|
|
|
|
|
by rieTohgh6
1271 days ago
|
|
Almost all security issues with ES stem from their idea to keep authorization as separate, paid product (X-pack). On other other hand MongoDB had similar issues since they wanted to their product to be easy to setup and use, maybe for people scarred of pg_hba.conf. |
|
You get authorization in the free offering and that's been the case for the least two major versions.
The things you need to pay for are IMHO not hobby project stuff, like integration with LDAP/AD.
You are of course correct that this used to be the case, and that to some extend this sentiment prevails.
But I feel Elastic (the company) deserves credit for acknowledging the issue and addressing it.