# Where to hook elasticsearch authentication plugin

**URL:** <https://discuss.elastic.co/t/where-to-hook-elasticsearch-authentication-plugin/174676>\
**Category:** Elasticsearch\
**Created:** [March 31, 2019, 1:23pm UTC](https://discuss.elastic.co/t/where-to-hook-elasticsearch-authentication-plugin/174676 "2019-03-31T13:23:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![MKU](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mku/32/48327_2.png) [@MKU](https://discuss.elastic.co/u/MKU)\
**Post date:** [March 31, 2019, 1:23pm UTC](https://discuss.elastic.co/t/where-to-hook-elasticsearch-authentication-plugin/174676/1 "2019-03-31T13:23:24Z")

</div>

I want to write a basic elasticsearch authentication plugin without involing x-pack,but i am confused where to begin(which java file i need to extend).  
Can you guys give me some hint.

Thank you.

---

<div class="post-metadata">

**Author:** ![MKU](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mku/32/48327_2.png) [@MKU](https://discuss.elastic.co/u/MKU)\
**Post date:** [April 4, 2019, 5:54am UTC](https://discuss.elastic.co/t/where-to-hook-elasticsearch-authentication-plugin/174676/2 "2019-04-04T05:54:40Z")

</div>

I found this blog about authentication plugin [https://qbox.io/blog/secure-elasticsearch-authentication-plugin-tutorial](https://qbox.io/blog/secure-elasticsearch-authentication-plugin-tutorial)  
But this is deprecated and is for es-2.5,where do i start ,can you briefly explain it.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 4, 2019, 9:43am UTC](https://discuss.elastic.co/t/where-to-hook-elasticsearch-authentication-plugin/174676/3 "2019-04-04T09:43:06Z")

</div>

The best way would be to go with the source. Start taking a look at the [Plugin](https://github.com/elastic/elasticsearch/blob/master/server/src/main/java/org/elasticsearch/plugins/Plugin.java) and its subclasses, that are listed in the javadoc comment. From there on you can pick what you need to implement based on your security requirements.

---

<div class="post-metadata">

**Author:** ![MKU](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mku/32/48327_2.png) [@MKU](https://discuss.elastic.co/u/MKU)\
**Post date:** [April 4, 2019, 9:59am UTC](https://discuss.elastic.co/t/where-to-hook-elasticsearch-authentication-plugin/174676/4 "2019-04-04T09:59:27Z")

</div>

Is it possible to modify rest controller for authentication.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2019, 10:09am UTC](https://discuss.elastic.co/t/where-to-hook-elasticsearch-authentication-plugin/174676/5 "2019-05-02T10:09:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
