# Upgrading to Elasticsearch 6.5.4 got Java AccessControlException: access denied for Elasticsearch.yml

**URL:** <https://discuss.elastic.co/t/upgrading-to-elasticsearch-6-5-4-got-java-accesscontrolexception-access-denied-for-elasticsearch-yml/164552>\
**Category:** Elasticsearch\
**Created:** [January 16, 2019, 11:18pm UTC](https://discuss.elastic.co/t/upgrading-to-elasticsearch-6-5-4-got-java-accesscontrolexception-access-denied-for-elasticsearch-yml/164552 "2019-01-16T23:18:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jqiu97](https://avatars.discourse-cdn.com/v4/letter/j/e19b73/32.png) [@jqiu97](https://discuss.elastic.co/u/jqiu97)\
**Post date:** [January 16, 2019, 11:18pm UTC](https://discuss.elastic.co/t/upgrading-to-elasticsearch-6-5-4-got-java-accesscontrolexception-access-denied-for-elasticsearch-yml/164552/1 "2019-01-16T23:18:08Z")

</div>

We are using Elasticsearch 6.1.2 now and are trying to upgrade to latest version Elasticsearch 6.5.4. When I start the new version of Elasticsearch on the same machine that we ran 6.1.2 before, I got  
Caused by: java.security.AccessControlException: access denied ("java.io.FilePermission" "/home/jqiu/search/elasticsearch-6.5.4/config/elasticsearch.yml" "read")

Does anyone know what extra steps I need in order to upgrade to 6.5.4? Do I need to add some java.policy file?

Thanks,

Jay

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 17, 2019, 12:59am UTC](https://discuss.elastic.co/t/upgrading-to-elasticsearch-6-5-4-got-java-accesscontrolexception-access-denied-for-elasticsearch-yml/164552/2 "2019-01-17T00:59:54Z")

</div>

What is the permissions on the file?

---

<div class="post-metadata">

**Author:** ![jqiu97](https://avatars.discourse-cdn.com/v4/letter/j/e19b73/32.png) [@jqiu97](https://discuss.elastic.co/u/jqiu97)\
**Post date:** [January 17, 2019, 9:36pm UTC](https://discuss.elastic.co/t/upgrading-to-elasticsearch-6-5-4-got-java-accesscontrolexception-access-denied-for-elasticsearch-yml/164552/3 "2019-01-17T21:36:33Z")

</div>

The problem is related to ElasticSearch 6.2 change: [https://www.elastic.co/guide/en/elasticsearch/reference/6.x/breaking-changes-6.2.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.x/breaking-changes-6.2.html)

### All permission bootstrap check

Elasticsearch installs a security manager during bootstrap to mitigate the scope of exploits in the JDK, in third-party dependencies, and in Elasticsearch itself as well as to sandbox untrusted plugins. A custom security policy can be applied and one permission that can be added to this policy is `java.security.AllPermission` .

But even I created the following file as java.policy and add this file in java -Djava.security.policy=file:/home/jqiu/java.policy, I still got the same access denied issue.

grant codeBase "file:/home/jqiu/search/\*" {  
permission java.security.AllPermission;  
};

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2019, 9:36pm UTC](https://discuss.elastic.co/t/upgrading-to-elasticsearch-6-5-4-got-java-accesscontrolexception-access-denied-for-elasticsearch-yml/164552/4 "2019-02-14T21:36:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
