Hendrik\_Dev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendrik_dev/32/978_2.png) [@Hendrik\_Dev](https://discuss.elastic.co/u/Hendrik_Dev)\
**Post date:** [June 23, 2014, 6:46pm UTC](https://discuss.elastic.co/t/elasticsearch-security-plugin-kerberos-ntlm-and-host-ip-based-coarse-grained-and-document-level-security-for-elasticsearch/14477/4 "2014-06-23T18:46:07Z")

</div>

The current master branch does not work with 1.2.1 out of the box but it  
should be easy to fix this.  
Just clone the repo and change ES version to 1.2.1 in pom.xml, then look  
either in ES docs for breaking changes and/or fix the compile errors.

There is no official release of the security plugin as of now so you have  
to build it yourself.

KR  
Hendrik

Am Montag, 23. Juni 2014 19:54:02 UTC+2 schrieb sri:

> Hello,
> 
> Is the plugin compatible with elasticsearch 1.2.1, cause when i tried  
> getting it running on ES 1.2.1, i was getting following error :  
> java.lang.IncompatibleClassChangeError: Implementing class  
> at java.lang.ClassLoader.defineClass1(Native Method)  
> at java.lang.ClassLoader.defineClass(ClassLoader.java:800)  
> at  
> java.security.SecureClassLoader.defineClass(SecureClassLoader.java:142)  
> at java.net.URLClassLoader.defineClass(URLClassLoader.java:449)  
> at java.net.URLClassLoader.access$100(URLClassLoader.java:71)  
> at java.net.URLClassLoader$1.run(URLClassLoader.java:361)  
> at java.net.URLClassLoader$1.run(URLClassLoader.java:355)  
> at java.security.AccessController.doPrivileged(Native Method)  
> at java.net.URLClassLoader.findClass(URLClassLoader.java:354)  
> at java.lang.ClassLoader.loadClass(ClassLoader.java:425)  
> at sun.misc.Launcher$AppClassLoader.loadClass(Launcher.java:308)  
> at java.lang.ClassLoader.loadClass(ClassLoader.java:358)  
> at  
> org.elasticsearch.plugins.security.service.SecurityService.doStart(SecurityService.java:79)  
> at  
> org.elasticsearch.common.component.AbstractLifecycleComponent.start(AbstractLifecycleComponent.java:85)  
> at  
> org.elasticsearch.node.internal.InternalNode.start(InternalNode.java:217)  
> at org.elasticsearch.bootstrap.Bootstrap.start(Bootstrap.java:122)  
> at org.elasticsearch.bootstrap.Bootstrap.main(Bootstrap.java:206)  
> at  
> org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:32)
> 
> Thanks and Regards  
> Srinath Kotu
> 
> On Tuesday, November 19, 2013 6:43:43 PM UTC-5, Hendrik wrote:
> 
> > Hi,
> > 
> > i am working on Kerberos/NTLM and host/ip based coarse-grained and  
> > document level security for elasticsearch (early dev stage but roughly  
> > working)
> > 
> > [GitHub - salyh/elasticsearch-security-plugin: Kerberos, LDAP, Active Directory, PKI/SSL/TLS and host/ip based ACL coarse-grained and document level security for elasticsearch (Authentication, Authorization, Auth, Spnego, ACL, Mutual authentication)](https://github.com/salyh/elasticsearch-security-plugin)
> > 
> > _This plugin adds http/rest security functionality to Elasticsearch in  
> > kind of separate modules. Instead of Netty a embedded Tomcat 7 is used to  
> > process http/rest requests._
> > 
> > \*Currently for user based authentication and authorization Kerberos and  
> > NTLM are supported through 3rd party library waffle (only on windows  
> > servers). \*  
> > _For UNIX servers Kerberos is supported through 3rd party library  
> > tomcatspnegoad (Works with any kerberos implementation. For authorization  
> > either Active Directory and generic LDAP is supported)._
> > 
> > _You can use this plugin also without Kerberos/NTLM but then only host  
> > based authentication is available._
> > 
> > _As of now two security modules are implemented:_
> > 
> > - _Actionpathfilter: Restrict actions against Elasticsearch on a  
> > coarse-grained level like who is allowed to to READ, WRITE or even ADMIN  
> > rest api calls_
> > - _Document level security (dls): Restrict actions on document level  
> > like who is allowed to query for which fields within a document_
> > 
> > Suggestions, corrections, improvements are very welcome!  
> > Thanks and best regards  
> > Hendrik

