# Why plugin-security.policy file has no effect?

**URL:** <https://discuss.elastic.co/t/why-plugin-security-policy-file-has-no-effect/44072>\
**Category:** Elasticsearch\
**Created:** [March 10, 2016, 7:43pm UTC](https://discuss.elastic.co/t/why-plugin-security-policy-file-has-no-effect/44072 "2016-03-10T19:43:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![thefourtheye](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thefourtheye/32/8414_2.png) [@thefourtheye](https://discuss.elastic.co/u/thefourtheye)\
**Post date:** [March 10, 2016, 7:43pm UTC](https://discuss.elastic.co/t/why-plugin-security-policy-file-has-no-effect/44072/1 "2016-03-10T19:43:25Z")

</div>

I am trying out a custom plugin with ES-2.2.0 and JDK-1.8. After the zip creation, the plugin-security.policy file is at the root level, and it looks like this

```
grant {
    permission java.lang.RuntimePermission "getClassLoader";
};

```

I had to include this, because one of my Service classes does,

```
InputStream stream = Thread.currentThread()
      .getContextClassLoader()
      .getResourceAsStream("conf/myplugin.properties");

```

Now, when I install the plugin, I get the message

```
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

@ WARNING: plugin requires additional permissions @

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

* java.lang.RuntimePermission getClassLoader
See http://docs.oracle.com/javase/8/docs/technotes/guides/security/permissions.html
for descriptions of what these permissions allow and the associated risks.

  Continue with installation? [y/N]

```

I respond with y and then the installation is successful. When I restart the ES, I get the following error in /var/log/elasticsearch.log file

```
java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "getClassLoader") 
  at java.security.AccessControlContext.checkPermission(AccessControlContext.java:472) 
  at java.security.AccessController.checkPermission(AccessController.java:884)   
  at java.lang.SecurityManager.checkPermission(SecurityManager.java:549)         
  at java.lang.ClassLoader.checkClassLoaderPermission(ClassLoader.java:1525)     
  at java.lang.Thread.getContextClassLoader(Thread.java:1436)                    

```

What could be the probleam and how I can fix this?

---

<div class="post-metadata">

**Author:** ![ddbullfrog](https://avatars.discourse-cdn.com/v4/letter/d/898d66/32.png) [@ddbullfrog](https://discuss.elastic.co/u/ddbullfrog)\
**Post date:** [March 13, 2016, 9:23pm UTC](https://discuss.elastic.co/t/why-plugin-security-policy-file-has-no-effect/44072/2 "2016-03-13T21:23:11Z")

</div>

I am facing similar issue, Have you found a solution for it? Thanks, Dong

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [March 13, 2016, 11:37pm UTC](https://discuss.elastic.co/t/why-plugin-security-policy-file-has-no-effect/44072/3 "2016-03-13T23:37:49Z")

</div>

You need to execute the above code inside a [`AccessController.doPrivleged` block](https://docs.oracle.com/javase/8/docs/technotes/guides/security/doprivileged.html). See also the javadocs for [AccessController](https://docs.oracle.com/javase/8/docs/api/java/security/AccessController.html). Make sure that you understand this stuff very carefully before proceeding, you do _not_ want to get security wrong. This is not for the faint of heart.

---

<div class="post-metadata">

**Author:** ![thefourtheye](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thefourtheye/32/8414_2.png) [@thefourtheye](https://discuss.elastic.co/u/thefourtheye)\
**Post date:** [March 14, 2016, 7:09am UTC](https://discuss.elastic.co/t/why-plugin-security-policy-file-has-no-effect/44072/4 "2016-03-14T07:09:44Z")

</div>

Thanks. It worked. I think the documentation can be expanded with a working example.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:08pm UTC](https://discuss.elastic.co/t/why-plugin-security-policy-file-has-no-effect/44072/5 "2017-07-05T23:08:45Z")

</div>


