# PKI authentication for "elastic" user

**URL:** <https://discuss.elastic.co/t/pki-authentication-for-elastic-user/178960>\
**Category:** Elasticsearch\
**Created:** [April 29, 2019, 4:09pm UTC](https://discuss.elastic.co/t/pki-authentication-for-elastic-user/178960 "2019-04-29T16:09:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tiuser4567](https://avatars.discourse-cdn.com/v4/letter/t/8dc957/32.png) [@tiuser4567](https://discuss.elastic.co/u/tiuser4567)\
**Post date:** [April 29, 2019, 4:09pm UTC](https://discuss.elastic.co/t/pki-authentication-for-elastic-user/178960/1 "2019-04-29T16:09:43Z")

</div>

Hello,

We are trying to authenticate using PKI with elastic with native realm as the authorization realm.

xpack.security.authc:  
realms:  
native:  
type: native  
order: 0  
pki:  
type: pki  
order: 1  
authorization\_realms: native

The setup is working with the users we created in the native realm (via /\_xpack/security/user).

However we are unable to login using the default elastic user with PKI.  
Error in the elastic server is  
"Authentication to realm pki failed - the principal [elastic] was authenticated, but no user could be found in realms [native/native]"

I'm not sure if it is not considered to be in the native realm even though the elastic superuser is accessible in /\_xpack/security/user/elastic?  
If not native realm, what realm is the elastic user in? and can it be used in the authorization\_realms?

Thanks

---

<div class="post-metadata">

**Author:** ![tiuser4567](https://avatars.discourse-cdn.com/v4/letter/t/8dc957/32.png) [@tiuser4567](https://discuss.elastic.co/u/tiuser4567)\
**Post date:** [April 29, 2019, 4:11pm UTC](https://discuss.elastic.co/t/pki-authentication-for-elastic-user/178960/2 "2019-04-29T16:11:02Z")

</div>

Sorry, found the answer, it is using the "reserved" realm.

Didn't find "reserved" realm in the documentation "[https://www.elastic.co/guide/en/elastic-stack-overview/7.0/setting-up-authentication.html](https://www.elastic.co/guide/en/elastic-stack-overview/7.0/setting-up-authentication.html)"

but only through another post [Authentication of [elastic] was terminated by realm [reserved]](https://discuss.elastic.co/t/authentication-of-elastic-was-terminated-by-realm-reserved/112206)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2019, 4:11pm UTC](https://discuss.elastic.co/t/pki-authentication-for-elastic-user/178960/3 "2019-05-27T16:11:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
