# I got the exception when I added kerberos authentication to es

**URL:** <https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 15, 2023, 8:04am UTC](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116 "2023-09-15T08:04:37Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![zytine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zytine/32/125598_2.png) [@zytine](https://discuss.elastic.co/u/zytine)\
**Post date:** [September 15, 2023, 8:04am UTC](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116/1 "2023-09-15T08:04:37Z")

</div>

Hello,  
My es was running fine, but when I added kerberos authentication and restarted，I got the following error

```auto
[2023-09-15T23:09:36,876][WARN][o.e.x.s.a.s.m.NativeRoleMappingStore] [bsa264] Failed to clear cache for realms [[kerb1]]
org.elasticsearch.ElasticsearchException: Security must be explicitly enabled when using a [trial] license. Enable security by setting [xpack.security.enabled] to [true] in the elasticsearch.yml file and restart the node.
        at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.apply(SecurityActionFilter.java:116) ~[?:?]
        at org.elasticsearch.action.support.TransportAction$RequestFilterChain.proceed(TransportAction.java:151) ~[elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.action.support.TransportAction.execute(TransportAction.java:129) ~[elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.action.support.TransportAction.execute(TransportAction.java:64) ~[elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.client.node.NodeClient.executeLocally(NodeClient.java:83) ~[elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.client.node.NodeClient.doExecute(NodeClient.java:72) ~[elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.client.support.AbstractClient.execute(AbstractClient.java:396) ~[elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.xpack.core.security.client.SecurityClient.clearRealmCache(SecurityClient.java:133) ~[?:?]
        at org.elasticsearch.xpack.core.ClientHelper.executeAsyncWithOrigin(ClientHelper.java:75) ~[?:?]
        at org.elasticsearch.xpack.security.authc.support.mapper.NativeRoleMappingStore.refreshRealms(NativeRoleMappingStore.java:340) ~[?:?]
        at org.elasticsearch.xpack.security.authc.support.mapper.NativeRoleMappingStore.onSecurityIndexStateChange(NativeRoleMappingStore.java:328) ~[?:?]
        at org.elasticsearch.xpack.security.support.SecurityIndexManager.clusterChanged(SecurityIndexManager.java:236) ~[?:?]
        at org.elasticsearch.cluster.service.ClusterApplierService.lambda$callClusterStateListeners$6(ClusterApplierService.java:527) ~[elasticsearch-7.5.2.jar:7.5.2]
        at java.util.Spliterators$ArraySpliterator.forEachRemaining(Spliterators.java:948) [?:1.8.0_211]
        at java.util.stream.Streams$ConcatSpliterator.forEachRemaining(Streams.java:742) [?:1.8.0_211]
        at java.util.stream.ReferencePipeline$Head.forEach(ReferencePipeline.java:580) [?:1.8.0_211]
        at org.elasticsearch.cluster.service.ClusterApplierService.callClusterStateListeners(ClusterApplierService.java:523) [elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.cluster.service.ClusterApplierService.applyChanges(ClusterApplierService.java:498) [elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.cluster.service.ClusterApplierService.runTask(ClusterApplierService.java:432) [elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.cluster.service.ClusterApplierService.access$100(ClusterApplierService.java:73) [elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.cluster.service.ClusterApplierService$UpdateTask.run(ClusterApplierService.java:176) [elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:703) [elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.runAndClean(PrioritizedEsThreadPoolExecutor.java:252) [elasticsearch-7.5.2.jar:7.5.2]
        at org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.run(PrioritizedEsThreadPoolExecutor.java:215) [elasticsearch-7.5.2.jar:7.5.2]
        at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) [?:1.8.0_211]
        at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) [?:1.8.0_211]
        at java.lang.Thread.run(Thread.java:748) [?:1.8.0_211]

```

And when I followed the documentation to do "Map Kerberos users to roles",I got the error too.

```auto
{"error":{"root_cause":[{"type":"exception","reason":"Security must be explicitly enabled when using a [basic] license. Enable security by setting [xpack.security.enabled] to [true] in the elasticsearch.yml file and restart the node."}],"type":"exception","reason":"Security must be explicitly enabled when using a [basic] license. Enable security by setting [xpack.security.enabled] to [true] in the elasticsearch.yml file and restart the node."},"status":500}

```

My elasticsearch.yml :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d4dc8a983fe84ac88bae83d161735e5e322af1f1.png)

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 15, 2023, 12:29pm UTC](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116/2 "2023-09-15T12:29:24Z")

</div>

The error message tells you what you need to do - you need to enable security by setting `xpack.security.enabled` to `true`.

---

<div class="post-metadata">

**Author:** ![zytine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zytine/32/125598_2.png) [@zytine](https://discuss.elastic.co/u/zytine)\
**Post date:** [September 18, 2023, 3:11am UTC](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116/4 "2023-09-18T03:11:43Z")

</div>

Is it necessary to enable xpack authentication before kerberos authentication? Wouldn't I need both username-password and keytab to access es?

---

<div class="post-metadata">

**Author:** ![zytine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zytine/32/125598_2.png) [@zytine](https://discuss.elastic.co/u/zytine)\
**Post date:** [September 18, 2023, 9:33am UTC](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116/5 "2023-09-18T09:33:11Z")

</div>

After I added these xpack settings,I started es successfully.But I got the following error when I verified:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e146d95d02e47cd30890f975408dd31477764ed7.png)

I have excuted "kinit":

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/5/45e836f8d4afb40ca796c7e9ae374a34addf0a4c.png)

So why? Help me please.

And actually the documentation doesn't mention about setting [xpack.security.enabled],and I can't find the message about the error. But It is mentioned somewhere that kerberos authentication can't be supported in [basic] version,does that cause the error?

And here is the kerberos documentation I refer to, is there more detailed documentation?

> **[Kerberos authentication | Elasticsearch Guide \[7.5\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/kerberos-realm.html)**

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 20, 2023, 1:53am UTC](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116/6 "2023-09-20T01:53:49Z")

</div>

> [@zytine](#):
>
> Is it necessary to enable xpack authentication before kerberos authentication?

Yes, because you cannot have Kerberos Authentication if you don't have authentication. If the Elasticsearch security features have been turned off, then there is no way to configure & use Kerberos - it is part of the security features.

You can configure some parts of Kerberos authentication without enabling all of security, but you eventually run into steps that cannot be completed while security is turned off.

> [@](#):
>
> `org.elasticsearch.ElasticsearchException: Security must be explicitly enabled when using a [trial] license. Enable security by setting [xpack.security.enabled] to [true] in the elasticsearch.yml file and restart the node.`

> [@](#):
>
> `{"error":{"root_cause":[{"type":"exception","reason":"Security must be explicitly enabled when using a [basic] license. Enable security by setting [xpack.security.enabled] to [true] in the elasticsearch.yml file and restart the node."}],"type":"exception","reason":"Security must be explicitly enabled when using a [basic] license. Enable security by setting [xpack.security.enabled] to [true] in the elasticsearch.yml file and restart the node."},"status":500}`

> [@zytine](#):
>
> kerberos authentication can't be supported in [basic] version,does that cause the error

That is correct. At some point you seem to have switched from a `trial` license to a `basic` license. Kerberos authentication is not available on a basic license.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2023, 1:53am UTC](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116/7 "2023-10-18T01:53:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
