# Extending Shield 2.0 with custom plugin

**URL:** <https://discuss.elastic.co/t/extending-shield-2-0-with-custom-plugin/33888>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 5, 2015, 4:07pm UTC](https://discuss.elastic.co/t/extending-shield-2-0-with-custom-plugin/33888 "2015-11-05T16:07:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![nielsoncr](https://avatars.discourse-cdn.com/v4/letter/n/c57346/32.png) [@nielsoncr](https://discuss.elastic.co/u/nielsoncr)\
**Post date:** [November 5, 2015, 4:07pm UTC](https://discuss.elastic.co/t/extending-shield-2-0-with-custom-plugin/33888/1 "2015-11-05T16:07:20Z")

</div>

I am looking for information on authoring a Java plugin that extends Shield 2.0 capabilities. Specifically I want the plugin to use a custom library to authenticate a user based a SAML token. The SAML token contains claims that would then be used to tell Shield whether a user is authenticated and what their Shield "role" is.

Thanks in advance.

Update : I have the CustomRealmExamplePlugin working -- see [https://github.com/elastic/shield-custom-realm-example](https://github.com/elastic/shield-custom-realm-example)

I'd like to change  
public class CustomRealm extends Realm

so it will accept a SAML token passed in the HTTP header for authentication. I haven't had much luck finding documentation on what other types are available to hand to the Realm class or how to use them. Something like Realm or similar would be very helpful.

Thanks

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [November 10, 2015, 1:53pm UTC](https://discuss.elastic.co/t/extending-shield-2-0-with-custom-plugin/33888/2 "2015-11-10T13:53:20Z")

</div>

Hi Curtis,

I'm glad you found the custom realm plugin and were able to get it working. You're correct in that you will need to create your own realm like the CustomRealm.

A list of things that you will probably need to do:

1. Create a `SamlToken` that implements `AuthenticationToken`
2. Create a custom realm for SAML. This will need the ability to extract a `SamlToken` from a HTTP header (most likely Base64 encoded). The realm will also need to be able to verify the SAML token and extract the user identity plus authorization information (roles).
3. Create a custom `AuthenticationFailureHandler` that will redirect requests to your authentication service when requests do not have a SAML token

Is there a SAML library that you are already planning to use?

-Jay

---

<div class="post-metadata">

**Author:** ![nielsoncr](https://avatars.discourse-cdn.com/v4/letter/n/c57346/32.png) [@nielsoncr](https://discuss.elastic.co/u/nielsoncr)\
**Post date:** [February 8, 2016, 2:05pm UTC](https://discuss.elastic.co/t/extending-shield-2-0-with-custom-plugin/33888/3 "2016-02-08T14:05:26Z")

</div>

Jay,

Thanks for your previous feedback -- I forgot to report back that we have our Custom Realm Shield Plugin working with SAML token authentication. Now we want to make it work with Kibana.

Our use case is Kibana users will use a login page that redirects them to Kibana with a SAML token in the HTTP Authorization header. We want Kibana to reject any access without a valid SAML token and pass the token to the Elasticsearch + Shield + Custom Realm Plugin on each call.

We are considering two possible options.

What would you recommend? I see that Kibana has new login page -- is there a way to plugin to it as I've described?

Thanks  
Curtis

---

<div class="post-metadata">

**Author:** ![Pierre\_Jacquot](https://avatars.discourse-cdn.com/v4/letter/p/e274bd/32.png) [@Pierre\_Jacquot](https://discuss.elastic.co/u/Pierre_Jacquot)\
**Post date:** [March 11, 2016, 2:03pm UTC](https://discuss.elastic.co/t/extending-shield-2-0-with-custom-plugin/33888/4 "2016-03-11T14:03:18Z")

</div>

Hello Nielson,

We are working on a similar topic on our side.  
Do you have any reference that may help us to implement this kind of solution.

---

<div class="post-metadata">

**Author:** ![nielsoncr](https://avatars.discourse-cdn.com/v4/letter/n/c57346/32.png) [@nielsoncr](https://discuss.elastic.co/u/nielsoncr)\
**Post date:** [March 15, 2016, 3:58pm UTC](https://discuss.elastic.co/t/extending-shield-2-0-with-custom-plugin/33888/5 "2016-03-15T15:58:48Z")

</div>

> [@nielsoncr](#):
>
> Update : I have the CustomRealmExamplePlugin working -- see [GitHub - elastic/shield-custom-realm-example](https://github.com/elastic/shield-custom-realm-example)

The CustomRealmExamplePlugin referenced above is a good place to start. see [GitHub - elastic/shield-custom-realm-example](https://github.com/elastic/shield-custom-realm-example)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/extending-shield-2-0-with-custom-plugin/33888/6 "2017-07-06T13:46:03Z")

</div>


