1ebee5bf9b
This commit introduces PKI realm delegation. This feature supports the PKI authentication feature in Kibana. In essence, this creates a new API endpoint which Kibana must call to authenticate clients that use certificates in their TLS connection to Kibana. The API call passes to Elasticsearch the client's certificate chain. The response contains an access token to be further used to authenticate as the client. The client's certificates are validated by the PKI realms that have been explicitly configured to permit certificates from the proxy (Kibana). The user calling the delegation API must have the delegate_pki privilege. Closes #34396 |
||
---|---|---|
.. | ||
alias-privileges.asciidoc | ||
custom-authorization.asciidoc | ||
field-and-document-access-control.asciidoc | ||
managing-roles.asciidoc | ||
mapping-roles.asciidoc | ||
role-templates.asciidoc | ||
run-as-privilege.asciidoc | ||
set-security-user.asciidoc |