# Error when testing sample about Security Extensions and Custom Realms from Elasticsearch blog post

**URL:** <https://discuss.elastic.co/t/error-when-testing-sample-about-security-extensions-and-custom-realms-from-elasticsearch-blog-post/159683>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 6, 2018, 8:31am UTC](https://discuss.elastic.co/t/error-when-testing-sample-about-security-extensions-and-custom-realms-from-elasticsearch-blog-post/159683 "2018-12-06T08:31:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Uiidoi12](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@Uiidoi12](https://discuss.elastic.co/u/Uiidoi12)\
**Post date:** [December 6, 2018, 8:31am UTC](https://discuss.elastic.co/t/error-when-testing-sample-about-security-extensions-and-custom-realms-from-elasticsearch-blog-post/159683/1 "2018-12-06T08:31:25Z")

</div>

Hi,

I followed steps from [this blog post](https://www.elastic.co/blog/how-to-develop-your-own-security-extensions-and-custom-realms-for-elasticsearch) and tried the following commands to test, after installing the plugin on my Elasticsearch instance:

```auto
$ curl 'localhost:9200/webstore-45/_doc/1' -d '{ "name":"store-45-item-1" }' \
  -u elastic -XPUT -H "Content-Type: application/json" 
$ curl 'localhost:9200/webstore-45/_doc/2' -d '{ "name":"store-45-item-2" }' \
  -u elastic -XPUT -H "Content-Type: application/json" 
$ curl 'localhost:9200/webstore-50/_doc/1' -d '{ "name":"store-50-item-1" }' \
  -u elastic -XPUT -H "Content-Type: application/json" 
$ curl 'localhost:9200/webstore-50/_doc/2' -d '{ "name":"store-50-item-2" }' \
  -u elastic -XPUT -H "Content-Type: application/json" 

```

```auto
$ ClaimJson='{"principal":"store-45-user","storeId":45,"role":"reader"}'
$ unzip certs.zip webstore/webstore.key
$ ClaimSig="$( printf '%s' "$ClaimJson" | \
    openssl dgst -sha256 -sign webstore/webstore.key | base64)"

```

then the call to:

```auto
curl "localhost:9200/_xpack/security/_authenticate" \
    -H "x-web-store-claims: $ClaimJson" -H "x-web-store-sig: $ClaimSig"

```

gives me the following error:

```json
{
  "error": {
    "root_cause": [
      {
        "type": "illegal_argument_exception",
        "reason": "a header name cannot contain the following prohibited characters: =,;: \\t\\r\\n\\v\\f: ="
      }
    ],
    "type": "illegal_argument_exception",
    "reason": "a header name cannot contain the following prohibited characters: =,;: \\t\\r\\n\\v\\f: ="
  },
  "status": 400
}

```

Just FYI I'm running Elasticsearch with docker and executing those commands from host machine.  
Tried with both v6.3 and 6.5.1

Any help please?

Thanks

---

<div class="post-metadata">

**Author:** ![Uiidoi12](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@Uiidoi12](https://discuss.elastic.co/u/Uiidoi12)\
**Post date:** [December 6, 2018, 11:14am UTC](https://discuss.elastic.co/t/error-when-testing-sample-about-security-extensions-and-custom-realms-from-elasticsearch-blog-post/159683/2 "2018-12-06T11:14:30Z")

</div>

Ok it seems I found a solution by adding:

```auto
ClaimSig=`echo $ClaimSig | sed 's/\n//g' | sed 's/\t//g' | sed 's/ //g'`

```

Now the problem is that the `_authenticate` call:

```auto
curl "localhost:9200/_xpack/security/_authenticate" \
    -H "x-web-store-claims: $ClaimJson" -H "x-web-store-sig: $ClaimSig"

```

returns:

```json
{
   "error" : {
      "header" : {
         "WWW-Authenticate" : "Basic realm=\"security\" charset=\"UTF-8\""
      },
      "reason" : "missing authentication token for REST request [/_xpack/security/_authenticate]",
      "root_cause" : [
         {
            "header" : {
               "WWW-Authenticate" : "Basic realm=\"security\" charset=\"UTF-8\""
            },
            "reason" : "missing authentication token for REST request [/_xpack/security/_authenticate]",
            "type" : "security_exception"
         }
      ],
      "type" : "security_exception"
   },
   "status" : 401
}

```

Any idea?  
Thanks

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 10, 2018, 4:58am UTC](https://discuss.elastic.co/t/error-when-testing-sample-about-security-extensions-and-custom-realms-from-elasticsearch-blog-post/159683/3 "2018-12-10T04:58:25Z")

</div>

> [@Uiidoi12](#):
>
> Any idea?

At a guess, it doesn't look like you've configured a `webstore` realm

---

<div class="post-metadata">

**Author:** ![Uiidoi12](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@Uiidoi12](https://discuss.elastic.co/u/Uiidoi12)\
**Post date:** [December 10, 2018, 1:44pm UTC](https://discuss.elastic.co/t/error-when-testing-sample-about-security-extensions-and-custom-realms-from-elasticsearch-blog-post/159683/4 "2018-12-10T13:44:15Z")

</div>

yes, you are right. I forgot to configure it!

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2019, 1:44pm UTC](https://discuss.elastic.co/t/error-when-testing-sample-about-security-extensions-and-custom-realms-from-elasticsearch-blog-post/159683/5 "2019-01-07T13:44:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
