From f092dc34f5fcbde6f7b8793c1f200e5803426365 Mon Sep 17 00:00:00 2001 From: Manuel Gutierrez <1380243+xr09@users.noreply.github.com> Date: Fri, 14 Aug 2020 16:34:44 +0200 Subject: [PATCH 1/2] Force basic auth --- roles/elastic-stack/ansible-elasticsearch/tasks/main.yml | 2 ++ 1 file changed, 2 insertions(+) mode change 100644 => 100755 roles/elastic-stack/ansible-elasticsearch/tasks/main.yml diff --git a/roles/elastic-stack/ansible-elasticsearch/tasks/main.yml b/roles/elastic-stack/ansible-elasticsearch/tasks/main.yml old mode 100644 new mode 100755 index d74a391b..7c453bad --- a/roles/elastic-stack/ansible-elasticsearch/tasks/main.yml +++ b/roles/elastic-stack/ansible-elasticsearch/tasks/main.yml @@ -128,6 +128,7 @@ validate_certs: no status_code: 200,401 return_content: yes + force_basic_auth: yes timeout: 4 register: _result until: ( _result.json is defined) and (_result.json.status == "green") @@ -145,6 +146,7 @@ password: "{{ elasticsearch_xpack_security_password }}" body: '{ "password" : "{{ item.value["password"] }}", "roles" : {{ item.value["roles"] }} }' validate_certs: no + force_basic_auth: yes loop: "{{ elasticsearch_xpack_users|default({})|dict2items }}" register: http_response failed_when: http_response.status != 200 From 87ad1cdfaf49eef2754861fc816b769af959e146 Mon Sep 17 00:00:00 2001 From: Manuel Gutierrez <1380243+xr09@users.noreply.github.com> Date: Fri, 14 Aug 2020 17:02:11 +0200 Subject: [PATCH 2/2] Basic auth on kibana role --- roles/elastic-stack/ansible-kibana/tasks/main.yml | 1 + 1 file changed, 1 insertion(+) mode change 100644 => 100755 roles/elastic-stack/ansible-kibana/tasks/main.yml diff --git a/roles/elastic-stack/ansible-kibana/tasks/main.yml b/roles/elastic-stack/ansible-kibana/tasks/main.yml old mode 100644 new mode 100755 index d2d06097..cf330640 --- a/roles/elastic-stack/ansible-kibana/tasks/main.yml +++ b/roles/elastic-stack/ansible-kibana/tasks/main.yml @@ -156,6 +156,7 @@ password: "{{ elasticsearch_xpack_security_password }}" validate_certs: no status_code: 200, 404 + force_basic_auth: yes - name: Create wazuh plugin config directory file: