# Java API for Shield is not Working

**URL:** <https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473>\
**Category:** Elasticsearch\
**Created:** [December 17, 2015, 1:31pm UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473 "2015-12-17T13:31:22Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anusha](https://avatars.discourse-cdn.com/v4/letter/a/c5a1d2/32.png) [@Anusha](https://discuss.elastic.co/u/Anusha)\
**Post date:** [December 17, 2015, 1:31pm UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/1 "2015-12-17T13:31:22Z")

</div>

Hi Team,

I installed shield 1.3 as am using elasticsearch 1.5.2,  
created \*\*user : es\_admin \*\*  
**role : admin**  
**password : anusha**

Tested the response in Sense plugin, working fine with user and password able to get the response.

But when  
Am using Java API for to add user credentials as shown..

**Settings settings = ImmutableSettings.settingsBuilder().put("[cluster.name](http://cluster.name)", "elasticsearch").put("shield.user", "admin:anusha").build();**  
**String token = basicAuthHeaderValue("es\_admin", new SecuredString("anusha".toCharArray()));**

**Client client = new TransportClient(settings).addTransportAddress(new InetSocketTransportAddress("localhost", 9300))**

// Code for Search Response using client

**SearchResponse response = client.prepareSearch("ast").setTypes("ast\_type").putHeader("Authorization", token).setSize(410000).execute() .actionGet();**

When am executing above code getting exception as:

Exception in thread "main" org.elasticsearch.client.transport.NoNodeAvailableException: None of the configured nodes are available: []  
at org.elasticsearch.client.transport.TransportClientNodesService.ensureNodesAreAvailable(TransportClientNodesService.java:278)  
at org.elasticsearch.client.transport.TransportClientNodesService.execute(TransportClientNodesService.java:197)  
....................................

Can anyone plz help me to solve this...

---

<div class="post-metadata">

**Author:** ![jimczi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimczi/32/47985_2.png) [@jimczi](https://discuss.elastic.co/u/jimczi)\
**Post date:** [December 17, 2015, 4:19pm UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/2 "2015-12-17T16:19:49Z")

</div>

Maybe not related but why are you setting the size to 410,000?, seems like a very big number of hits to retrieve in one request. Check the logs of your es instance to see if your node did not ran out of memory (which could explain the exception you're getting).

---

<div class="post-metadata">

**Author:** ![Anusha](https://avatars.discourse-cdn.com/v4/letter/a/c5a1d2/32.png) [@Anusha](https://discuss.elastic.co/u/Anusha)\
**Post date:** [December 19, 2015, 9:23am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/3 "2015-12-19T09:23:45Z")

</div>

Hi Jim,

Thanks for your response,

If I disable the shield plugin (like I have added **shield.enabled: false** in **elasticsearch.yml** file), then the query working fine and able to get the response,

May I know the why it is behaving differently when I use shield plugin,  
But am able to get the response in sense plugin..

