# Type HTTP with Auth Digest

**URL:** <https://discuss.elastic.co/t/type-http-with-auth-digest/216482>\
**Category:** Beats\
**Tags:** heartbeat\
**Created:** [January 24, 2020, 7:45pm UTC](https://discuss.elastic.co/t/type-http-with-auth-digest/216482 "2020-01-24T19:45:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![holiveira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/holiveira/32/100472_2.png) [@holiveira](https://discuss.elastic.co/u/holiveira)\
**Post date:** [January 24, 2020, 7:45pm UTC](https://discuss.elastic.co/t/type-http-with-auth-digest/216482/1 "2020-01-24T19:45:12Z")

</div>

Any way to monitor an http type that has digest authentication?

I've tried using user policies and password, but without success.

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [January 24, 2020, 8:05pm UTC](https://discuss.elastic.co/t/type-http-with-auth-digest/216482/2 "2020-01-24T20:05:20Z")

</div>

It looks like go's HTTP client doesn't support digest, but [there is a proposal here](https://github.com/golang/go/issues/29409). So, we'd have to do a custom implementation.

I should note that HTTP digest is an old insecure standard, using a long deprecated hashing algorithm (MD5), is vulnerable to MITM attacks, and provides few of the protections TLS/SSL provides. I assume you're testing against software that only provides digest auth, but if it does provide another form (say, basic over TLS), that would work today.

I've opened a github issue to track this here: [https://github.com/elastic/beats/issues/15837](https://github.com/elastic/beats/issues/15837)

We would accept a patch for it, but given that this is the fist time we've seen a request for it, it probably won't be something we prioritize or build anytime soon given that it is no longer a best practice and is not something in wide use.

---

<div class="post-metadata">

**Author:** ![holiveira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/holiveira/32/100472_2.png) [@holiveira](https://discuss.elastic.co/u/holiveira)\
**Post date:** [January 24, 2020, 8:12pm UTC](https://discuss.elastic.co/t/type-http-with-auth-digest/216482/3 "2020-01-24T20:12:25Z")

</div>

Thanks for this information, monitoring is on a legacy system, and there is no possibility to change to another type of authentication.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2020, 8:23pm UTC](https://discuss.elastic.co/t/type-http-with-auth-digest/216482/4 "2020-02-21T20:23:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
