License expiration for security features #74646
Labels
enhancement
New value added to drive a business result
Feature:License
Team:Security
Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more!
Many of our security features are available for free under Elastic's Basic License, but some of the more complex or esoteric features are only available under a paid license.
We have historically been lenient at best, and inconsistent at worst when licenses expire. We should research and remediate any shortcomings we have with respect to license enforcement. Specifically:
a) User Management
b) Role Management, without sub-feature privileges
c) Authentication via our
basic
andtoken
auth providersa) Paid authentication providers (SAML, OIDC, Kerberos, PKI). It might suffice to rely on Elasticsearch for this check, although a better UX would be to mark them as disabled in the
access agreementlogin selector UI. See also Better error handling when SAML realm is not available under current license #60337, SAML config - error message displayed when a license which is any less than platinum is applied, can be improved. #34592b) Access Agreement UI: should no longer be part of the login flow
c) Sub-feature privileges: should no longer be configurable. I believe this is already resolved, just mentioning it for completeness
d) Role Mappings UI: should no longer be visible under the Stack Management application. I believe this is already resolved, just mentioning it for completeness
The text was updated successfully, but these errors were encountered: