# Security

**URL:** https://forum.opensearch.org/c/security/3.md

[Latest](https://forum.opensearch.org/latest.md) · [Categories](https://forum.opensearch.org/categories.md) · [Tags](https://forum.opensearch.org/tags.md)

---

## [About the Security category](https://forum.opensearch.org/t/about-the-security-category/2)

<div class="topic-metadata">

**Author:** [@system](https://forum.opensearch.org/u/system)\
**Replies:** 1\
**Last updated:** [January 14, 2023, 3:08am UTC](https://forum.opensearch.org/t/about-the-security-category/2 "2023-01-14T03:08:07Z")

</div>

Security in OpenSearch is built around four main features that work together to safeguard data and track activity within a cluster. From setting up TLS and roles-based access control, to configuring Kibana tenants and a…

---

## [Alerting / Monitors](https://forum.opensearch.org/t/alerting-monitors/28286)

<div class="topic-metadata">

**Author:** [@muraliv](https://forum.opensearch.org/u/muraliv)\
**Replies:** 8\
**Last updated:** [September 29, 2026, 10:42am UTC](https://forum.opensearch.org/t/alerting-monitors/28286 "2026-09-29T10:42:54Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.8 Describe the issue: Members sharing at least one common backend role are not able to see the alerts or monitor definition. When I look at the monitor d…

---

## [Log4j 2.25.4 Vulnerability in OpenSearch 3.8.0](https://forum.opensearch.org/t/log4j-2-25-4-vulnerability-in-opensearch-3-8-0/28266)

<div class="topic-metadata">

**Author:** [@scott](https://forum.opensearch.org/u/scott)\
**Replies:** 1\
**Last updated:** [September 3, 2026, 5:23pm UTC](https://forum.opensearch.org/t/log4j-2-25-4-vulnerability-in-opensearch-3-8-0/28266 "2026-09-03T17:23:06Z")

</div>

Versions: OpenSearch 3.8.0 & Log4j 2.25.4 Describe the issue: OpenSearch 3.8.0 uses Log4j 2.25.4 which has a vulnerability, CVE-2026-49844. Does CVE-2026-49844 impact OpenSearch? Any plans to upgrade Log4j version? …

---

## [LDAP fails when user is in a disabled group](https://forum.opensearch.org/t/ldap-fails-when-user-is-in-a-disabled-group/28233)

<div class="topic-metadata">

**Author:** [@neil.chikode](https://forum.opensearch.org/u/neil.chikode)\
**Replies:** 10\
**Last updated:** [August 7, 2026, 8:28pm UTC](https://forum.opensearch.org/t/ldap-fails-when-user-is-in-a-disabled-group/28233 "2026-08-07T20:28:18Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Describe the issue: The LDAP login fails when user is in a disabled group like CN=VZI Users 2,OU=DisabledGroups,OU=Disabled,DC=vdsi,DC=ent,DC=verizon,DC=com…

---

## [How to enable http strict transport security (HSTS)?](https://forum.opensearch.org/t/how-to-enable-http-strict-transport-security-hsts/12619)

<div class="topic-metadata">

**Author:** [@strattao](https://forum.opensearch.org/u/strattao)\
**Replies:** 5\
**Last updated:** [July 29, 2026, 5:54pm UTC](https://forum.opensearch.org/t/how-to-enable-http-strict-transport-security-hsts/12619 "2026-07-29T17:54:07Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Opensearch 2.5 Describe the issue: I want to enable hsts for the opensearch dashboards and for the opensearch service. I can’t figure out how to correctly …

---

## [Granting permissions to third-party JAR in lib/ — is patching security.policy inside opensearch-3.2.0.jar the right approach?](https://forum.opensearch.org/t/granting-permissions-to-third-party-jar-in-lib-is-patching-security-policy-inside-opensearch-3-2-0-jar-the-right-approach/28212)

<div class="topic-metadata">

**Author:** [@SanthoshCV](https://forum.opensearch.org/u/SanthoshCV)\
**Replies:** 1\
**Last updated:** [July 23, 2026, 12:32pm UTC](https://forum.opensearch.org/t/granting-permissions-to-third-party-jar-in-lib-is-patching-security-policy-inside-opensearch-3-2-0-jar-the-right-approach/28212 "2026-07-23T12:32:19Z")

