# Security Exception when Running Sample Security Plugin

**URL:** <https://discuss.elastic.co/t/security-exception-when-running-sample-security-plugin/214671>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 10, 2020, 9:15pm UTC](https://discuss.elastic.co/t/security-exception-when-running-sample-security-plugin/214671 "2020-01-10T21:15:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![YanbangLiuUiPath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanbangliuuipath/32/60975_2.png) [@YanbangLiuUiPath](https://discuss.elastic.co/u/YanbangLiuUiPath)\
**Post date:** [January 10, 2020, 9:15pm UTC](https://discuss.elastic.co/t/security-exception-when-running-sample-security-plugin/214671/1 "2020-01-10T21:15:01Z")

</div>

I have followed the steps from [This post](https://www.elastic.co/blog/how-to-develop-your-own-security-extensions-and-custom-realms-for-elasticsearch)

But at the step to authenticate using this command:  
curl "localhost:9200/\_xpack/security/\_authenticate"   
-H "x-web-store-claims: $ClaimJson" -H "x-web-store-sig: $ClaimSig"

I get the following error:  
{"error":{"root\_cause":[{"type":"security\_exception","reason":"missing authentication credentials for REST request [/\_xpack/security/\_authenticate]","header":{"WWW-Authenticate":"Basic realm="security" charset="UTF-8""}}],"type":"security\_exception","reason":"missing authentication credentials for REST request [/\_xpack/security/\_authenticate]","header":{"WWW-Authenticate":"Basic realm="security" charset="UTF-8""}},"status":401}

It looks like the elasticsearch instance is not using the custom realm, but I do not know the reason. I have followed every steps in the tutorial (to my best knowledge), please let me know if I have missed anything.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 11, 2020, 12:36pm UTC](https://discuss.elastic.co/t/security-exception-when-running-sample-security-plugin/214671/2 "2020-01-11T12:36:34Z")

</div>

> [@YanbangLiuUiPath](#):
>
> please let me know if I have missed anything.

Since you haven't provided any details about the steps you took, it is impossible for us to offer any specific advice.

---

<div class="post-metadata">

**Author:** ![YanbangLiuUiPath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanbangliuuipath/32/60975_2.png) [@YanbangLiuUiPath](https://discuss.elastic.co/u/YanbangLiuUiPath)\
**Post date:** [January 13, 2020, 5:47pm UTC](https://discuss.elastic.co/t/security-exception-when-running-sample-security-plugin/214671/3 "2020-01-13T17:47:17Z")

</div>

The steps are all described in the blog post I've linked.

I'll also describe what I did below:

1. Build the plugin with mvn package, which generates a .zip file
2. start up elasticsearch using docker-compose up
3. copy the .zip file into the container
4. install the plugin using bin/elasticsearch-plugin command
5. replace the elasticsearch.yml file with the settings described in the blog post
6. restart the container
7. try the curl command in my original post

Here are my docker-compose.yml and elasticsearch.yml:

docker-compose.yml:  
version: '3'

services:  
elasticsearch:  
image: elasticsearch\_backup:latest  
container\_name: elasticsearch\_secured  
#volumes:  
#- ./config/elasticsearch.yml:/usr/share/elasticsearch/config/elasticsearch.yml  
environment:  
- discovery.type=single-node  
- xpack.security.enabled=true  
ports:  
- 9200:9200

kibana:  
image: [docker.elastic.co/kibana/kibana:7.5.0](http://docker.elastic.co/kibana/kibana:7.5.0)  
container\_name: kibana\_secured  
environment:  
ELASTICSEARCH\_USERNAME: elastic  
ELASTICSEARCH\_PASSWORD: UzpQs3XkdoLrv31sycoC  
ports:  
- 5601:5601

elasticsearch.yml:  
cluster.name: "docker-cluster"  
network.host: 0.0.0.0  
xpack.security.authc.realms:  
file.file:  
order: 0

native.native:  
order: 1

webstore.webstore:  
certificate: webstore/webstore.crt

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 14, 2020, 10:45am UTC](https://discuss.elastic.co/t/security-exception-when-running-sample-security-plugin/214671/4 "2020-01-14T10:45:15Z")

</div>

I know the steps in the blog post - I wrote it.  
I also know that those steps work, which is why you need to describe what you did so that we can work out where you might have deviated from the steps described in that blog.

I think the most likely problem here is that you're trying to do this in docker, and mess with the yml file inside the container. My guess is that the yml you are editing isn't actually used by the elasticsearch process in the container.

The other issue you have is that plugin code in the blog post generates a plugin for Elasticsearch 6.3, it looks like you are running Elasticsearch 7.5. How did you update the code for the newer version?

---

<div class="post-metadata">

**Author:** ![YanbangLiuUiPath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanbangliuuipath/32/60975_2.png) [@YanbangLiuUiPath](https://discuss.elastic.co/u/YanbangLiuUiPath)\
**Post date:** [January 17, 2020, 5:28pm UTC](https://discuss.elastic.co/t/security-exception-when-running-sample-security-plugin/214671/5 "2020-01-17T17:28:50Z")

</div>

The problems you mentioned had all been addressed before I asked the question. I tried the ES setup on Windows as well and it did not work either. As of the plugin code, I referred to the breaking changes page of 7.0 and updated the code accordingly.  
Could you please provide your docker-compose.yml (if you used one) as well as the elasticsearch.yml?  
Also, just making sure, does this security plugin work on free version?  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2020, 5:28pm UTC](https://discuss.elastic.co/t/security-exception-when-running-sample-security-plugin/214671/6 "2020-02-14T17:28:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
