OpenSearch/x-pack/docs/en/security/authorization
Albert Zaharovits 1ebee5bf9b
PKI realm authentication delegation (#45906)
This commit introduces PKI realm delegation. This feature
supports the PKI authentication feature in Kibana.

In essence, this creates a new API endpoint which Kibana must
call to authenticate clients that use certificates in their TLS
connection to Kibana. The API call passes to Elasticsearch the client's
certificate chain. The response contains an access token to be further
used to authenticate as the client. The client's certificates are validated
by the PKI realms that have been explicitly configured to permit
certificates from the proxy (Kibana). The user calling the delegation
API must have the delegate_pki privilege.

Closes #34396
2019-08-27 14:42:46 +03:00
..
alias-privileges.asciidoc Remove remaining occurances of "include_type_name=true" in docs (#37646) 2019-01-22 15:13:52 +01:00
custom-authorization.asciidoc Correct documentation link for authorization engine example (#40261) (#40292) 2019-03-22 12:38:03 +11:00
field-and-document-access-control.asciidoc Clarify that FLS/DLS disable shard request cache (#45462) 2019-08-13 09:05:57 -04:00
managing-roles.asciidoc Update managing-roles.asciidoc 2019-03-19 08:21:29 -07:00
mapping-roles.asciidoc PKI realm authentication delegation (#45906) 2019-08-27 14:42:46 +03:00
role-templates.asciidoc Deprecate /_xpack/security/* in favor of /_security/* (#36293) 2018-12-11 11:13:10 +02:00
run-as-privilege.asciidoc [DOCS] Update X-Pack terminology in security docs (#36564) 2018-12-19 14:53:37 -08:00
set-security-user.asciidoc ingest: raise visibility of ingest plugin documentation (#35048) 2018-11-05 11:44:10 -06:00