# Authentication of \[kibana\_system\] was terminated by realm \[reserved\] - failed to authenticate user \[kibana\_system\]

**URL:** <https://discuss.elastic.co/t/authentication-of-kibana-system-was-terminated-by-realm-reserved-failed-to-authenticate-user-kibana-system/285399>\
**Category:** Kibana\
**Tags:** elastic-stack-security, docker\
**Created:** [September 28, 2021, 6:04pm UTC](https://discuss.elastic.co/t/authentication-of-kibana-system-was-terminated-by-realm-reserved-failed-to-authenticate-user-kibana-system/285399 "2021-09-28T18:04:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dominique.bejean](https://avatars.discourse-cdn.com/v4/letter/d/dc4da7/32.png) [@dominique.bejean](https://discuss.elastic.co/u/dominique.bejean)\
**Post date:** [September 28, 2021, 6:04pm UTC](https://discuss.elastic.co/t/authentication-of-kibana-system-was-terminated-by-realm-reserved-failed-to-authenticate-user-kibana-system/285399/1 "2021-09-28T18:04:05Z")

</div>

Hi,

I am testing elsatistack 7.14.1 security in a docker-compose stack by following this documentation

> **[Running the Elastic Stack on Docker | Getting Started \[7.15\] | Elastic](https://www.elastic.co/guide/en/elastic-stack-get-started/current/get-started-docker.html)**

From the Kibana server, the following resquest works perfectly

`# curl --user kibana_system:xxxxxxxxxxxxxxxxxxxxx --cert config/certificats/kibana/kibana.crt --key config/certificats/kibana/kibana.key --cacert config/certificats/ca/ca.crt https:///es1:9200`

I can also acces and authenticate to ES with the elastic user with a browser.

However, Kibana fails to start with the following errors in logs

`es1_1 | [2021-09-28T16:47:24,076][INFO][o.e.x.s.a.AuthenticationService] [es1] Authentication of [kibana_system] was terminated by realm [reserved] - failed to authenticate user [kibana_system]`

`kibana_1 | {"type":"log","@timestamp":"2021-09-28T16:47:24+00:00","tags":["error","savedobjects-service"],"pid":19,"message":"Unable to retrieve version information from Elasticsearch nodes. security_exception: [security_exception] Reason: unable to authenticate user [kibana_system] for REST request [/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip]"}`

Does somebody has any ideas what can cause this issue ?

I found some threads about similar issues but without real solution.

Regards

Dominique

---

<div class="post-metadata">

**Author:** ![dominique.bejean](https://avatars.discourse-cdn.com/v4/letter/d/dc4da7/32.png) [@dominique.bejean](https://discuss.elastic.co/u/dominique.bejean)\
**Post date:** [September 29, 2021, 9:03am UTC](https://discuss.elastic.co/t/authentication-of-kibana-system-was-terminated-by-realm-reserved-failed-to-authenticate-user-kibana-system/285399/2 "2021-09-29T09:03:16Z")

</div>

Hi,

It looks like it is a ssl certificat issue due to not matching IP.  
I fixed the problem by assigning fixed IP to my containers and add container's IPs in the instances.yml file.

Dominique

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 27, 2021, 9:04am UTC](https://discuss.elastic.co/t/authentication-of-kibana-system-was-terminated-by-realm-reserved-failed-to-authenticate-user-kibana-system/285399/3 "2021-10-27T09:04:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
