# Securing apis

**URL:** <https://discuss.elastic.co/t/securing-apis/21132>\
**Category:** Elasticsearch\
**Created:** [December 8, 2014, 6:04am UTC](https://discuss.elastic.co/t/securing-apis/21132 "2014-12-08T06:04:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cheten\_Dev](https://avatars.discourse-cdn.com/v4/letter/c/8e8cbc/32.png) [@Cheten\_Dev](https://discuss.elastic.co/u/Cheten_Dev)\
**Post date:** [December 8, 2014, 6:04am UTC](https://discuss.elastic.co/t/securing-apis/21132/1 "2014-12-08T06:04:52Z")

</div>

Hi,

Is there any way i can secure the Apis ?  
I want to restrict the rights so that nobody other than administrator is  
able to delete or update indexes

Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a4b622b8-e226-4450-b3b1-ae43439cf283%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a4b622b8-e226-4450-b3b1-ae43439cf283%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Jason\_Zhang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason_zhang/32/745_2.png) [@Jason\_Zhang](https://discuss.elastic.co/u/Jason_Zhang)\
**Post date:** [December 8, 2014, 6:29am UTC](https://discuss.elastic.co/t/securing-apis/21132/2 "2014-12-08T06:29:00Z")

</div>

Hi,

elasticsearch-jetty plugin can help add authentication

> **[GitHub - sonian/elasticsearch-jetty](https://github.com/sonian/elasticsearch-jetty)**
>
> Contribute to sonian/elasticsearch-jetty development by creating an account on GitHub.

sample config here:

> <https://github.com/sonian/elasticsearch-jetty/blob/master/config/jetty-restrict-writes.xml>

On Sun 07.07.14 22:04, Chetan Dev wrote:

> Hi,
> 
> Is there any way i can secure the Apis ?  
> I want to restrict the rights so that nobody other than administrator is  
> able to delete or update indexes
> 
> Thanks
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a4b622b8-e226-4450-b3b1-ae43439cf283%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a4b622b8-e226-4450-b3b1-ae43439cf283%40googlegroups.com).  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/20141208062900.GA29681%40Lain.routerbf573c.com](https://groups.google.com/d/msgid/elasticsearch/20141208062900.GA29681%40Lain.routerbf573c.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![elvarb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elvarb/32/44840_2.png) [@elvarb](https://discuss.elastic.co/u/elvarb)\
**Post date:** [December 8, 2014, 1:52pm UTC](https://discuss.elastic.co/t/securing-apis/21132/3 "2014-12-08T13:52:02Z")

</div>

Front it with a reverse proxy, limit access to the DELETE method

On Monday, December 8, 2014 6:04:52 AM UTC, Chetan Dev wrote:

> Hi,
> 
> Is there any way i can secure the Apis ?  
> I want to restrict the rights so that nobody other than administrator is  
> able to delete or update indexes
> 
> Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/5634b9b5-8d41-48fa-8951-580e5e26cbf2%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/5634b9b5-8d41-48fa-8951-580e5e26cbf2%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Cheten\_Dev](https://avatars.discourse-cdn.com/v4/letter/c/8e8cbc/32.png) [@Cheten\_Dev](https://discuss.elastic.co/u/Cheten_Dev)\
**Post date:** [December 11, 2014, 6:06am UTC](https://discuss.elastic.co/t/securing-apis/21132/4 "2014-12-11T06:06:09Z")

</div>

Hi,

I am not able to set up nginx on windows can you help me ?

On Monday, December 8, 2014 7:22:02 PM UTC+5:30, Elvar Böðvarsson wrote:

> Front it with a reverse proxy, limit access to the DELETE method
> 
> On Monday, December 8, 2014 6:04:52 AM UTC, Chetan Dev wrote:
> 
> > Hi,
> > 
> > Is there any way i can secure the Apis ?  
> > I want to restrict the rights so that nobody other than administrator  
> > is able to delete or update indexes
> > 
> > Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/3b83f289-58ee-4892-8950-ebd7571cce69%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3b83f289-58ee-4892-8950-ebd7571cce69%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![elvarb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elvarb/32/44840_2.png) [@elvarb](https://discuss.elastic.co/u/elvarb)\
**Post date:** [December 11, 2014, 7:03pm UTC](https://discuss.elastic.co/t/securing-apis/21132/5 "2014-12-11T19:03:29Z")

</div>

Setting up nginx on windows is actually very easy since they provide a  
native binary.

But, take a look at IIS ARR to do reverse proxy for elasticsearch, can do  
kerberos authentication, give access based on active directory and limit  
what methods are available.

On Thursday, December 11, 2014 6:06:09 AM UTC, Chetan Dev wrote:

> Hi,
> 
> I am not able to set up nginx on windows can you help me ?
> 
> On Monday, December 8, 2014 7:22:02 PM UTC+5:30, Elvar Böðvarsson wrote:
> 
> > Front it with a reverse proxy, limit access to the DELETE method
> > 
> > On Monday, December 8, 2014 6:04:52 AM UTC, Chetan Dev wrote:
> > 
> > > Hi,
> > > 
> > > Is there any way i can secure the Apis ?  
> > > I want to restrict the rights so that nobody other than administrator  
> > > is able to delete or update indexes
> > > 
> > > Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b892f4f7-182d-4e10-a7c3-38d95d30d6b1%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b892f4f7-182d-4e10-a7c3-38d95d30d6b1%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:44am UTC](https://discuss.elastic.co/t/securing-apis/21132/6 "2017-07-06T00:44:06Z")

</div>


