# How to customize plugin-security.policy for custom realm

**URL:** <https://discuss.elastic.co/t/how-to-customize-plugin-security-policy-for-custom-realm/71570>\
**Category:** Elasticsearch\
**Created:** [January 13, 2017, 9:07pm UTC](https://discuss.elastic.co/t/how-to-customize-plugin-security-policy-for-custom-realm/71570 "2017-01-13T21:07:38Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![kldavis4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kldavis4/32/14562_2.png) [@kldavis4](https://discuss.elastic.co/u/kldavis4)\
**Post date:** [January 13, 2017, 9:07pm UTC](https://discuss.elastic.co/t/how-to-customize-plugin-security-policy-for-custom-realm/71570/1 "2017-01-13T21:07:38Z")

</div>

I have a custom realm that uses OkHttpClient. When it is instantiated, it calls ProxySelector.getDefault() which requires 'permission java.net.NetPermission "getProxySelector"'. This is not granted to x-pack, so it breaks the realm. I tried editing the plugin policy for x-pack after the fact and it sort of works. Is that the best approach? When I try to do this using a customized Elasticsearch docker image, it fails (I have a Dockerfile that installs the x-pack, the realm, and then updates the x-pack plugin policy). If I run the custom image without starting up docker and then start it manually, it seems to pick up the change.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [January 13, 2017, 9:29pm UTC](https://discuss.elastic.co/t/how-to-customize-plugin-security-policy-for-custom-realm/71570/2 "2017-01-13T21:29:00Z")

</div>

You can add a custom policy for your custom realm at the same directory level as the descriptor properties file. It needs to have the file name `x-pack-extension-security.policy`. We will work on updating the example realm to include an example of this

---

<div class="post-metadata">

**Author:** ![kldavis4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kldavis4/32/14562_2.png) [@kldavis4](https://discuss.elastic.co/u/kldavis4)\
**Post date:** [January 13, 2017, 10:24pm UTC](https://discuss.elastic.co/t/how-to-customize-plugin-security-policy-for-custom-realm/71570/3 "2017-01-13T22:24:30Z")

</div>

Ok, great. Thanks for the quick answer. I assume this isn't in the docs anywhere yet, right?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [January 14, 2017, 9:42pm UTC](https://discuss.elastic.co/t/how-to-customize-plugin-security-policy-for-custom-realm/71570/4 "2017-01-14T21:42:29Z")

</div>

Correct, it is not in the docs yet either.

---

<div class="post-metadata">

**Author:** ![kldavis4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kldavis4/32/14562_2.png) [@kldavis4](https://discuss.elastic.co/u/kldavis4)\
**Post date:** [January 16, 2017, 1:50pm UTC](https://discuss.elastic.co/t/how-to-customize-plugin-security-policy-for-custom-realm/71570/5 "2017-01-16T13:50:08Z")

</div>

So, now, after installing the custom realm extension I have a file named  
x-pack-extension-security.policy in  
/usr/share/elasticsearch/plugins/x-pack/extensions/mycustomrealm.

The contents of the file is:

grant {  
permission java.net.NetPermission "getProxySelector";  
};

I am still getting an error: java.security.AccessControlException: access  
denied ("java.net.NetPermission" "getProxySelector") when the client is  
instantiated. Any ideas? This is with 5.1.1.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [January 17, 2017, 3:55pm UTC](https://discuss.elastic.co/t/how-to-customize-plugin-security-policy-for-custom-realm/71570/6 "2017-01-17T15:55:00Z")

</div>

Is the code that is calling the OkHttp code that needs additional privileges wrapped in a doPrivileged block?

```
AccessController.doPrivileged((PrivilegedAction<Void>) () -> {
     // privileged code goes here
    return null;
});
```

---

<div class="post-metadata">

**Author:** ![kldavis4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kldavis4/32/14562_2.png) [@kldavis4](https://discuss.elastic.co/u/kldavis4)\
**Post date:** [January 17, 2017, 4:53pm UTC](https://discuss.elastic.co/t/how-to-customize-plugin-security-policy-for-custom-realm/71570/7 "2017-01-17T16:53:22Z")

</div>

Thank you. That was the problem. I am not to familiar with the Java SecurityManager so this is new to me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2017, 4:53pm UTC](https://discuss.elastic.co/t/how-to-customize-plugin-security-policy-for-custom-realm/71570/8 "2017-02-14T16:53:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
