# Shield user across multiple nodes

**URL:** <https://discuss.elastic.co/t/shield-user-across-multiple-nodes/43555>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 4, 2016, 9:13pm UTC](https://discuss.elastic.co/t/shield-user-across-multiple-nodes/43555 "2016-03-04T21:13:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![boreal](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@boreal](https://discuss.elastic.co/u/boreal)\
**Post date:** [March 4, 2016, 9:13pm UTC](https://discuss.elastic.co/t/shield-user-across-multiple-nodes/43555/1 "2016-03-04T21:13:54Z")

</div>

Hi,  
What is the instruction for installing shields on multi-node cluster?

Long story short, I have a node 1 with shield with username/password, then I am trying to add another node. Shield configuration is exactly the same. Am I supposed to set up same username/password on node 2? I did, and not sure if it's caused by that but I am getting this exception in the log.

> [2016-03-04 14:54:40,144][INFO][rest.suppressed] /\_nodes Params: {}  
> ElasticsearchSecurityException[missing authentication token for REST request [/\_nodes]]  
> at org.elasticsearch.shield.support.Exceptions.authenticationError(Exceptions.java:39)

Thanks a lot!  
B

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 4, 2016, 9:26pm UTC](https://discuss.elastic.co/t/shield-user-across-multiple-nodes/43555/2 "2016-03-04T21:26:08Z")

</div>

> [@boreal](#):
>
> What is the instruction for installing shields on multi-node cluster?

It's the same for a one node cluster a multiple node cluster. Just make sure the plugin is installed before trying to join nodes, and roll the same config out to all nodes.

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [March 4, 2016, 9:28pm UTC](https://discuss.elastic.co/t/shield-user-across-multiple-nodes/43555/3 "2016-03-04T21:28:41Z")

</div>

> [@warkolm](#):
>
> and roll the same config out to all nodes

This means you need to have the same users, roles, and user role mapping files on all nodes in the cluster. This isn't optional - you're not secure unless these files are in sync.

We're adding API-based user configuration to a near-term version, so the user/role config piece will be getting a lot easier soon!

---

<div class="post-metadata">

**Author:** ![boreal](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@boreal](https://discuss.elastic.co/u/boreal)\
**Post date:** [March 4, 2016, 9:31pm UTC](https://discuss.elastic.co/t/shield-user-across-multiple-nodes/43555/4 "2016-03-04T21:31:21Z")

</div>

Thanks Mark and Steve for a quick response!

So once I installed Shield on new node, I would run "bin/shield/esusers useradd myUser..." and set up identical username and password, is that correct?

I am also getting this exception as well. Not sure, if it's anything to do with shield though..

> [RemoteTransportException[[node-2][myIP:9300][indices:data/write/bulk[s][r]]]; nested: ElasticsearchSecurityException[action [indices:data/write/bulk[s][r]] is unauthorized for user [\_\_marvel\_user]]; ]  
> RemoteTransportException[[node-2][myIP:9300][indices:data/write/bulk[s][r]]]; nested: ElasticsearchSecurityException[action [indices:data/write/bulk[s][r]] is unauthorized for user [\_\_marvel\_user]];

Thanks!

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [March 9, 2016, 3:14pm UTC](https://discuss.elastic.co/t/shield-user-across-multiple-nodes/43555/5 "2016-03-09T15:14:01Z")

</div>

> [@boreal](#):
>
> So once I installed Shield on new node, I would run "bin/shield/esusers useradd myUser..." and set up identical username and password, is that correct?

That is correct or you can copy the files (`users`, `users_roles`, and `roles.yml`) from the existing node to the new node.

> [@boreal](#):
>
> I am also getting this exception as well. Not sure, if it's anything to do with shield though..
> 
> [RemoteTransportException[[node-2][myIP:9300][indices:data/write/bulk[s][r]]]; nested: ElasticsearchSecurityException[action [indices:data/write/bulk[s][r]] is unauthorized for user [\_marveluser]]; ]RemoteTransportException[[node-2][myIP:9300][indices:data/write/bulk[s][r]]]; nested: ElasticsearchSecurityException[action [indices:data/write/bulk[s][r]] is unauthorized for user [\_marveluser]];

Do you have any special marvel configuration in your elasticsearch.yml?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/shield-user-across-multiple-nodes/43555/6 "2017-07-06T13:46:15Z")

</div>


