# Authentication issues while xpack security enabling - Elasticsearch version 7.7

**URL:** <https://discuss.elastic.co/t/authentication-issues-while-xpack-security-enabling-elasticsearch-version-7-7/233555>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 20, 2020, 2:26pm UTC](https://discuss.elastic.co/t/authentication-issues-while-xpack-security-enabling-elasticsearch-version-7-7/233555 "2020-05-20T14:26:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![tryelk](https://avatars.discourse-cdn.com/v4/letter/t/b2d939/32.png) [@tryelk](https://discuss.elastic.co/u/tryelk)\
**Post date:** [May 20, 2020, 2:26pm UTC](https://discuss.elastic.co/t/authentication-issues-while-xpack-security-enabling-elasticsearch-version-7-7/233555/1 "2020-05-20T14:26:26Z")

</div>

Hello,

I'm having issues setting up security for a fresh install of ES.  
The issue is after enabling xpack.security on the elasticsearch.yml and starting the ES service, then executing for example:

" curl --insecure -X GET [http://suelastic501.ritta.local:9200/\_cluster/health?pretty](http://suelastic501.ritta.local:9200/_cluster/health?pretty)"

Which return the following errors:

```auto
* "error" : {*
* "root_cause" : [*
* {*
* "type" : "security_exception",*
* "reason" : "missing authentication credentials for REST request [/_cluster/health?pretty]",*
* "header" : {*
* "WWW-Authenticate" : "Basic realm=\"security\" charset=\"UTF-8\""*
* }*
* }*
* ],*
* "type" : "security_exception",*
* "reason" : "missing authentication credentials for REST request [/_cluster/health?pretty]",*
* "header" : {*
* "WWW-Authenticate" : "Basic realm=\"security\" charset=\"UTF-8\""*
* }*
* },*
* "status" : 401*
*}*

```

**Scenario:**  
2 VMs running ES service - RHEL 8  
1 VM with Kibana - RHEL 8

I following the steps described in : [https://www.elastic.co/blog/getting-started-with-elasticsearch-security](https://www.elastic.co/blog/getting-started-with-elasticsearch-security)

I can't execute the " Step 2: Elasticsearch cluster passwords" from the previously " from the previously link.

**Information from my setup:**

**1.** Running ES with Basic support - installed following the link : [https://www.elastic.co/guide/en/elasticsearch/reference/current/rpm.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/rpm.html)

**2.** My config/elasticsearch.yaml has the following data:  
xpack.security.enabled: true  
xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12  
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

**3.** Already generated and prepared certificates

**4.** When executing "/usr/share/elasticsearch/bin/elasticsearch-setup-passwords auto" , i'm getting the following error.

```auto
*Failed to determine the health of the cluster running at http://10.191.37.94:9200*
*Unexpected response code [503] from calling GET http://10.191.37.94:9200/_cluster/health?pretty*
*Cause: master_not_discovered_exception*

*It is recommended that you resolve the issues with your cluster before running elasticsearch-setup-passwords.*
*It is very likely that the password changes will fail when run against an unhealthy cluster.*

*Do you want to continue with the password setup process [y/N]*

```

Anyone got any ideas how to solve this issue ?

Thanks a lot,

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 21, 2020, 5:48am UTC](https://discuss.elastic.co/t/authentication-issues-while-xpack-security-enabling-elasticsearch-version-7-7/233555/2 "2020-05-21T05:48:22Z")

</div>

> [@tryelk](#):
>
> then executing for example:
> 
> " curl --insecure -X GET [http://suelastic501.ritta.local:9200/\_cluster/health?pretty](http://suelastic501.ritta.local:9200/_cluster/health?pretty)"
> 
> Which return the following errors:

You are not passing in a username and password so elasticsearch cant authenticate you.

> [@tryelk](#):
>
> Already generated and prepared certificates

How, _exactly_ ?

> [@tryelk](#):
>
> When executing "/usr/share/elasticsearch/bin/elasticsearch-setup-passwords auto" , i'm getting the following error.

As the error message says you cant execute that command because your cluster is unhealthy. Please check your elasticsearch logs ,the reason why your cluster cant form ,will be in there

---

<div class="post-metadata">

**Author:** ![tryelk](https://avatars.discourse-cdn.com/v4/letter/t/b2d939/32.png) [@tryelk](https://discuss.elastic.co/u/tryelk)\
**Post date:** [May 21, 2020, 8:14am UTC](https://discuss.elastic.co/t/authentication-issues-while-xpack-security-enabling-elasticsearch-version-7-7/233555/3 "2020-05-21T08:14:57Z")

</div>

Hello ikakavas,

Thank you for your reply 🙂 .

