# Can the Elastic Search Java Node Clients be authenticated

**URL:** <https://forum.search-guard.com/t/can-the-elastic-search-java-node-clients-be-authenticated/345>\
**Category:** Search Guard\
**Created:** [December 21, 2016, 1:17pm UTC](https://forum.search-guard.com/t/can-the-elastic-search-java-node-clients-be-authenticated/345 "2016-12-21T13:17:25Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![shashanka](https://avatars.discourse-cdn.com/v4/letter/s/a9a28c/32.png) [@shashanka](https://forum.search-guard.com/u/shashanka)\
**Post date:** [December 21, 2016, 1:17pm UTC](https://forum.search-guard.com/t/can-the-elastic-search-java-node-clients-be-authenticated/345/1 "2016-12-21T13:17:25Z")

</div>

> **[Security for Elasticsearch | Using Transport Clients | Search Guard](https://search-guard.com/searchguard-elasicsearch-transport-clients/)**
>
> How to use Transport Clients to securely access your Elasticsearch cluster that is protected by Search Guard.

Reading the article pointed by the above link. I was unable to understand the statement “NodeClients are not supported by Search Guard”

Can some one explain what does this mean ?

Requirement:

We have Elastic Search embedded in our application rather than as a service. We are using java node clients (I believe anything which we use to talk to Cluster apart from transport clients are referred as node clients…please correct me if i am wrong ) to talk to the ES Cluster from within our application. Now we have a requirement to authenticate access to indexes. I know Transport clients does this by setting authorisation headers. But what about the java node clients ? is is possible to authenticate the java node clients using HTTP Authentication against Search guard Internal Users Database ?

What exactly does “NodeClients are not supported by Search Guard” mean ?

Thanks

---

<div class="post-metadata">

**Author:** ![shashanka](https://avatars.discourse-cdn.com/v4/letter/s/a9a28c/32.png) [@shashanka](https://forum.search-guard.com/u/shashanka)\
**Post date:** [December 21, 2016, 8:08pm UTC](https://forum.search-guard.com/t/can-the-elastic-search-java-node-clients-be-authenticated/345/2 "2016-12-21T20:08:22Z")

</div>

Any reply on this

---

<div class="post-metadata">

**Author:** ![11116](https://avatars.discourse-cdn.com/v4/letter/1/6bbea6/32.png) [@11116](https://forum.search-guard.com/u/11116)\
**Post date:** [March 29, 2017, 7:35am UTC](https://forum.search-guard.com/t/can-the-elastic-search-java-node-clients-be-authenticated/345/3 "2017-03-29T07:35:13Z")

</div>

Hi，I am currently testing how to achieve java program and ES cluster communication. Have you already understood the answer now?

在 2016年12月21日星期三 UTC+8下午9:17:25，supraj写道：

> **···**
>
> > [https://floragunn.com/searchguard-elasicsearch-transport-clients/](https://floragunn.com/searchguard-elasicsearch-transport-clients/)
> 
> > 
> 
> > Reading the article pointed by the above link. I was unable to understand the statement “NodeClients are not supported by Search Guard”
> 
> > 
> 
> > Can some one explain what does this mean ?
> 
> > 
> 
> > Requirement:
> 
> > We have Elastic Search embedded in our application rather than as a service. We are using java node clients (I believe anything which we use to talk to Cluster apart from transport clients are referred as node clients…please correct me if i am wrong ) to talk to the ES Cluster from within our application. Now we have a requirement to authenticate access to indexes. I know Transport clients does this by setting authorisation headers. But what about the java node clients ? is is possible to authenticate the java node clients using HTTP Authentication against Search guard Internal Users Database ?
> 
> > 
> 
> > What exactly does “NodeClients are not supported by Search Guard” mean ?
> 
> > 
> 
> > Thanks

---

<div class="post-metadata">

**Author:** ![Fabien\_Wernli](https://avatars.discourse-cdn.com/v4/letter/f/48db29/32.png) [@Fabien\_Wernli](https://forum.search-guard.com/u/Fabien_Wernli)\
**Post date:** [March 30, 2017, 7:31am UTC](https://forum.search-guard.com/t/can-the-elastic-search-java-node-clients-be-authenticated/345/4 "2017-03-30T07:31:14Z")

</div>

Hi,

You can use the official java client to talk to SG enabled ES, but it needs to be configured as a transport client, as the SG documentation suggests (node not supported).  
Don’t worry, the ‘Node’ mode is slowly being deprecated in ES anyway.  
The other way is to use HTTP(s) using the Jest library.

[Here is an example on how to integrate with SG using the transport protocol](https://github.com/balabit/syslog-ng/blob/master/modules/java-modules/elastic-v2/src/main/java/org/syslog_ng/elasticsearch_v2/client/esnative/ESTransportSearchGuardClient.java).  
[Here is another example on how to integrate with SG using Jest.](https://github.com/balabit/syslog-ng/tree/master/modules/java-modules/elastic-v2/src/main/java/org/syslog_ng/elasticsearch_v2/client/http)

If you use HTTP, you can authenticate using password or clientcert or Negotiate.  
If you use Transport you can only use the keystore mechanism.

---

<div class="post-metadata">

**Author:** ![11116](https://avatars.discourse-cdn.com/v4/letter/1/6bbea6/32.png) [@11116](https://forum.search-guard.com/u/11116)\
**Post date:** [April 1, 2017, 7:07am UTC](https://forum.search-guard.com/t/can-the-elastic-search-java-node-clients-be-authenticated/345/5 "2017-04-01T07:07:02Z")

</div>

Thank you for the reference, but this seems to be for the ES-v2 version. I am currently using the ES5.2, the reference on the web is less. Do you currently implement the V2 version of the certification?

在 2016年12月21日星期三 UTC+8下午9:17:25，supraj写道：

> **···**
>
> > [https://floragunn.com/searchguard-elasicsearch-transport-clients/](https://floragunn.com/searchguard-elasicsearch-transport-clients/)
> 
> > 
> 
> > Reading the article pointed by the above link. I was unable to understand the statement “NodeClients are not supported by Search Guard”
> 
> > 
> 
> > Can some one explain what does this mean ?
> 
> > 
> 
> > Requirement:
> 
> > We have Elastic Search embedded in our application rather than as a service. We are using java node clients (I believe anything which we use to talk to Cluster apart from transport clients are referred as node clients…please correct me if i am wrong ) to talk to the ES Cluster from within our application. Now we have a requirement to authenticate access to indexes. I know Transport clients does this by setting authorisation headers. But what about the java node clients ? is is possible to authenticate the java node clients using HTTP Authentication against Search guard Internal Users Database ?
> 
> > 
> 
> > What exactly does “NodeClients are not supported by Search Guard” mean ?
> 
> > 
> 
> > Thanks

---

<div class="post-metadata">

**Author:** ![Fabien\_Wernli](https://avatars.discourse-cdn.com/v4/letter/f/48db29/32.png) [@Fabien\_Wernli](https://forum.search-guard.com/u/Fabien_Wernli)\
**Post date:** [April 3, 2017, 7:31pm UTC](https://forum.search-guard.com/t/can-the-elastic-search-java-node-clients-be-authenticated/345/6 "2017-04-03T19:31:40Z")

</div>

HTTP will work the same way with any ES version.  
As for the transport node, it should work the same way, try it.

It’s really just a matter of running a regular transport client, and simply adding the searchguard plugin using  
plugins.add(SearchGuardSSLPlugin.class);

``