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/25945945-6135-437d-abce-0edef371f38c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/25945945-6135-437d-abce-0edef371f38c%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Emrul\_Islam](https://avatars.discourse-cdn.com/v4/letter/e/a87d85/32.png) [@Emrul\_Islam](https://discuss.elastic.co/u/Emrul_Islam)\
**Post date:** [November 26, 2014, 10:45am UTC](https://discuss.elastic.co/t/elasticsearch-security-plugin-kerberos-ntlm-and-host-ip-based-coarse-grained-and-document-level-security-for-elasticsearch/14477/5 "2014-11-26T10:45:49Z")

</div>

Can I just say this project looks really excellent. Thank you for doing it  
and sharing it Henrik!

Best,

Emrul

On Monday, June 23, 2014 7:46:08 PM UTC+1, Hendrik Dev wrote:

> The current master branch does not work with 1.2.1 out of the box but it  
> should be easy to fix this.  
> Just clone the repo and change ES version to 1.2.1 in pom.xml, then look  
> either in ES docs for breaking changes and/or fix the compile errors.
> 
> There is no official release of the security plugin as of now so you have  
> to build it yourself.
> 
> KR  
> Hendrik
> 
> Am Montag, 23. Juni 2014 19:54:02 UTC+2 schrieb sri:
> 
> > Hello,
> > 
> > Is the plugin compatible with elasticsearch 1.2.1, cause when i tried  
> > getting it running on ES 1.2.1, i was getting following error :  
> > java.lang.IncompatibleClassChangeError: Implementing class  
> > at java.lang.ClassLoader.defineClass1(Native Method)  
> > at java.lang.ClassLoader.defineClass(ClassLoader.java:800)  
> > at  
> > java.security.SecureClassLoader.defineClass(SecureClassLoader.java:142)  
> > at java.net.URLClassLoader.defineClass(URLClassLoader.java:449)  
> > at java.net.URLClassLoader.access$100(URLClassLoader.java:71)  
> > at java.net.URLClassLoader$1.run(URLClassLoader.java:361)  
> > at java.net.URLClassLoader$1.run(URLClassLoader.java:355)  
> > at java.security.AccessController.doPrivileged(Native Method)  
> > at java.net.URLClassLoader.findClass(URLClassLoader.java:354)  
> > at java.lang.ClassLoader.loadClass(ClassLoader.java:425)  
> > at sun.misc.Launcher$AppClassLoader.loadClass(Launcher.java:308)  
> > at java.lang.ClassLoader.loadClass(ClassLoader.java:358)  
> > at  
> > org.elasticsearch.plugins.security.service.SecurityService.doStart(SecurityService.java:79)  
> > at  
> > org.elasticsearch.common.component.AbstractLifecycleComponent.start(AbstractLifecycleComponent.java:85)  
> > at  
> > org.elasticsearch.node.internal.InternalNode.start(InternalNode.java:217)  
> > at org.elasticsearch.bootstrap.Bootstrap.start(Bootstrap.java:122)  
> > at org.elasticsearch.bootstrap.Bootstrap.main(Bootstrap.java:206)  
> > at  
> > org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:32)
> > 
> > Thanks and Regards  
> > Srinath Kotu
> > 
> > On Tuesday, November 19, 2013 6:43:43 PM UTC-5, Hendrik wrote:
> > 
> > > Hi,
> > > 
> > > i am working on Kerberos/NTLM and host/ip based coarse-grained and  
> > > document level security for elasticsearch (early dev stage but roughly  
> > > working)
> > > 
> > > [GitHub - salyh/elasticsearch-security-plugin: Kerberos, LDAP, Active Directory, PKI/SSL/TLS and host/ip based ACL coarse-grained and document level security for elasticsearch (Authentication, Authorization, Auth, Spnego, ACL, Mutual authentication)](https://github.com/salyh/elasticsearch-security-plugin)
> > > 
> > > _This plugin adds http/rest security functionality to Elasticsearch in  
> > > kind of separate modules. Instead of Netty a embedded Tomcat 7 is used to  
> > > process http/rest requests._
> > > 
> > > \*Currently for user based authentication and authorization Kerberos and  
> > > NTLM are supported through 3rd party library waffle (only on windows  
> > > servers). \*  
> > > _For UNIX servers Kerberos is supported through 3rd party library  
> > > tomcatspnegoad (Works with any kerberos implementation. For authorization  
> > > either Active Directory and generic LDAP is supported)._
> > > 
> > > _You can use this plugin also without Kerberos/NTLM but then only host  
> > > based authentication is available._
> > > 
> > > _As of now two security modules are implemented:_
> > > 
> > > - _Actionpathfilter: Restrict actions against Elasticsearch on a  
> > > coarse-grained level like who is allowed to to READ, WRITE or even ADMIN  
> > > rest api calls_
> > > - _Document level security (dls): Restrict actions on document level  
> > > like who is allowed to query for which fields within a document_
> > > 
> > > Suggestions, corrections, improvements are very welcome!  
> > > Thanks and best regards  
> > > Hendrik

