# Proxy auth doesn't work

**URL:** <https://forum.opensearch.org/t/proxy-auth-doesnt-work/4369>\
**Category:** Security\
**Created:** [December 10, 2020, 4:13pm UTC](https://forum.opensearch.org/t/proxy-auth-doesnt-work/4369 "2020-12-10T16:13:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![roman](https://avatars.discourse-cdn.com/v4/letter/r/ed8c4c/32.png) [@roman](https://forum.opensearch.org/u/roman)\
**Post date:** [December 10, 2020, 4:13pm UTC](https://forum.opensearch.org/t/proxy-auth-doesnt-work/4369/1 "2020-12-10T16:13:35Z")

</div>

Hello I have such config.yml  
—  
\_meta:  
type: “config”  
config\_version: 2

```
config:
  dynamic:
    do_not_fail_on_forbidden: true
    http:
      anonymous_auth_enabled: false
      xff:
        enabled: true
        internalProxies: '.*' # regex pattern
        remoteIpHeader: 'x-forwarded-for'
    
authc:
  basic_internal_auth_domain:
    description: "Authenticate via HTTP Basic against internal users database"
    http_enabled: true
    transport_enabled: true
    order: 1
    http_authenticator:
      type: basic
      challenge: true
    authentication_backend:
      type: intern
  proxy_auth_domain:
    description: "Authenticate via proxy"
    http_enabled: true
    transport_enabled: false
    order: 0
    http_authenticator:
      type: proxy
      challenge: false
      config:
        user_header: "x-proxy-user"
        roles_header: "x-proxy-roles"
    authentication_backend:
      type: noop

```

I use such command to apply it  
./securityadmin.sh -f config.yml -icl -nhnv -cert kirk.pem -cacert root-ca.pem -h -key kirk-key.pem -t config

In ES log I can see it -  
[2020-12-10T19:11:00,309][DEBUG][c.a.o.s.c.ConfigurationLoaderSecurity7] [olimp\_master] Received config for internalusers (of [INTERNALUSERS]) with current latch value=0  
[2020-12-10T19:11:00,546][DEBUG][c.a.o.s.c.ConfigurationLoaderSecurity7] [olimp\_master] Received config for internalusers (of [INTERNALUSERS]) with current latch value=0  
[2020-12-10T19:11:00,685][DEBUG][c.a.o.s.d.r.a.RestApiPrivilegesEvaluator] [olimp\_master] Checking admin access for endpoint CONFIG, path /\_opendistro/\_security/api/securityconfig and method GET  
[2020-12-10T19:11:00,690][DEBUG][c.a.o.s.c.ConfigurationLoaderSecurity7] [olimp\_master] Load config with version 2  
[2020-12-10T19:11:00,693][DEBUG][c.a.o.s.c.ConfigurationLoaderSecurity7] [olimp\_master] Received config for config (of [CONFIG]) with current latch value=0

But in kibana web interface proxy\_auth is still disabled:

 ![Screenshot 2020-12-10 at 19.13.06](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/1X/2b9a4e2e86f430445aff5ac26b7a567d21178280.png)  
Need some help

---

<div class="post-metadata">

**Author:** ![spapadop](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/spapadop/32/950_2.png) [@spapadop](https://forum.opensearch.org/u/spapadop)\
**Post date:** [December 14, 2020, 3:32pm UTC](https://forum.opensearch.org/t/proxy-auth-doesnt-work/4369/2 "2020-12-14T15:32:56Z")

</div>

According to the [documentation](https://opendistro.github.io/for-elasticsearch-docs/docs/security/configuration/proxy/#enable-proxy-authentication) seems like you should set `transport_enabled: true` within `proxy_auth_domain` configuration.

Hope this helps…

---

<div class="post-metadata">

**Author:** ![Anthony](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/anthony/32/9939_2.png) [@Anthony](https://forum.opensearch.org/u/Anthony)\
**Post date:** [February 17, 2021, 10:42am UTC](https://forum.opensearch.org/t/proxy-auth-doesnt-work/4369/3 "2021-02-17T10:42:46Z")

</div>

@roman Did you check if the proxy auth is working? Might be just a UI bug. Does it appear as enabled if both http and transport are enabled in config? I tried to reproduce, but using latest odfe 1.12.0 it works as expected, but I did enable both at the start and removed transport later.
