# Security\_exception with curl

**URL:** <https://discuss.elastic.co/t/security-exception-with-curl/85965>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 16, 2017, 3:21pm UTC](https://discuss.elastic.co/t/security-exception-with-curl/85965 "2017-05-16T15:21:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![zeenon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zeenon/32/24883_2.png) [@zeenon](https://discuss.elastic.co/u/zeenon)\
**Post date:** [May 16, 2017, 3:21pm UTC](https://discuss.elastic.co/t/security-exception-with-curl/85965/1 "2017-05-16T15:21:53Z")

</div>

Hi, my first steps with shield 2.3 and some troubles with this plugin.

I create an user superadmin3 and all seems OK

```
# ./esusers useradd superadmin3 -r admin --path.conf=/etc/elasticsearch/
Enter new password:
Retype new password:

 # ./esusers list
kibana4-server : kibana4_server
superadmin : admin
superadmin3 : admin
es_admin : admin

```

but a basic curl fail:

```
# curl -u superadmin3:elastic -XGET 'http://localhost:9200/'
{"error":{"root_cause":[{"type":"security_exception","reason":"unable to authenticate user [superadmin3] for REST request [/]","header":{"WWW-Authenticate":"Basic realm=\"shield\""}}],"type":"security_exception","reason":"unable to authenticate user [superadmin3] for REST request [/]","header":{"WWW-Authenticate":"Basic realm=\"shield\""}},"status":401}

```

My configuration for realm:

```
# tail -6 /etc/elasticsearch/elasticsearch.yml
shield:
  authc:
    realms:
      native1:
        type: native
        order: 0

```

What's wrong ?  
thanks for your tips

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 19, 2017, 6:05am UTC](https://discuss.elastic.co/t/security-exception-with-curl/85965/2 "2017-05-19T06:05:37Z")

</div>

```auto
./esusers useradd superadmin3 -r admin --path.conf=/etc/elasticsearch/

```

The `esusers` command manages the [shield file realm](https://www.elastic.co/guide/en/shield/2.3/file-realm.html).

```auto
    realms:
      native1:
        type: native

```

You have configured your server to have a [native realm](https://www.elastic.co/guide/en/shield/2.3/native-realm.html), file based users do not work in the native realm.

You either need to add the _file realm_ to your config file, or use the native [users API](https://www.elastic.co/guide/en/shield/2.3/shield-rest.html#shield-users-rest) to manage your users.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2017, 6:05am UTC](https://discuss.elastic.co/t/security-exception-with-curl/85965/3 "2017-06-16T06:05:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