</div>

I am embedding a third-party logging JAR (logagent.jar) into OpenSearch 3.2.0 by placing it in lib/. The JAR needs SocketPermission to connect to an external HTTPS endpoint. I found that OpenSearch’s agent-based securit…

---

## [Is it possible to use AD Authc and Opensearch internal role mapping (no AD Authz)?](https://forum.opensearch.org/t/is-it-possible-to-use-ad-authc-and-opensearch-internal-role-mapping-no-ad-authz/28162)

<div class="topic-metadata">

**Author:** [@subgenius](https://forum.opensearch.org/u/subgenius)\
**Replies:** 5\
**Last updated:** [July 3, 2026, 8:27am UTC](https://forum.opensearch.org/t/is-it-possible-to-use-ad-authc-and-opensearch-internal-role-mapping-no-ad-authz/28162 "2026-07-03T08:27:40Z")

</div>

I have successfully set up AD Authc on Opensearch. Now I am moving on to configure Authz. Is it feasible to configure Authz to be manually configured in Opensearch for AD authenticated clients? In the Active Directory…

---

## [Nodes do not form a cluster](https://forum.opensearch.org/t/nodes-do-not-form-a-cluster/28167)

<div class="topic-metadata">

**Author:** [@ivkrlv](https://forum.opensearch.org/u/ivkrlv)\
**Replies:** 1\
**Last updated:** [June 29, 2026, 7:10am UTC](https://forum.opensearch.org/t/nodes-do-not-form-a-cluster/28167 "2026-06-29T07:10:37Z")

</div>

Versions (opensearch 3.4.0/Server OS: Windows 2019/Browser: No browser): Describe the issue Please help me understand why my nodes aren’t forming a cluster. OpenSearch 3.4.0 is installed on two Windows nodes. Ports 9…

---

## [Question over TLS transport configs as relates to LDAP authc](https://forum.opensearch.org/t/question-over-tls-transport-configs-as-relates-to-ldap-authc/28152)

<div class="topic-metadata">

**Author:** [@subgenius](https://forum.opensearch.org/u/subgenius)\
**Replies:** 3\
**Last updated:** [June 25, 2026, 6:46pm UTC](https://forum.opensearch.org/t/question-over-tls-transport-configs-as-relates-to-ldap-authc/28152 "2026-06-25T18:46:45Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Describe the issue:Empty file path for plugins.security.ssl.transport.truststore\_filepath Configuration: Active Directory Authc Relevant Logs or Screenshot…

---

## [API Keys access version 3.7.0](https://forum.opensearch.org/t/api-keys-access-version-3-7-0/28130)

<div class="topic-metadata">

**Author:** [@hitesh303](https://forum.opensearch.org/u/hitesh303)\
**Replies:** 4\
**Last updated:** [June 22, 2026, 7:34pm UTC](https://forum.opensearch.org/t/api-keys-access-version-3-7-0/28130 "2026-06-22T19:34:25Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Describe the issue: Upgraded to 3.7.0. When log-in as user can’t see API key option in UI. Is this only limited to Admin? Configuration: Relevant Logs or S…

---

## [No results when using API keys](https://forum.opensearch.org/t/no-results-when-using-api-keys/28134)

<div class="topic-metadata">

**Author:** [@marcb](https://forum.opensearch.org/u/marcb)\
**Replies:** 3\
**Last updated:** [June 16, 2026, 8:20am UTC](https://forum.opensearch.org/t/no-results-when-using-api-keys/28134 "2026-06-16T08:20:35Z")

</div>

Versions OpenSearch 3.7 Describe the issue: I am having issues when trying to use API keys. The cluster is a small QA environment. Human users authenticate via SAML to Dashboards and get permissions from LDAP, tools use…

---

## [NPM flagging all versions of opensearch-project as compromised](https://forum.opensearch.org/t/npm-flagging-all-versions-of-opensearch-project-as-compromised/28103)

<div class="topic-metadata">

**Author:** [@Aquacephale](https://forum.opensearch.org/u/Aquacephale)\
**Replies:** 4\
**Last updated:** [June 3, 2026, 9:21am UTC](https://forum.opensearch.org/t/npm-flagging-all-versions-of-opensearch-project-as-compromised/28103 "2026-06-03T09:21:37Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): all versions Describe the issue: Since 3 days ago, npm is flagging all versions of opensearch-project as compromised (see screenshot below). We discovered th…

