impersonation

A couple of questions on user impersonation:

  1. does the setting have to be on all ES nodes, or will the one hit by the request suffice?

  2. what’s the format to use certificate DNs in the config? I tried the following:

searchguard.authcz.rest_impersonation_user.CN=sgadmin,OU=client,O=client,L=Test,C=DE:

  • ‘*’

``

1) on all
2) User impersonation in Search Guard | Security for Elasticsearch | Search Guard

···

Am 18.01.2019 um 15:14 schrieb Fabien Wernli <swissunix@gmail.com>:

A couple of questions on user impersonation:

1. does the setting have to be on all ES nodes, or will the one hit by the request suffice?
2. what's the format to use certificate DNs in the config? I tried the following:

searchguard.authcz.rest_impersonation_user.CN=sgadmin,OU=client,O=client,L=Test,C=DE:
  - '*'

--
You received this message because you are subscribed to the Google Groups "Search Guard Community Forum" group.
To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
To post to this group, send email to search-guard@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/65957bcc-89e8-4020-8b02-b4d31b07b987%40googlegroups.com\.
For more options, visit https://groups.google.com/d/optout\.