# Dgraph Security Control

**URL:** <https://discuss.dgraph.io/t/dgraph-security-control/18411>\
**Category:** Dgraph\
**Created:** [March 22, 2023, 10:21am UTC](https://discuss.dgraph.io/t/dgraph-security-control/18411 "2023-03-22T10:21:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lukel](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/lukel/32/10314_2.png) [@lukel](https://discuss.dgraph.io/u/lukel)\
**Post date:** [March 22, 2023, 10:21am UTC](https://discuss.dgraph.io/t/dgraph-security-control/18411/1 "2023-03-22T10:21:52Z")

</div>

Hello,  
I like to use dgraph at work, and now I have some security issues, please support

1. How to set the login password, we need to deploy a production environment, so we need a strong password  

2. How to create a read-only account. As you can see, any user can enter query and mute and modify the schema. I need to restrict ordinary users to only query  

 ![89Tci9TW4J](https://canada1.discourse-cdn.com/flex007/uploads/dgraph/original/2X/4/4cf3017cb749a5354b69019ed2d09303471a18bb.jpeg)

In addition, is the acl only available in the enterprise version?

---

<div class="post-metadata">

**Author:** ![amanmangal](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/amanmangal/32/1249_2.png) [@amanmangal](https://discuss.dgraph.io/u/amanmangal)\
**Post date:** [March 22, 2023, 7:54pm UTC](https://discuss.dgraph.io/t/dgraph-security-control/18411/2 "2023-03-22T19:54:40Z")

</div>

yes, ACL is an enterprise feature. Either you will have to use Dgraph Cloud or get an Enterprise Support contract.

---

<div class="post-metadata">

**Author:** ![lukel](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/lukel/32/10314_2.png) [@lukel](https://discuss.dgraph.io/u/lukel)\
**Post date:** [March 23, 2023, 1:53am UTC](https://discuss.dgraph.io/t/dgraph-security-control/18411/3 "2023-03-23T01:53:01Z")

</div>

ok thanks.How about my question one.Can the open source version change the default login password

---

<div class="post-metadata">

**Author:** ![MichelDiz](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/micheldiz/32/11873_2.png) [@MichelDiz](https://discuss.dgraph.io/u/MichelDiz)\
**Post date:** [March 23, 2023, 2:19am UTC](https://discuss.dgraph.io/t/dgraph-security-control/18411/4 "2023-03-23T02:19:47Z")

</div>

Options for the community version:

You can use [TLS Configuration - Dgraph](https://dgraph.io/docs/deploy/security/tls-configuration/) - With TLS only those clients with the cert will be able to access.

You can also set a token

```auto
--security string Security options
 token=; If set, all Admin requests to Dgraph will need to have this token. 
The token can be passed as follows: for HTTP requests, in the X-Dgraph-AuthToken header. 
For Grpc, in auth-token key in the context.

```

With this all clients have to pass that token(custom token, AKA Poor Man’s ACL)

> [@lukel](#):
>
> I tried to change password as [access-control](http://discuss.hypermode.com/t/access-control-lists-enterprise-features/9801) but got an error

You are trying to execute a GraphQL mutation in Ratel. Ratel does not support GraphQL. Hence the error. You should the Admin run query/mutation it via cURL or a GraphQL client.

# Important

Never expose your database in public. Always create an API and put it behind a firewall. Your back-end should be the one that controls the DB access.

> [@lukel](#):
>
> Can the open source version change the default login password

No, ACL is EE.

If you are confused by the Login part in Ratel. Don’t worry, you don’t need to log in to the community version.

---

<div class="post-metadata">

**Author:** ![lukel](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/lukel/32/10314_2.png) [@lukel](https://discuss.dgraph.io/u/lukel)\
**Post date:** [March 23, 2023, 4:00am UTC](https://discuss.dgraph.io/t/dgraph-security-control/18411/5 "2023-03-23T04:00:06Z")

</div>

Thanks, I have successfully configured tls. Later, if I need to strengthen authority control, I will consider purchasing the enterprise version
