# Provide Authentication In Head

**URL:** <https://discuss.elastic.co/t/provide-authentication-in-head/8861>\
**Category:** Elasticsearch\
**Created:** [August 27, 2012, 6:06pm UTC](https://discuss.elastic.co/t/provide-authentication-in-head/8861 "2012-08-27T18:06:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sumit\_Guptaa](https://avatars.discourse-cdn.com/v4/letter/s/e8c25b/32.png) [@Sumit\_Guptaa](https://discuss.elastic.co/u/Sumit_Guptaa)\
**Post date:** [August 27, 2012, 6:06pm UTC](https://discuss.elastic.co/t/provide-authentication-in-head/8861/1 "2012-08-27T18:06:42Z")

</div>

Hi All,

Can Anybody tell me how we can provide authentication in ES head....so nobody wants to delete my index or create an index etc....is it possible in Elasticsearch.

Thanx

Regards,  
Sumit Gupta

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [August 27, 2012, 6:27pm UTC](https://discuss.elastic.co/t/provide-authentication-in-head/8861/2 "2012-08-27T18:27:29Z")

</div>

There are a couple of options:

One is the jetty plugin: [GitHub - sonian/elasticsearch-jetty](https://github.com/sonian/elasticsearch-jetty)

The other is to lock things down at the server level. My load  
balancer/firewalls disallows any REST requests that are not GETs. Full  
REST interface is enabled while on the same machine via localhost  
only.

--  
Ivan

On Mon, Aug 27, 2012 at 11:06 AM, Sumit Guptaa  
[sumit.gupta.ngi@gmail.com](mailto:sumit.gupta.ngi@gmail.com) wrote:

> Hi All,
> 
> Can Anybody tell me how we can provide authentication in ES head....so  
> nobody wants to delete my index or create an index etc....is it possible in  
> Elasticsearch.
> 
> Thanx
> 
> Regards,  
> Sumit Gupta
> 
> --  
> View this message in context: [http://elasticsearch-users.115913.n3.nabble.com/Provide-Authentication-In-Head-tp4022173.html](http://elasticsearch-users.115913.n3.nabble.com/Provide-Authentication-In-Head-tp4022173.html)  
> Sent from the Elasticsearch Users mailing list archive at [Nabble.com](http://Nabble.com).
> 
> --

--

---

<div class="post-metadata">

**Author:** ![andreas\_chatzakis](https://avatars.discourse-cdn.com/v4/letter/a/58956e/32.png) [@andreas\_chatzakis](https://discuss.elastic.co/u/andreas_chatzakis)\
**Post date:** [August 28, 2012, 8:13am UTC](https://discuss.elastic.co/t/provide-authentication-in-head/8861/3 "2012-08-28T08:13:00Z")

</div>

Another option is to use e.g. apache web server as a reverse proxy and  
enforce authentication via mod\_auth.  
Then you would setup the firewall on the Elasticsearch instance(s) to only  
allow access to elasticsearch port from the web server.

On Monday, August 27, 2012 9:27:29 PM UTC+3, Ivan Brusic wrote:

> There are a couple of options:
> 
> One is the jetty plugin: [GitHub - sonian/elasticsearch-jetty](https://github.com/sonian/elasticsearch-jetty)
> 
> The other is to lock things down at the server level. My load  
> balancer/firewalls disallows any REST requests that are not GETs. Full  
> REST interface is enabled while on the same machine via localhost  
> only.
> 
> --  
> Ivan
> 
> On Mon, Aug 27, 2012 at 11:06 AM, Sumit Guptaa  
> \<[sumit.g...@gmail.com](mailto:sumit.g...@gmail.com) \<javascript:\>\> wrote:
> 
> > Hi All,
> > 
> > Can Anybody tell me how we can provide authentication in ES head....so  
> > nobody wants to delete my index or create an index etc....is it possible  
> > in  
> > Elasticsearch.
> > 
> > Thanx
> > 
> > Regards,  
> > Sumit Gupta
> > 
> > --  
> > View this message in context:  
> > [http://elasticsearch-users.115913.n3.nabble.com/Provide-Authentication-In-Head-tp4022173.html](http://elasticsearch-users.115913.n3.nabble.com/Provide-Authentication-In-Head-tp4022173.html)  
> > Sent from the Elasticsearch Users mailing list archive at [Nabble.com](http://Nabble.com).
> > 
> > --

--

---

<div class="post-metadata">

**Author:** ![Hendrik](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@Hendrik](https://discuss.elastic.co/u/Hendrik)\
**Post date:** [December 7, 2013, 10:50pm UTC](https://discuss.elastic.co/t/provide-authentication-in-head/8861/4 "2013-12-07T22:50:54Z")

</div>

Maybe this is interesting for you

> **[GitHub - salyh/elasticsearch-security-plugin: Kerberos, LDAP, Active...](https://github.com/salyh/elasticsearch-security-plugin)**
>
> Kerberos, LDAP, Active Directory, PKI/SSL/TLS and host/ip based ACL coarse-grained and document level security for elasticsearch (Authentication, Authorization, Auth, Spnego, ACL, Mutual authentica...

Am Dienstag, 28. August 2012 10:13:00 UTC+2 schrieb andreas.chatzakis:

> Another option is to use e.g. apache web server as a reverse proxy and  
> enforce authentication via mod\_auth.  
> Then you would setup the firewall on the Elasticsearch instance(s) to  
> only allow access to elasticsearch port from the web server.
> 
> On Monday, August 27, 2012 9:27:29 PM UTC+3, Ivan Brusic wrote:
> 
> > There are a couple of options:
> > 
> > One is the jetty plugin: [GitHub - sonian/elasticsearch-jetty](https://github.com/sonian/elasticsearch-jetty)
> > 
> > The other is to lock things down at the server level. My load  
> > balancer/firewalls disallows any REST requests that are not GETs. Full  
> > REST interface is enabled while on the same machine via localhost  
> > only.
> > 
> > --  
> > Ivan
> > 
> > On Mon, Aug 27, 2012 at 11:06 AM, Sumit Guptaa  
> > [sumit.g...@gmail.com](mailto:sumit.g...@gmail.com) wrote:
> > 
> > > Hi All,
> > > 
> > > Can Anybody tell me how we can provide authentication in ES head....so  
> > > nobody wants to delete my index or create an index etc....is it  
> > > possible in  
> > > Elasticsearch.
> > > 
> > > Thanx
> > > 
> > > Regards,  
> > > Sumit Gupta
> > > 
> > > --  
> > > View this message in context:  
> > > [http://elasticsearch-users.115913.n3.nabble.com/Provide-Authentication-In-Head-tp4022173.html](http://elasticsearch-users.115913.n3.nabble.com/Provide-Authentication-In-Head-tp4022173.html)  
> > > Sent from the Elasticsearch Users mailing list archive at [Nabble.com](http://Nabble.com).
> > > 
> > > --

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/85d2c60f-78af-43bb-b88d-59d44b37eb8a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/85d2c60f-78af-43bb-b88d-59d44b37eb8a%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:02am UTC](https://discuss.elastic.co/t/provide-authentication-in-head/8861/5 "2017-07-06T02:02:42Z")

</div>