The dependency that I have added for shield and license is :

```
    <!-- add the Shield jar as a dependency -->
    <dependency>
        <groupId>org.elasticsearch</groupId>
        <artifactId>elasticsearch-shield</artifactId>
        <version>1.0.0</version>
    </dependency>
    <!-- add the License jar as a dependency -->
    <dependency>
        <groupId>org.elasticsearch</groupId>
        <artifactId>elasticsearch-license-plugin</artifactId>
        <version>1.0.0</version>
        <scope>runtime</scope>
    </dependency>
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 19, 2015, 9:36am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/4 "2015-12-19T09:36:09Z")

</div>

Why not using shield 1.3?

---

<div class="post-metadata">

**Author:** ![Anusha](https://avatars.discourse-cdn.com/v4/letter/a/c5a1d2/32.png) [@Anusha](https://discuss.elastic.co/u/Anusha)\
**Post date:** [December 19, 2015, 9:39am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/5 "2015-12-19T09:39:26Z")

</div>

Hello David,

Yes I changed to 1.3.3 (shield version), even though it is behaving in the same way

> [@Anusha](#):
>
> Exception in thread "main" org.elasticsearch.client.transport.NoNodeAvailableException: None of the configured nodes are available:

.........

Don't know, is there any thing wrong in the query??? If so, then why the query is working when I disabled the shield plugin..

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 19, 2015, 10:05am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/6 "2015-12-19T10:05:07Z")

</div>

I'd check all the steps there: [https://www.elastic.co/guide/en/shield/shield-1.3/\_using\_elasticsearch\_java\_clients\_with\_shield.html](https://www.elastic.co/guide/en/shield/shield-1.3/_using_elasticsearch_java_clients_with_shield.html)

I don't see BTW why you are adding the license plugin.

---

<div class="post-metadata">

**Author:** ![Anusha](https://avatars.discourse-cdn.com/v4/letter/a/c5a1d2/32.png) [@Anusha](https://discuss.elastic.co/u/Anusha)\
**Post date:** [December 19, 2015, 10:17am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/7 "2015-12-19T10:17:29Z")

</div>

I just commented out the license plugin dependency, my application is showing lot of errors.

Is there any problem on adding license plugin in dependencies??????

---

<div class="post-metadata">

**Author:** ![Anusha](https://avatars.discourse-cdn.com/v4/letter/a/c5a1d2/32.png) [@Anusha](https://discuss.elastic.co/u/Anusha)\
**Post date:** [December 19, 2015, 10:23am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/8 "2015-12-19T10:23:44Z")

</div>

And I even verified the versions of the shield and license plugin those are installed in ES using ,

**GET /\_nodes?plugin=true**

in sense plugin, seen that **shield : 1.3.3** and **license :1.0.0** versions, so I have used those versions in my dependencies.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 19, 2015, 10:42am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/9 "2015-12-19T10:42:45Z")

</div>

If I read the doc correctly you don't need the license plugin when you use Java transport client.

---

<div class="post-metadata">

**Author:** ![Anusha](https://avatars.discourse-cdn.com/v4/letter/a/c5a1d2/32.png) [@Anusha](https://discuss.elastic.co/u/Anusha)\
**Post date:** [December 19, 2015, 10:58am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/10 "2015-12-19T10:58:22Z")

</div>

Yes David, I just removed the license plugin dependency(no errors I have seen in my code) , but even though am unable to get the response......

---

<div class="post-metadata">

**Author:** ![Anusha](https://avatars.discourse-cdn.com/v4/letter/a/c5a1d2/32.png) [@Anusha](https://discuss.elastic.co/u/Anusha)\
**Post date:** [December 19, 2015, 11:14am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/11 "2015-12-19T11:14:30Z")

</div>

Hi David,

This time am getting a different error, where I just changed here

**ImmutableSettings.settingsBuilder().put("[cluster.name](http://cluster.name)", "elasticsearch").put("shield.user", "es\_admin:anusha").build();**

shield.user I have changed as **es\_admin:anusha**

And for this am getting Exception as,

**Exception in thread "main" org.elasticsearch.shield.authc.AuthenticationException: missing authentication token for action [indices:data/read/search] at org.elasticsearch.shield.authc.InternalAuthenticationService.authenticateWithRealms(InternalAuthenticationService.java:229) at org.elasticsearch.shield.authc.InternalAuthenticationService.authenticate(InternalAuthenticationService.java:136)......**

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 19, 2015, 11:55am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/12 "2015-12-19T11:55:21Z")

</div>

You really added that?

```auto
String token = basicAuthHeaderValue("es_admin", new SecuredString("anusha".toCharArray()));
client.prepareSearch().putHeader("Authorization", token).get();

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 19, 2015, 11:57am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/13 "2015-12-19T11:57:54Z")

</div>

May be you could share:

- your `config/shield/*` files
- your `config/elasticsearch.yml` file
- your elasticsearch logs
- your java client code

---

<div class="post-metadata">

**Author:** ![Anusha](https://avatars.discourse-cdn.com/v4/letter/a/c5a1d2/32.png) [@Anusha](https://discuss.elastic.co/u/Anusha)\
**Post date:** [December 21, 2015, 5:20am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/14 "2015-12-21T05:20:44Z")

</div>

Hi David,

Here is my files:

**elasticsearch.yml:**

cluster.name: elasticsearch

node.name: "Franz Kafka1"

node.master: true

node.data: true

discovery.zen.ping.multicast.enabled: false

discovery.zen.ping.unicast.hosts: ["localhost"]

http.jsonp.enable: true  
script.disable\_dynamic: false  
script.inline: on  
script.indexed: on  
http.cors.enabled: true  
http.cors.allow-origin: [http://localhost:5601](http://localhost:5601)

In shield folder:

**logging.yml:**

logger:  
shield.audit.logfile: INFO, access\_log

additivity:  
shield.audit.logfile: false

appender:

access\_log:  
type: dailyRollingFile  
file: {path.logs}/{cluster.name}-access.log  
datePattern: "'.'yyyy-MM-dd"  
layout:  
type: pattern  
conversionPattern: "[%d{ISO8601}] %m%n"

**role\_mapping.yml:**  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/196dbb6c512f69c86c0c3ded272d3d3765855b0e.png)

**roles.yml:**

##### # All cluster rights

##### # All operations on all indices

admin:  
cluster: all  
indices:  
'\*': all

##### # monitoring cluster privileges

##### # All operations on all indices

power\_user:  
cluster: monitor  
indices:  
'\*': all

##### # Read-only operations on indices

user:  
indices:  
'\*': read

##### # Defines the required permissions for transport clients

transport\_client:  
cluster:  
- cluster:monitor/nodes/info  
#uncomment the following for sniffing  
#- cluster:monitor/state

