# Authentication Limitation

**URL:** <https://forum.opensearch.org/t/authentication-limitation/1305>\
**Category:** Security\
**Created:** [August 13, 2019, 1:59pm UTC](https://forum.opensearch.org/t/authentication-limitation/1305 "2019-08-13T13:59:48Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![siva](https://avatars.discourse-cdn.com/v4/letter/s/7c8e57/32.png) [@siva](https://forum.opensearch.org/u/siva)\
**Post date:** [August 13, 2019, 1:59pm UTC](https://forum.opensearch.org/t/authentication-limitation/1305/1 "2019-08-13T13:59:48Z")

</div>

Multiple services are pushing documents to our elasticsearch and it’s validated via JWT authentication

As per my understanding authentication, is happening based on the order updated in the config.yml (/usr/share/elasticsearch/plugins/opendistro\_security/securityconfig/config.yml)

When we tried to onboard new service with the order:7 requests started failing with the error 401 hence for testing purpose, used JWT type with the order:6 and it succeeds.

Do we have any limitation from opendistro related to the authentication order which it will support?

Example:  
Worked configuration:

jwt\_auth\_domain6:  
http\_enabled: true  
transport\_enabled: false  
order: 6  
http\_authenticator:  
type: jwt  
challenge: false  
config:  
signing\_key: |-  
-----BEGIN PUBLIC KEY-----  
KEY  
-----END PUBLIC KEY-----  
jwt\_header: “Authorization”  
jwt\_url\_parameter: null  
roles\_key: “roles”  
subject\_key: “sub”  
authentication\_backend:  
type: noop

Not working configuration:

jwt\_auth\_domain7:  
http\_enabled: true  
transport\_enabled: false  
order: 7  
http\_authenticator:  
type: jwt  
challenge: false  
config:  
signing\_key: |-  
-----BEGIN PUBLIC KEY-----  
KEY  
-----END PUBLIC KEY-----  
jwt\_header: “Authorization”  
jwt\_url\_parameter: null  
roles\_key: “roles”  
subject\_key: “sub”  
authentication\_backend:  
type: noop

Note:  
We have already used till order:6 for other services

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [May 19, 2021, 11:14am UTC](https://forum.opensearch.org/t/authentication-limitation/1305/2 "2021-05-19T11:14:40Z")

</div>

Hello @siva

Do you still have this issue? What is the ODFE version?
