# Question about the On-Behalf-Of feature

**URL:** <https://forum.opensearch.org/t/question-about-the-on-behalf-of-feature/26556>\
**Category:** Security\
**Created:** [August 29, 2025, 4:22pm UTC](https://forum.opensearch.org/t/question-about-the-on-behalf-of-feature/26556 "2025-08-29T16:22:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![asfoorial](https://avatars.discourse-cdn.com/v4/letter/a/3da27b/32.png) [@asfoorial](https://forum.opensearch.org/u/asfoorial)\
**Post date:** [August 29, 2025, 4:22pm UTC](https://forum.opensearch.org/t/question-about-the-on-behalf-of-feature/26556/1 "2025-08-29T16:22:52Z")

</div>

**Hi all,**

I highly appreciate explanation on the below in docs of On-Behalf-Of feature. Aren’t the signing and encryption keys distributed to all nodes automatically sine they are set as part of config.yml (security index) which is expected to be visible to all nodes?

“Both the signing key and the encryption key are base64 encoded and stored on the OpenSearch node’s file system. The keys should be the same on all hosts.”

> **[Authorization tokens](https://docs.opensearch.org/latest/security/access-control/authentication-tokens/)**
>
> Authorization tokens

---

<div class="post-metadata">

**Author:** ![Anthony](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/anthony/32/9939_2.png) [@Anthony](https://forum.opensearch.org/u/Anthony)\
**Post date:** [September 1, 2025, 9:51am UTC](https://forum.opensearch.org/t/question-about-the-on-behalf-of-feature/26556/2 "2025-09-01T09:51:15Z")

</div>

@asfoorial yes, you are correct, The configuration is stored in security index and is not needed to be present in the filesystem. The docs will be updated shortly.
