# Internet user, permissions, roles and role mappings

**URL:** <https://forum.opensearch.org/t/internet-user-permissions-roles-and-role-mappings/7862>\
**Category:** Security\
**Tags:** configure\
**Created:** [December 3, 2021, 8:55pm UTC](https://forum.opensearch.org/t/internet-user-permissions-roles-and-role-mappings/7862 "2021-12-03T20:55:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![elmidwill](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@elmidwill](https://forum.opensearch.org/u/elmidwill)\
**Post date:** [December 3, 2021, 8:55pm UTC](https://forum.opensearch.org/t/internet-user-permissions-roles-and-role-mappings/7862/1 "2021-12-03T20:55:48Z")

</div>

Hello Everyone,

I am new to opensearch and have been tasked with getting it setup and working. I extracted the tarball, replaced the certificates, and created two user. The users can only create one index that is the same as their names.  
I have tried creating roles and role mappings but I am getting this error:

{“error”:{“root\_cause”:[{“type”:“security\_exception”,“reason”:“no permissions for [indices:admin/create] and User [name=jeff, backend\_roles=[index\_full\_read\_write\_access], requestedTenant=null]”}],“type”:“security\_exception”,“reason”:"no permissions for [indices:admin/create] [anddf207@perf-dedicate:/mnt/opensearch-1.2.0/plugins/opensearch-security/securityconfig](mailto:.../plugins/opensearch-security/securityconfig)

I read the documents but something is not clicking for me. Anyone assistance would be appreciated.

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [December 4, 2021, 2:43am UTC](https://forum.opensearch.org/t/internet-user-permissions-roles-and-role-mappings/7862/2 "2021-12-04T02:43:07Z")

</div>

Hello @elmidwill

As per the error, your users are missing `indices:admin/create` privilege in their assigned role.

---

<div class="post-metadata">

**Author:** ![elmidwill](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@elmidwill](https://forum.opensearch.org/u/elmidwill)\
**Post date:** [March 2, 2022, 1:26am UTC](https://forum.opensearch.org/t/internet-user-permissions-roles-and-role-mappings/7862/3 "2022-03-02T01:26:52Z")

</div>

Thanks for the reply Pablo, and sorry about the delay. So does this mean that a user need indices:admin/create to create indices that are not their names? And does this give them access to other user created indices much like a typical admin user?

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [March 3, 2022, 12:08am UTC](https://forum.opensearch.org/t/internet-user-permissions-roles-and-role-mappings/7862/4 "2022-03-03T00:08:31Z")

</div>

@elmidwill Would you mind sharing configs of the `index_full_read_write_access` role (roles.yml and roles\_mapping.yml)?

Please also run the below command and send the result.

```auto
curl --insecure -u jeff -XGET https://<opensearch_node>:9200/_plugins/_security/authinfo?pretty

```

What type of authentication did you set? (basicauth,ldap,saml,openid etc…)