---

## [Opensearch Netty vulnerability](https://forum.opensearch.org/t/opensearch-netty-vulnerability/28101)

<div class="topic-metadata">

**Author:** [@nikhil.rathore](https://forum.opensearch.org/u/nikhil.rathore)\
**Replies:** 1\
**Last updated:** [June 2, 2026, 7:37pm UTC](https://forum.opensearch.org/t/opensearch-netty-vulnerability/28101 "2026-06-02T19:37:02Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.6.0 Describe the issue: Latest opensearch 3.6.0 has critical vulneability on Netty Project 4.2.12.Final and Netty Project 4.2.7.Final. Below are the vulner…

---

## [Docker And Security Plug-In Setup](https://forum.opensearch.org/t/docker-and-security-plug-in-setup/28092)

<div class="topic-metadata">

**Author:** [@OSuser](https://forum.opensearch.org/u/OSuser)\
**Replies:** 2\
**Last updated:** [May 29, 2026, 2:07pm UTC](https://forum.opensearch.org/t/docker-and-security-plug-in-setup/28092 "2026-05-29T14:07:13Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.6.0 Describe the issue: I get the error No ‘Authorization’ header, send 401 and ‘WWW-Authenticate Basic’ when I make a POST request. How can I fix this? C…

---

## [Basic Auth How To](https://forum.opensearch.org/t/basic-auth-how-to/28085)

<div class="topic-metadata">

**Author:** [@OSuser](https://forum.opensearch.org/u/OSuser)\
**Replies:** 4\
**Last updated:** [May 27, 2026, 10:35pm UTC](https://forum.opensearch.org/t/basic-auth-how-to/28085 "2026-05-27T22:35:34Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Latest version of OS Describe the issue: Is base64 encoding needed with Basic Auth to make a POST request to insert data? I am using C++ to build the request…

---

## [Security configuration in OpenSearch Helm Charts](https://forum.opensearch.org/t/security-configuration-in-opensearch-helm-charts/28072)

<div class="topic-metadata">

**Author:** [@pablo](https://forum.opensearch.org/u/pablo)\
**Replies:** 2\
**Last updated:** [May 19, 2026, 4:06pm UTC](https://forum.opensearch.org/t/security-configuration-in-opensearch-helm-charts/28072 "2026-05-19T16:06:23Z")

</div>

\*\* On behalf of a user of Slack \*\* Hi, i am having a hard time finding a complete example for a helm chart setup with security enabled, using a external cryptographic key pair, defining an admin user and password and di…

---

## [Getting Missing role error for AD user with all\_access role](https://forum.opensearch.org/t/getting-missing-role-error-for-ad-user-with-all-access-role/28041)

<div class="topic-metadata">

**Author:** [@Santhosh.Gollapudi](https://forum.opensearch.org/u/Santhosh.Gollapudi)\
**Replies:** 8\
**Last updated:** [May 18, 2026, 3:40pm UTC](https://forum.opensearch.org/t/getting-missing-role-error-for-ad-user-with-all-access-role/28041 "2026-05-18T15:40:25Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.6.0 / RHEL 9.7 / Chrome Describe the issue: We recently built a opensearch cluster for our test environment and we have configured our ADOM group as backen…

---

## [Passwords in opensearch keystore](https://forum.opensearch.org/t/passwords-in-opensearch-keystore/28063)

<div class="topic-metadata">

**Author:** [@muraliv](https://forum.opensearch.org/u/muraliv)\
**Replies:** 1\
**Last updated:** [May 13, 2026, 5:56pm UTC](https://forum.opensearch.org/t/passwords-in-opensearch-keystore/28063 "2026-05-13T17:56:01Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.6 Describe the issue: I would like to know if I could use the opensearch keystore to store the bind password for a domain user instead of using environmen…

---

## [Opensearch dashboards logging screen on the browser throwing "missing role" error](https://forum.opensearch.org/t/opensearch-dashboards-logging-screen-on-the-browser-throwing-missing-role-error/16092)

