Segurity Problem using X-pack with 5.0.1

(oscar) #1


Recently I start to configure my EL Cluster and Kibana aganist a AD. Im using 5.0.1

I preferred to start configuring my cluster aganist and simple LDAP. I use for this OpenDS.

The main configuration in elasticsearch.yml is the next:
    type: ldap
    order: 0
    url: "ldap://"
      - "cn={0},ou=usuarios,dc=XXXXX,dc=com"
      base_dn: "ou=roles,dc=XXXXX,dc=com"
      role_mapping: "/XXXXX/cluster-elk/EL-node 1_MD-5.0.1/config/x-pack/role_mapping.yml"
    unmapped_groups_as_roles: false

and my role-mapping.xml is like this;

  - "cn=role_app1,ou=aplicacion,ou=roles,dc=XXXX,dc=com"

All is working good but my problem is:

1.- I log with my user asign to role_app. Any problem
2.- I logout of kibana.
3.- In openDS, I change the password of my user.
4.- I try to login in kibana with the old password, and i can login....

Worst of all was that if I stop my openDS.... i can enter using old password....

If I have not made any configuration errors, I suspect that Xpack is internally saving the user and password and does not validate it against OpenDS anymore until a different user or password is entered.

This is normal? Is there a way to force by configuration that you always have to validate the user and password against the external security provider?


(Jay Modi) #2

Hi @olorasde,

The username and a hash of the password is being cached by x-pack for performance reasons. This can be disabled on a per realm basis. If you would like to disable it, in your ldap1 realm settings, add cache.ttl: -1. Details about the cache settings:

(Steve Kearns) #3

One thing to keep in mind is that if you disable this cache, as @jaymode describes, every request to Elasticsearch will make a request to your LDAP server to validate the user information, and this will slow your response times and put a lot of load on the LDAP server.

(oscar) #4

Thx for information Jay and Steve.

I assume that it is not currently possible to only force authentication in the login process, no?

Using this configuration, in my elasticsearch log console has begun to appear this exceptions, any ideas?

[2016-12-07T15:31:36,713][ERROR][o.e.x.m.c.c.ClusterStatsCollector] [node-MD-1] collector [cluster-stats-collector] - failed collecting data
        at ~[?:?]
        at ~[?:?]
        at ~[?:?]
        at$usageStats$0( ~[?:?]
        at$$Lambda$1474/187280844.apply(Unknown Source) ~[?:?]
        at java.util.HashMap.compute( ~[?:1.8.0_45]
        at ~[?:?]
        at ~[?:?]
        at ~[?:?]
        at org.elasticsearch.xpack.action.TransportXPackUsageAction$$Lambda$1473/1101385431.apply(Unknown Source) ~[?:?]
        at$3$1.accept( ~[?:1.8.0_45]
        at java.util.Iterator.forEachRemaining( ~[?:1.8.0_45]
        at java.util.Spliterators$IteratorSpliterator.forEachRemaining( ~[?:1.8.0_45]
        at ~[?:1.8.0_45]
        at ~[?:1.8.0_45]
        at$ReduceOp.evaluateSequential( ~[?:1.8.0_45]
        at ~[?:1.8.0_45]
        at ~[?:1.8.0_45]
        at org.elasticsearch.xpack.action.TransportXPackUsageAction.masterOperation( ~[?:?]
        at org.elasticsearch.xpack.action.TransportXPackUsageAction.masterOperation( ~[?:?]
        at ~[elasticsearch-5.0.1.jar:5.0.1]
        at$AsyncSingleAction$3.doRun( ~[elasticsearch-5.0.1.jar:5.0.1]
        at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingAbstractRunnable.doRun( ~[elasticsearch-5.0.1.jar:5.0.1]
        at ~[elasticsearch-5.0.1.jar:5.0.1]
        at java.util.concurrent.ThreadPoolExecutor.runWorker( ~[?:1.8.0_45]
        at java.util.concurrent.ThreadPoolExecutor$ ~[?:1.8.0_45]
        at [?:1.8.0_45]


(system) #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.