##### # The required role for kibana 3 users

kibana3:  
cluster: cluster:monitor/nodes/info  
indices:  
'\*': indices:data/read/search, indices:data/read/get, indices:admin/get  
'kibana-int': indices:data/read/search, indices:data/read/get, indices:data/write/delete, indices:data/write/index, create\_index

##### # The required permissions for kibana 4 users.

kibana4:  
cluster:  
- cluster:monitor/nodes/info  
- cluster:monitor/health  
indices:  
'\*':  
- indices:admin/mappings/fields/get  
- indices:admin/validate/query  
- indices:data/read/search  
- indices:data/read/msearch  
- indices:admin/get  
'.kibana':  
- indices:admin/exists  
- indices:admin/mapping/put  
- indices:admin/mappings/fields/get  
- indices:admin/refresh  
- indices:admin/validate/query  
- indices:data/read/get  
- indices:data/read/mget  
- indices:data/read/search  
- indices:data/write/delete  
- indices:data/write/index  
- indices:data/write/update  
- indices:admin/create

##### # The required permissions for the kibana 4 server

kibana4\_server:  
cluster:  
- cluster:monitor/nodes/info  
- cluster:monitor/health  
indices:  
'.kibana':  
- indices:admin/exists  
- indices:admin/mapping/put  
- indices:admin/mappings/fields/get  
- indices:admin/refresh  
- indices:admin/validate/query  
- indices:data/read/get  
- indices:data/read/mget  
- indices:data/read/search  
- indices:data/write/delete  
- indices:data/write/index  
- indices:data/write/update

##### # The required role for logstash users

logstash:  
cluster: indices:admin/template/get, indices:admin/template/put  
indices:  
'logstash-\*': indices:data/write/bulk, indices:data/write/delete, indices:data/write/update, indices:data/read/search, indices:data/read/scroll, create\_index

##### # Marvel role, allowing all operations

##### # on the marvel indices

marvel\_user:  
cluster: cluster:monitor/nodes/info, cluster:admin/plugin/license/get  
indices:  
'.marvel-\*': all

##### # Marvel Agent users

marvel\_agent:  
cluster: indices:admin/template/get, indices:admin/template/put  
indices:  
'.marvel-\*': indices:data/write/bulk, create\_index

**users.yml:**

es\_admin:$2a$10$RbWXUQSEmsR1JbhmP4xCFudyMc1SvT.KXjz3rvc2ZzxJ2XW8v9sgW

**user\_roles.yml:**

admin:es\_admin

**Here is my Java Client Code:**

**public class Test{**

```
public static final Client client = getTransportClient("localhost", 9300);
public static String token = null;

public static Client getTransportClient(String host, int port) {

    Settings settings = ImmutableSettings.settingsBuilder().put("cluster.name", "elasticsearch").put("shield.user", "es_admin:anusha").build();
    token = basicAuthHeaderValue("es_admin", new SecuredString("anusha".toCharArray()));

    return new TransportClient(settings).addTransportAddress(new InetSocketTransportAddress(host, port));
}

    public static void getResponse(String index, String indextype) throws InvalidFormatException, Exception {
    SearchHits hits = null;
    SearchHit hit = null;

    SearchResponse response = client.prepareSearch(index).setTypes(indextype).putHeader("Authorization", token).get();

    hits = response.getHits();
    Iterator<SearchHit> hitsIte = hits.iterator();
    while (hitsIte.hasNext()) {
        hit = hitsIte.next();
        // jsonArray.add(hit.getSource());
        System.out.println(hit.getSourceAsString());
    }
}

```

**}**

---

<div class="post-metadata">

**Author:** ![Anusha](https://avatars.discourse-cdn.com/v4/letter/a/c5a1d2/32.png) [@Anusha](https://discuss.elastic.co/u/Anusha)\
**Post date:** [December 21, 2015, 7:02am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/15 "2015-12-21T07:02:58Z")

</div>

Hi David,

I hope this information supports you to trace the root cause..

---

<div class="post-metadata">

**Author:** ![Anusha](https://avatars.discourse-cdn.com/v4/letter/a/c5a1d2/32.png) [@Anusha](https://discuss.elastic.co/u/Anusha)\
**Post date:** [December 21, 2015, 8:48am UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/16 "2015-12-21T08:48:34Z")

</div>

Thanks David,

Got the response,

> [@Anusha](#):
>
> Settings settings = ImmutableSettings.settingsBuilder().put("cluster.name", "elasticsearch").put("shield.user", "es\_admin:anusha").build();  
> token = basicAuthHeaderValue("es\_admin", new SecuredString("anusha".toCharArray()));
> 
> ```
> return new TransportClient(settings).addTransportAddress(new InetSocketTransportAddress(host, port));
> 
> ```

Here token need to set after client....

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:29pm UTC](https://discuss.elastic.co/t/java-api-for-shield-is-not-working/37473/17 "2017-07-05T23:29:38Z")

</div>


