# Auto authenticating to an embedded Kibana dashboard (on Elastic.co CLOUD)

**URL:** <https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248>\
**Category:** Kibana\
**Created:** [January 11, 2017, 3:52pm UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248 "2017-01-11T15:52:51Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gabriele](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriele/32/14515_2.png) [@Gabriele](https://discuss.elastic.co/u/Gabriele)\
**Post date:** [January 11, 2017, 3:52pm UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/1 "2017-01-11T15:52:51Z")

</div>

I have ElasticSearch 5.1 on **[Elastic.co](http://Elastic.co)** with a Kibana 5.1 dashboard that I'm embedding into a web app via iframe, protected by XPack authentication.  
Is there any way to programmatically provide the user/password so that the user automatically auths and the dashboard is displayed?

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [January 11, 2017, 4:48pm UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/2 "2017-01-11T16:48:39Z")

</div>

hi @Gabriele,

you can do this by passing the login information with a reverse-proxy.

See this thread for more information: [Auto-authenticating to iframe-embedded Kibana dashboard](https://discuss.elastic.co/t/auto-authenticating-to-iframe-embedded-kibana-dashboard/46091/4).

The example there uses nginx, but other platforms should support a similar setup.

---

<div class="post-metadata">

**Author:** ![Gabriele](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriele/32/14515_2.png) [@Gabriele](https://discuss.elastic.co/u/Gabriele)\
**Post date:** [January 11, 2017, 8:06pm UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/3 "2017-01-11T20:06:36Z")

</div>

@thomasneirynck since this is a known issue, you can not give a solution to avoid the cross domain problem, such as a GET API for the login in an embedded web-app , instead suggest the use of a proxy?

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [January 11, 2017, 9:26pm UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/4 "2017-01-11T21:26:22Z")

</div>

hi @Gabriele

Do I have it right, you want to be able to do this without a reverse proxy?

As for the CORS issue, that is generally resolved server-side as well (in this case, you would configure this in the reverse proxy too). You'll need to configure the server to allow requests from remote hosts.

You might be interested in this outstanding enhancement request too: [https://github.com/elastic/kibana/issues/4453](https://github.com/elastic/kibana/issues/4453). It calls for a more fine-grained access to Kibana-objects (e.g. a dashboard). Perhaps this is more in line with what you are looking for?

---

<div class="post-metadata">

**Author:** ![Gabriele](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriele/32/14515_2.png) [@Gabriele](https://discuss.elastic.co/u/Gabriele)\
**Post date:** [January 12, 2017, 8:30am UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/5 "2017-01-12T08:30:22Z")

</div>

Hi @thomasneirynck,

> As for the CORS issue, that is generally resolved server-side as well (in this case, you would configure this in the reverse proxy too). You'll need to configure the server to allow requests from remote hosts.

I do not think it's a possible solution using the [Elastic.co](http://Elastic.co) cloud service

> You might be interested in this outstanding enhancement request too: [[Infra UI] Use URL /infrastructure/metrics instead of /metrics by Zacqary · Pull Request #44532 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/44532). It calls for a more fine-grained access to Kibana-objects (e.g. a dashboard). Perhaps this is more in line with what you are looking for?

thank you, but it's not what I'm looking for

---

<div class="post-metadata">

**Author:** ![michele.pagnin](https://avatars.discourse-cdn.com/v4/letter/m/eada6e/32.png) [@michele.pagnin](https://discuss.elastic.co/u/michele.pagnin)\
**Post date:** [January 12, 2017, 11:16am UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/6 "2017-01-12T11:16:12Z")

</div>

Hi @thomasneirynck,

I've tried to use ngix as a reverse-proxy.  
But I had this error message:  
`{"ok":false,"message":"Unknown cluster."}`  
I'm using an [Elastic.co](http://Elastic.co) cloud instance.

Could you help me please?  
Thx

---

<div class="post-metadata">

**Author:** ![Cylindric](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cylindric/32/5660_2.png) [@Cylindric](https://discuss.elastic.co/u/Cylindric)\
**Post date:** [January 12, 2017, 11:20am UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/7 "2017-01-12T11:20:18Z")

</div>

@michele.pagnin you should probably post this as a separate issue, not tack it onto someone else's. You'll need to provide some information about what you've tried, I imagine, for anyone to be able to help.