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/c433f1ac-4870-4631-b1ef-f3d1c87d113b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/c433f1ac-4870-4631-b1ef-f3d1c87d113b%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![clement\_motreff](https://avatars.discourse-cdn.com/v4/letter/c/b9bd4f/32.png) [@clement\_motreff](https://discuss.elastic.co/u/clement_motreff)\
**Post date:** [December 10, 2014, 8:02am UTC](https://discuss.elastic.co/t/elasticsearch-security-plugin-kerberos-ntlm-and-host-ip-based-coarse-grained-and-document-level-security-for-elasticsearch/14477/6 "2014-12-10T08:02:28Z")

</div>

Hello,

Is the plugin still compatible with ES 1.3.4 or sup ?  
Is it possible de use a Kerberos auth ?

Regards.

Le mercredi 20 novembre 2013 00:43:43 UTC+1, Hendrik a écrit :

> Hi,
> 
> i am working on Kerberos/NTLM and host/ip based coarse-grained and  
> document level security for elasticsearch (early dev stage but roughly  
> working)
> 
> [GitHub - salyh/elasticsearch-security-plugin: Kerberos, LDAP, Active Directory, PKI/SSL/TLS and host/ip based ACL coarse-grained and document level security for elasticsearch (Authentication, Authorization, Auth, Spnego, ACL, Mutual authentication)](https://github.com/salyh/elasticsearch-security-plugin)
> 
> _This plugin adds http/rest security functionality to Elasticsearch in  
> kind of separate modules. Instead of Netty a embedded Tomcat 7 is used to  
> process http/rest requests._
> 
> \*Currently for user based authentication and authorization Kerberos and  
> NTLM are supported through 3rd party library waffle (only on windows  
> servers). \*  
> _For UNIX servers Kerberos is supported through 3rd party library  
> tomcatspnegoad (Works with any kerberos implementation. For authorization  
> either Active Directory and generic LDAP is supported)._
> 
> _You can use this plugin also without Kerberos/NTLM but then only host  
> based authentication is available._
> 
> _As of now two security modules are implemented:_
> 
> - _Actionpathfilter: Restrict actions against Elasticsearch on a  
> coarse-grained level like who is allowed to to READ, WRITE or even ADMIN  
> rest api calls_
> - _Document level security (dls): Restrict actions on document level  
> like who is allowed to query for which fields within a document_
> 
> Suggestions, corrections, improvements are very welcome!  
> Thanks and best regards  
> Hendrik

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b1b92d70-18ac-47b1-be9c-2025d3bcc4f8%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b1b92d70-18ac-47b1-be9c-2025d3bcc4f8%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:44am UTC](https://discuss.elastic.co/t/elasticsearch-security-plugin-kerberos-ntlm-and-host-ip-based-coarse-grained-and-document-level-security-for-elasticsearch/14477/7 "2017-07-06T00:44:34Z")

</div>


