2019-10-04 11:19:10 -04:00
|
|
|
[role="xpack"]
|
|
|
|
[[pki-realm]]
|
|
|
|
=== PKI user authentication
|
|
|
|
|
2019-11-19 13:29:20 -05:00
|
|
|
You can configure {es} to use Public Key Infrastructure (PKI) certificates to
|
|
|
|
authenticate users. This requires clients connecting directly to {es} to
|
|
|
|
present X.509 certificates. The certificates must first be accepted for
|
|
|
|
authentication on the SSL/TLS layer on {es}. Only then they are optionally
|
|
|
|
further validated by a PKI realm. See <<pki-realm-for-direct-clients>>.
|
2019-10-04 11:19:10 -04:00
|
|
|
|
2019-11-19 13:29:20 -05:00
|
|
|
You can also use PKI certificates to authenticate to {kib}, however this
|
|
|
|
requires some additional configuration. On {es}, this configuration enables {kib}
|
|
|
|
to act as a proxy for SSL/TLS authentication and to submit the client
|
|
|
|
certificates to {es} for further validation by a PKI realm. See
|
|
|
|
<<pki-realm-for-proxied-clients>>.
|
2019-10-04 11:19:10 -04:00
|
|
|
|
2019-11-19 13:29:20 -05:00
|
|
|
include::configuring-pki-realm.asciidoc[]
|