<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Do you support sig4 auth headers for AWS Elasticsearch?]]></title><description><![CDATA[<p dir="auto">Does FusionAuth support sig4 auth headers for an aws hosted elasticsearch domain?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/141/do-you-support-sig4-auth-headers-for-aws-elasticsearch</link><generator>RSS for Node</generator><lastBuildDate>Sun, 17 May 2026 20:53:24 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/141.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 03 Jun 2020 16:20:21 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Do you support sig4 auth headers for AWS Elasticsearch? on Wed, 03 Jun 2020 16:25:20 GMT]]></title><description><![CDATA[<p dir="auto">If you are using <a href="https://aws.amazon.com/elasticsearch-service/" rel="nofollow ugc">https://aws.amazon.com/elasticsearch-service/</a> for your Elasticsearch server, you can access it via AWS APIs and use IAM to control access: <a href="https://docs.aws.amazon.com/elasticsearch-service/latest/developerguide/es-ac.html" rel="nofollow ugc">https://docs.aws.amazon.com/elasticsearch-service/latest/developerguide/es-ac.html</a></p>
<p dir="auto">However, FusionAuth doesn't currently support the AWS signature for Elasticsearch requests.</p>
<p dir="auto">The recommended way of securing such clusters is to place it in a private subnet and restricting traffic to it using a security group. More information: <a href="https://fusionauth.io/docs/v1/tech/installation-guide/securing#fusionauth-search" rel="nofollow ugc">https://fusionauth.io/docs/v1/tech/installation-guide/securing#fusionauth-search</a></p>
<p dir="auto">If you have to make it public to make it accessible to resources outside if AWS you could use a source IP lock, a VPN, basic auth if AWS supports it, or you could proxy the request perhaps to another endpoint that can build the AWS sig v4 header.</p>
]]></description><link>https://fusionauth.io/community/forum/post/330</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/330</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Wed, 03 Jun 2020 16:25:20 GMT</pubDate></item></channel></rss>