<div class="topic-metadata">

**Author:** [@geetha](https://forum.opensearch.org/u/geetha)\
**Replies:** 8\
**Last updated:** [May 5, 2026, 12:53pm UTC](https://forum.opensearch.org/t/opensearch-dashboards-logging-screen-on-the-browser-throwing-missing-role-error/16092 "2026-05-05T12:53:01Z")

</div>

Versions 1.3.10 Opensearch dashboards logging screen on the browser throwing “missing role” error. Using self signed certs. created user and role as predefined all\_access role and mapped role with user. Describe the is…

---

## [Dedicated Coordinating Cluster for Cross Cluster Search](https://forum.opensearch.org/t/dedicated-coordinating-cluster-for-cross-cluster-search/28014)

<div class="topic-metadata">

**Author:** [@farman](https://forum.opensearch.org/u/farman)\
**Replies:** 7\
**Last updated:** [April 27, 2026, 8:11am UTC](https://forum.opensearch.org/t/dedicated-coordinating-cluster-for-cross-cluster-search/28014 "2026-04-27T08:11:13Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Describe the issue: Is a “dedicated coordinating cluster” to support Cross Cluster Search a best practice or architecture pattern that is widely used or prop…

---

## [Does opensearch inter node communication follow mtls?](https://forum.opensearch.org/t/does-opensearch-inter-node-communication-follow-mtls/28006)

<div class="topic-metadata">

**Author:** [@rharidas](https://forum.opensearch.org/u/rharidas)\
**Replies:** 1\
**Last updated:** [April 21, 2026, 3:48pm UTC](https://forum.opensearch.org/t/does-opensearch-inter-node-communication-follow-mtls/28006 "2026-04-21T15:48:12Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.5.0 Describe the issue: When opensearch is installed with security enabled, certificates are configured for nodes. When nodes communicate with each other f…

---

## [Internal read-only user cannot view any dashboards/data](https://forum.opensearch.org/t/internal-read-only-user-cannot-view-any-dashboards-data/27964)

<div class="topic-metadata">

**Author:** [@seanthegeek](https://forum.opensearch.org/u/seanthegeek)\
**Replies:** 7\
**Last updated:** [April 12, 2026, 1:29am UTC](https://forum.opensearch.org/t/internal-read-only-user-cannot-view-any-dashboards-data/27964 "2026-04-12T01:29:36Z")

</div>

Versions 3.5.0 via Docker: Describe the issue: I’m trying to create an analyst user role that grants read-only access to dashboards in specific tenants. I’ve created a role that I thought would accomplish that and mappe…

---

## [OBO token - roles encryption](https://forum.opensearch.org/t/obo-token-roles-encryption/27951)

<div class="topic-metadata">

**Author:** [@pablo](https://forum.opensearch.org/u/pablo)\
**Replies:** 1\
**Last updated:** [March 26, 2026, 12:35pm UTC](https://forum.opensearch.org/t/obo-token-roles-encryption/27951 "2026-03-26T12:35:17Z")

</div>

\*\* On behalf of a user of Slack \*\* Hello all, I am trying to setup OBO token, but the documentation is a bit limited in explaining how to do this. So I have configured the security config for on\_behalf\_of with the req…

---

## [HTTPS/TLS with own PKI](https://forum.opensearch.org/t/https-tls-with-own-pki/27941)

<div class="topic-metadata">

**Author:** [@cguillaume](https://forum.opensearch.org/u/cguillaume)\
**Replies:** 6\
**Last updated:** [March 24, 2026, 10:18pm UTC](https://forum.opensearch.org/t/https-tls-with-own-pki/27941 "2026-03-24T22:18:50Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Graylog 7.0 + mongodb 8.x + opensearch/opensearch dashboards 2.19.4 unbuntu 24.04 virtual server install made by apt package Describe the issue: one opens…

---

## [SSL Certificates not working](https://forum.opensearch.org/t/ssl-certificates-not-working/27869)

<div class="topic-metadata">

**Author:** [@mmarunbabu](https://forum.opensearch.org/u/mmarunbabu)\
**Replies:** 11\
**Last updated:** [March 20, 2026, 9:35am UTC](https://forum.opensearch.org/t/ssl-certificates-not-working/27869 "2026-03-20T09:35:41Z")

</div>

\*\*HI Team, We are getting below error while configuring the security admin. Versions\*\* (relevant - OpenSearch/Dashboard/Server OS/Browser): Describe the issue: aster-0\\\] Exception during establishing a SSL connection:…

---

## [When Is It Safe To Disable The Security Plugin?](https://forum.opensearch.org/t/when-is-it-safe-to-disable-the-security-plugin/27933)

<div class="topic-metadata">

**Author:** [@xalexander](https://forum.opensearch.org/u/xalexander)\
**Replies:** 1\
**Last updated:** [March 18, 2026, 12:13am UTC](https://forum.opensearch.org/t/when-is-it-safe-to-disable-the-security-plugin/27933 "2026-03-18T00:13:24Z")

</div>

Hi, I’m currently setting up opensearch as the search server for Confluence (this is on an internal network). In regards to the security plugin, when is it “safe“ to disable it?

---

## [Cluster stuck in "Security not initialized" loop after TLS certificate rotation (2.11.1)](https://forum.opensearch.org/t/cluster-stuck-in-security-not-initialized-loop-after-tls-certificate-rotation-2-11-1/27711)

<div class="topic-metadata">

**Author:** [@v1k1ng0](https://forum.opensearch.org/u/v1k1ng0)\
**Replies:** 10\
**Last updated:** [March 17, 2026, 8:51am UTC](https://forum.opensearch.org/t/cluster-stuck-in-security-not-initialized-loop-after-tls-certificate-rotation-2-11-1/27711 "2026-03-17T08:51:49Z")

</div>

Description: Environment: OpenSearch Version: 2.11.1 Deployment: OpenSearch Kubernetes Operator Replicas: 3 Masters (currently trying to recover with 1) The Issue: My transport and http certificates expired. …

---

## [OpenSearch 3.5 ignores verify\_hostnames: false in OpenID config and fails with SAN hostname validation error](https://forum.opensearch.org/t/opensearch-3-5-ignores-verify-hostnames-false-in-openid-config-and-fails-with-san-hostname-validation-error/27893)

<div class="topic-metadata">

**Author:** [@shubtiwa](https://forum.opensearch.org/u/shubtiwa)\
**Replies:** 4\
**Last updated:** [March 4, 2026, 7:03pm UTC](https://forum.opensearch.org/t/opensearch-3-5-ignores-verify-hostnames-false-in-openid-config-and-fails-with-san-hostname-validation-error/27893 "2026-03-04T19:03:25Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.5 Describe the issue: We are configuring OpenSearch 3.5 to use OpenID authentication with Keycloak as the IdP. Our OpenSearch security configuration inclu…

---

## [Adding custom http authenticators on top of security plugin](https://forum.opensearch.org/t/adding-custom-http-authenticators-on-top-of-security-plugin/27887)

<div class="topic-metadata">

**Author:** [@tony.bargnesi](https://forum.opensearch.org/u/tony.bargnesi)\
**Replies:** 4\
**Last updated:** [March 4, 2026, 1:33pm UTC](https://forum.opensearch.org/t/adding-custom-http-authenticators-on-top-of-security-plugin/27887 "2026-03-04T13:33:51Z")

</div>

Versions: OpenSearch 3.5.0; Security 3.5.0.0 Describe the issue: I would like to extend the existing JWT authentication to verify the token using the public key from a trusted certificate chain with the x5c JWS header…

---

## [Opensearch Dashboard SAML2 Failure](https://forum.opensearch.org/t/opensearch-dashboard-saml2-failure/27871)

<div class="topic-metadata">

**Author:** [@Lambertyan](https://forum.opensearch.org/u/Lambertyan)\
**Replies:** 2\
**Last updated:** [March 1, 2026, 10:41am UTC](https://forum.opensearch.org/t/opensearch-dashboard-saml2-failure/27871 "2026-03-01T10:41:36Z")

</div>

Versions OpenSearch / Dashboard: v3.5.0, v3.4.0 Server OS: Intel Mac OS X 10\_15\_7 Browser: Chrome/145.0.0.0 Describe the issue: Facing (different) error in both IdP initialised flow and SP initialised flow, can any …

[Next page](https://forum.opensearch.org/c/security/3.md?page=1)