After some more digging, i found the issue.  
We need to make sure the cluster Health in terms of communication with the other cluster members are working OK, otherwise we can't run the command to generate the passwords for built-in users.

So, my issue was with the certificates on my other cluster node. After the communication between the clusters using xpack was working fine, i was able to run the command to generate the password successfully.

Best Regards,

---

<div class="post-metadata">

**Author:** ![tryelk](https://avatars.discourse-cdn.com/v4/letter/t/b2d939/32.png) [@tryelk](https://discuss.elastic.co/u/tryelk)\
**Post date:** [May 21, 2020, 10:56am UTC](https://discuss.elastic.co/t/authentication-issues-while-xpack-security-enabling-elasticsearch-version-7-7/233555/4 "2020-05-21T10:56:23Z")

</div>

Hello,

Well now i'm having issues logging to kibana URL.  
I'm getting error 404 Not Found on the Browser.

I'm using the user elastic and the password generated from the "elasticsearch-setup-passwords auto" command.

Also changed the kibana.yml config and added kibana user and password:  
elasticsearch.username: "kibana"  
elasticsearch.password: "\*\*\*\*"

Isn't elastic the default user for the kibana Web Console ?

Best Regards,

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 21, 2020, 11:01am UTC](https://discuss.elastic.co/t/authentication-issues-while-xpack-security-enabling-elasticsearch-version-7-7/233555/5 "2020-05-21T11:01:59Z")

</div>

> [@tryelk](#):
>
> Well now i'm having issues logging to kibana URL.  
> I'm getting error 404 Not Found on the Browser.

This doesnt sound like an authentication issue. Van you please explain in detail what you are trying to do and the _exact_ error you get ?

---

<div class="post-metadata">

**Author:** ![tryelk](https://avatars.discourse-cdn.com/v4/letter/t/b2d939/32.png) [@tryelk](https://discuss.elastic.co/u/tryelk)\
**Post date:** [May 21, 2020, 11:18am UTC](https://discuss.elastic.co/t/authentication-issues-while-xpack-security-enabling-elasticsearch-version-7-7/233555/6 "2020-05-21T11:18:13Z")

</div>

> Blockquote This doesnt sound like an authentication issue. Van you please explain in detail what you are trying to do and the _exact_ error you get ?

So, i just configured xpack on the ES cluster, generated the passwords automatically, then confgiured kibana.yml with the kibana user and password.

Next step was trying to login to kibana GUI.  
http://:5601/app/kibana

The GUI asks for a user and password and when i enter the user and password i'm getting error "404 not found".

I'm using "elastic" user and the automatically generated password.

Example:

 ![kibana_gui_login_error](https://us1.discourse-cdn.com/elastic/original/3X/5/1/51224d6b852fb2db43ca28dabbaf1a072e5280b6.png)

Best Regards,

---

<div class="post-metadata">

**Author:** ![tryelk](https://avatars.discourse-cdn.com/v4/letter/t/b2d939/32.png) [@tryelk](https://discuss.elastic.co/u/tryelk)\
**Post date:** [May 21, 2020, 11:33am UTC](https://discuss.elastic.co/t/authentication-issues-while-xpack-security-enabling-elasticsearch-version-7-7/233555/7 "2020-05-21T11:33:53Z")

</div>

Hello,

Additional info:

On kibana logs i'm getting the following when performing the login:

```auto
{"type":"log","@timestamp":"2020-05-21T11:30:34Z","tags":["debug","plugins","security","basic","basic"],"pid":10502,"message":"Trying to authenticate user request to /app/kibana."}
{"type":"log","@timestamp":"2020-05-21T11:30:34Z","tags":["debug","plugins","security","basic","basic"],"pid":10502,"message":"Cannot authenticate requests with `Authorization` header."}
{"type":"log","@timestamp":"2020-05-21T11:30:34Z","tags":["debug","plugins","security","http"],"pid":10502,"message":"Trying to authenticate user request to /app/kibana."}
{"type":"log","@timestamp":"2020-05-21T11:30:34Z","tags":["debug","plugins","security","http"],"pid":10502,"message":"Request to /app/kibana has been authenticated via authorization header with \"Basic\" scheme."}
{"type":"log","@timestamp":"2020-05-21T11:30:34Z","tags":["debug","plugins","security","app-authorization"],"pid":10502,"message":"authorizing access to \"kibana\""}
{"type":"log","@timestamp":"2020-05-21T11:30:34Z","tags":["debug","plugins","security","app-authorization"],"pid":10502,"message":"not authorized for \"kibana\""}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 18, 2020, 11:34am UTC](https://discuss.elastic.co/t/authentication-issues-while-xpack-security-enabling-elasticsearch-version-7-7/233555/8 "2020-06-18T11:34:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