---

<div class="post-metadata">

**Author:** ![michele.pagnin](https://avatars.discourse-cdn.com/v4/letter/m/eada6e/32.png) [@michele.pagnin](https://discuss.elastic.co/u/michele.pagnin)\
**Post date:** [January 12, 2017, 11:24am UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/8 "2017-01-12T11:24:25Z")

</div>

Hi @Cylindric  
@Gabriele and I are working for the same company and we have the same target.  
So, my request in this thread is correct

---

<div class="post-metadata">

**Author:** ![Cylindric](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cylindric/32/5660_2.png) [@Cylindric](https://discuss.elastic.co/u/Cylindric)\
**Post date:** [January 12, 2017, 11:40am UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/9 "2017-01-12T11:40:59Z")

</div>

Ah, you didn't make that clear. I think some information about what you've done to the nginx config will be required though/

---

<div class="post-metadata">

**Author:** ![michele.pagnin](https://avatars.discourse-cdn.com/v4/letter/m/eada6e/32.png) [@michele.pagnin](https://discuss.elastic.co/u/michele.pagnin)\
**Post date:** [January 12, 2017, 11:46am UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/10 "2017-01-12T11:46:13Z")

</div>

@Cylindric, as @thomasneirynck wrote, I have tryed to use nginx as reverse proxy.  
This is what I wrote in configuration file:  
server {  
listen 443;  
server\_name localhost;

```
	#root html;
	#index index.html index.htm;

	ssl on;
	ssl_certificate /etc/nginx/ssl/nginx.crt;
    ssl_certificate_key /etc/nginx/ssl/nginx.key;

	ssl_session_cache shared:SSL:1m;
	ssl_session_timeout 5m;

	#ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;
	#ssl_ciphers "HIGH:!aNULL:!MD5 or HIGH:!aNULL:!MD5:!3DES";
	ssl_ciphers HIGH:!aNULL:!MD5;
	ssl_prefer_server_ciphers on;

	location / {
         proxy_set_header Host $host;
         proxy_set_header X-Real-IP $remote_addr;
         proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
         proxy_set_header Authorization "Basic XXXXXXXXXXXXXXXXX";
         proxy_pass https://XXXXXXXXXXXXXX.eu-west-1.aws.found.io/app/kibana;
     }
}
```

---

<div class="post-metadata">

**Author:** ![Gabriele](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriele/32/14515_2.png) [@Gabriele](https://discuss.elastic.co/u/Gabriele)\
**Post date:** [January 12, 2017, 1:43pm UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/11 "2017-01-12T13:43:23Z")

</div>

@Cylindric, @thomasneirynck

Attention! We are using the application in the **[Elastic.co](http://Elastic.co) cloud**

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [January 17, 2017, 2:39pm UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/12 "2017-01-17T14:39:47Z")

</div>

@michele.pagnin

thanks,

not sure about that error message and how this would relate to the cloud cluster.

Do you get that when you are trying to visit any link to a Kibana-page? or just the embedded dashboard links?

---

<div class="post-metadata">

**Author:** ![michele.pagnin](https://avatars.discourse-cdn.com/v4/letter/m/eada6e/32.png) [@michele.pagnin](https://discuss.elastic.co/u/michele.pagnin)\
**Post date:** [January 18, 2017, 9:52am UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/13 "2017-01-18T09:52:53Z")

</div>

@thomasneirynck

We have resolved the issue in the following way:

```
server {
	listen 443;
	server_name localhost;
	ssl on;
	ssl_certificate /etc/nginx/ssl/nginx.crt;
    ssl_certificate_key /etc/nginx/ssl/nginx.key;
	ssl_session_cache shared:SSL:1m;
	ssl_session_timeout 5m;
	ssl_ciphers HIGH:!aNULL:!MD5;
	ssl_prefer_server_ciphers on;

	location / {
	     proxy_set_header X-Found-Cluster XXXXXX;
         proxy_set_header Host $host;
         proxy_set_header X-Real-IP $remote_addr;
         proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
         proxy_set_header Authorization "Basic YYYYYY";
         proxy_pass https://XXXXXX.eu-west-1.aws.found.io;
     }
}

```

Where XXXXXX is the cluster ID and YYYYYY is the string "username:password" encoded in base64.  
Thank to everyone for the support  
Bye

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2017, 9:53am UTC](https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/14 "2017-02-15T09:53:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
