# Enabling entitlements for my plugin using Elastic Search 8.18.0

**URL:** <https://discuss.elastic.co/t/enabling-entitlements-for-my-plugin-using-elastic-search-8-18-0/377624>\
**Category:** Elasticsearch\
**Created:** [April 29, 2025, 1:30pm UTC](https://discuss.elastic.co/t/enabling-entitlements-for-my-plugin-using-elastic-search-8-18-0/377624 "2025-04-29T13:30:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![eereiter](https://avatars.discourse-cdn.com/v4/letter/e/b5e925/32.png) [@eereiter](https://discuss.elastic.co/u/eereiter)\
**Post date:** [April 29, 2025, 1:30pm UTC](https://discuss.elastic.co/t/enabling-entitlements-for-my-plugin-using-elastic-search-8-18-0/377624/1 "2025-04-29T13:30:04Z")

</div>

I have a custom search plugin that I can install. I am getting an exception when the plugin gets called:  
Not entitled: component [cmr\_spatial], module [ALL-UNNAMED], class [class clojure.lang.DynamicClassLoader], entitlement [create\_class\_loader]"

I have tried creating a entitlement-policy.yaml file with the following contents:  
ALL-UNNAMED:

- create\_class\_loader

I have added to the jvm-opts -Des.entitlements.enabled=false - although earlier in the jvm-opts Elastic search sets this to true.

I can't figure out how to either get permission to create the class loader or to disable the entitlements. Any help would be appreciated. Thank you

---

<div class="post-metadata">

**Author:** ![Lorenzo\_Dematte](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lorenzo_dematte/32/142692_2.png) [@Lorenzo\_Dematte](https://discuss.elastic.co/u/Lorenzo_Dematte)\
**Post date:** [April 30, 2025, 8:41am UTC](https://discuss.elastic.co/t/enabling-entitlements-for-my-plugin-using-elastic-search-8-18-0/377624/2 "2025-04-30T08:41:10Z")

</div>

Hello @eereiter;  
Entitlements are a security feature and It's not possible to disable them.  
You are on the right path creating a `entitlement-policy.yaml` file, but as you can see here [Creating classic plugins | Elastic Documentation](https://www.elastic.co/docs/extend/elasticsearch/creating-classic-plugins) in the docs, `create_class_loader` is not available to external plugins; give the ability to 3rd party code to create and load arbitrary classes from arbitrary sources could compromise the ES server process security.  
I am afraid there is no workaround available for 8.18.0 and 9.0.0 currently; the only option is to re-work your plugin so it does not create or use a dependency that creates a class loader.

---

<div class="post-metadata">

**Author:** ![eereiter](https://avatars.discourse-cdn.com/v4/letter/e/b5e925/32.png) [@eereiter](https://discuss.elastic.co/u/eereiter)\
**Post date:** [April 30, 2025, 10:50am UTC](https://discuss.elastic.co/t/enabling-entitlements-for-my-plugin-using-elastic-search-8-18-0/377624/3 "2025-04-30T10:50:00Z")

</div>

> [@Lorenzo\_Dematte](#):
>
> Hello @eereiter;  
> Entitlements are a security feature and It's not possible to disable them.  
> You are on the right path creating a `entitlement-policy.yaml` file, but as you can see here [Creating classic plugins | Elastic Documentation](https://www.elastic.co/docs/extend/elasticsearch/creating-classic-plugins) in the docs, `create_class_loader` is not available to external plugins; give the ability to 3rd party code to create and load arbitrary classes from arbitrary sources could compromise the ES server process security.  
> I am afraid there is no workaround available for 8.18.0 and 9.0.0 currently; the only option is to re-work your plugin so it does not create or use a dependency that creates a class loader.

Thanks for the response and information. I appreciate it.
