# Setup Authentication and Authorization WITHOUT X-Pack?

**URL:** <https://discuss.elastic.co/t/setup-authentication-and-authorization-without-x-pack/123458>\
**Category:** Elasticsearch\
**Created:** [March 11, 2018, 9:27pm UTC](https://discuss.elastic.co/t/setup-authentication-and-authorization-without-x-pack/123458 "2018-03-11T21:27:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![titan1978](https://avatars.discourse-cdn.com/v4/letter/t/c37758/32.png) [@titan1978](https://discuss.elastic.co/u/titan1978)\
**Post date:** [March 11, 2018, 9:27pm UTC](https://discuss.elastic.co/t/setup-authentication-and-authorization-without-x-pack/123458/1 "2018-03-11T21:27:52Z")

</div>

Am part of a small enterprise and unfortuntely we cannot afford the licensing model to leverage X-PACK. In light of this, I was wondering what is considered a robust open source authentication and authorization setup to allow controlled access to our EC2 Based Elastic Instances? Here is the needs I want to solve for:

- Allow Support for SSO based authentication for my small enterprise's employees
- Support for Authorization and role based access (ie allow admin rights for administration and read-only rights to read data from Elastic Stack per user basis?)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 12, 2018, 3:49am UTC](https://discuss.elastic.co/t/setup-authentication-and-authorization-without-x-pack/123458/2 "2018-03-12T03:49:35Z")

</div>

I guess you can add a ngnix on top of elasticsearch and try to protect some urls with it.

But be aware that some APIS will probably need to be blocked all together like `_bulk` and `_msearch` and `_mget`.  
Also any usage of index wildcard may be?

At the very least, do not expose elasticsearch on internet but use an application layer for which elasticsearch access is granted.

BTW did you engage with the sales team about your project? If not, check with them as many options are available and one might fit your budget.  
Also consider [cloud.elastic.co](http://cloud.elastic.co).

---

<div class="post-metadata">

**Author:** ![titan1978](https://avatars.discourse-cdn.com/v4/letter/t/c37758/32.png) [@titan1978](https://discuss.elastic.co/u/titan1978)\
**Post date:** [March 12, 2018, 4:04am UTC](https://discuss.elastic.co/t/setup-authentication-and-authorization-without-x-pack/123458/3 "2018-03-12T04:04:16Z")

</div>

@dadoonet thank you.

1. So by adding an NGINX layer in front of ElasticSearch - will authentication automatically bubble up to Kibana Layer?
2. Can I support Authorization in addition to Authentication and allow certain roles to access certain types of HTTP Methods (ie allow Normal Users only access to GET whilst Admin Users to GET/PUT/POST/DELETE?)

This is my revised architecture in light of what you have suggested:

Route53(KB) \> ElasticLoadBalancer (KB) \> KB EC2 \>Route53(ELASTICSEARCH)\> **(NGINX)**\> ElasticLoadBalancer(ELASTICSEARCH)\>ELASTIC EC2

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 12, 2018, 6:28am UTC](https://discuss.elastic.co/t/setup-authentication-and-authorization-without-x-pack/123458/4 "2018-03-12T06:28:10Z")

</div>

1. No I don't think so.
2. Probably. That's a Ngnix question IMO.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2018, 6:28am UTC](https://discuss.elastic.co/t/setup-authentication-and-authorization-without-x-pack/123458/5 "2018-04-09T06:28:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
