# Question: Are the authc authentication domain names used in the security plugins config.yml arbitrary strings?

**URL:** <https://forum.opensearch.org/t/question-are-the-authc-authentication-domain-names-used-in-the-security-plugins-config-yml-arbitrary-strings/22066>\
**Category:** OpenSearch\
**Tags:** discuss, documentation\
**Created:** [October 23, 2024, 8:38pm UTC](https://forum.opensearch.org/t/question-are-the-authc-authentication-domain-names-used-in-the-security-plugins-config-yml-arbitrary-strings/22066 "2024-10-23T20:38:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jaimie.livingston](https://avatars.discourse-cdn.com/v4/letter/j/f05b48/32.png) [@jaimie.livingston](https://forum.opensearch.org/u/jaimie.livingston)\
**Post date:** [October 23, 2024, 8:38pm UTC](https://forum.opensearch.org/t/question-are-the-authc-authentication-domain-names-used-in-the-security-plugins-config-yml-arbitrary-strings/22066/1 "2024-10-23T20:38:42Z")

</div>

**Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):  
Any

**Describe the issue** :

General Question:

Are the authc authentication domain names used in the security plugins config.yml arbitrary strings?  
The documentation is not clear. I suspect these are arbitrary strings, but I don’t want to make the assumption.

> **[Configuring the Security backend](https://opensearch.org/docs/latest/security/configuration/configuration/#authentication)**
>
> Configuring the Security backend

We’ve been using the domain name `internal_users_domain` in the `authc` configuration since since v2.0, but the v2.17 example configuration in github uses `basic_internal_auth_domain` where I would expect to see `internal_users_domain`. (Yes, I’m just noticing this. The config I’m using has been working for a good long while, and I haven’t had need to revisit it until now.)

> <https://github.com/opensearch-project/security/blob/main/config/config.yml#L101>

**Configuration** :  
security plugin, config.yml, `authc` section.

**Relevant Logs or Screenshots** :  
not applicable

---

<div class="post-metadata">

**Author:** ![Mantas](https://avatars.discourse-cdn.com/v4/letter/m/7bcc69/32.png) [@Mantas](https://forum.opensearch.org/u/Mantas)\
**Post date:** [October 24, 2024, 12:18pm UTC](https://forum.opensearch.org/t/question-are-the-authc-authentication-domain-names-used-in-the-security-plugins-config-yml-arbitrary-strings/22066/2 "2024-10-24T12:18:21Z")

</div>

Hi @jaimie.livingston,

I would assume so - you can call it whatever you want as long as the `type` is correct, to illustrate here is the setup from my lab:

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/d/dd6200b8caf257dc329d2a2b1fbb3315f2b075ea.png)

Best,  
mj

---

<div class="post-metadata">

**Author:** ![jaimie.livingston](https://avatars.discourse-cdn.com/v4/letter/j/f05b48/32.png) [@jaimie.livingston](https://forum.opensearch.org/u/jaimie.livingston)\
**Post date:** [October 24, 2024, 3:56pm UTC](https://forum.opensearch.org/t/question-are-the-authc-authentication-domain-names-used-in-the-security-plugins-config-yml-arbitrary-strings/22066/3 "2024-10-24T15:56:09Z")

</div>

Thanks for the confirmation.  
I suspected as much, but didn’t have an immediate way of testing this.

~Jaimie
