# Getting java.security.AccessControlException error on service startup

**URL:** <https://discuss.elastic.co/t/getting-java-security-accesscontrolexception-error-on-service-startup/191884>\
**Category:** Elasticsearch\
**Created:** [July 23, 2019, 5:52pm UTC](https://discuss.elastic.co/t/getting-java-security-accesscontrolexception-error-on-service-startup/191884 "2019-07-23T17:52:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![byoungman](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@byoungman](https://discuss.elastic.co/u/byoungman)\
**Post date:** [July 23, 2019, 5:52pm UTC](https://discuss.elastic.co/t/getting-java-security-accesscontrolexception-error-on-service-startup/191884/1 "2019-07-23T17:52:50Z")

</div>

The specific error is:  
Getting java.security.AccessControlException: access denied ("java.io.FilePermission" "D:\ELK\appdynamics\conf\SAPPLOG01\processPersistenceFile.ser" "read") error

I've installed an APM agent in my Elasticsearch instance and have a parameter in my jvm.options file to start it up on Elasticsearch startup. The issue that I am running into is the error that I've specified above. I've searched the documentation for Elasticsearch configuration but can't find anything that references when Elasticsearch needs to access anything outside of it's directory structure.

What am I missing here?

TIA,  
Bill Youngman

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [July 24, 2019, 3:58am UTC](https://discuss.elastic.co/t/getting-java-security-accesscontrolexception-error-on-service-startup/191884/2 "2019-07-24T03:58:05Z")

</div>

You have to grant an additional security manager permission to Elasticsearch, as Elasticsearch restricts itself to only read a limited set of paths. Note that doing so is at your own risk.

---

<div class="post-metadata">

**Author:** ![byoungman](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@byoungman](https://discuss.elastic.co/u/byoungman)\
**Post date:** [July 24, 2019, 1:11pm UTC](https://discuss.elastic.co/t/getting-java-security-accesscontrolexception-error-on-service-startup/191884/3 "2019-07-24T13:11:10Z")

</div>

New at this - how would I do that?

Thanks

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [July 25, 2019, 8:12am UTC](https://discuss.elastic.co/t/getting-java-security-accesscontrolexception-error-on-service-startup/191884/4 "2019-07-25T08:12:45Z")

</div>

You can create a custom [policy file](https://docs.oracle.com/javase/7/docs/technotes/guides/security/PolicyFiles.html) and add the grant `permission java.io.FilePermission "D:\ELK\appdynamics\conf\SAPPLOG01\processPersistenceFile.ser", "read"` to that policy file.

I want to be clear about two things here:

- you're in your own territory here as far as the security risks here
- we do not support Elasticsearch with agents like this attached

---

<div class="post-metadata">

**Author:** ![byoungman](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@byoungman](https://discuss.elastic.co/u/byoungman)\
**Post date:** [July 25, 2019, 1:19pm UTC](https://discuss.elastic.co/t/getting-java-security-accesscontrolexception-error-on-service-startup/191884/5 "2019-07-25T13:19:47Z")

</div>

Jason,

Our ELK stack is located in an internal domain that you have to be a member of in order to get access to the system so if you haven't been added to that domain group you can't access anything in it.

Understood about the agent support or not supporting. I tried to make the pitch to use your APM but our Technical Director went off and in a silo selected this system without consulting anybody or getting feedback so we're stuck with it.

Thanks,  
Bill

---

<div class="post-metadata">

**Author:** ![byoungman](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@byoungman](https://discuss.elastic.co/u/byoungman)\
**Post date:** [July 26, 2019, 6:35pm UTC](https://discuss.elastic.co/t/getting-java-security-accesscontrolexception-error-on-service-startup/191884/6 "2019-07-26T18:35:01Z")

</div>

Jason,

I was able to get a custom security .policy configuration up and running so I'm going to mark this thread as solved.

But as i stated earlier once we get approval to expand our ELK stack we'll be moving the apm into the Elasticsearch environment.

Thanks,  
Bill

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [July 27, 2019, 2:12pm UTC](https://discuss.elastic.co/t/getting-java-security-accesscontrolexception-error-on-service-startup/191884/7 "2019-07-27T14:12:34Z")

</div>

Great news, on both fronts, that you’re running for now, and aiming to move to Elastic APM.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2019, 2:12pm UTC](https://discuss.elastic.co/t/getting-java-security-accesscontrolexception-error-on-service-startup/191884/8 "2019-08-24T14:12:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
