# Basic Authentication of ES without X-Pack

**URL:** <https://discuss.elastic.co/t/basic-authentication-of-es-without-x-pack/94840>\
**Category:** Elasticsearch\
**Created:** [July 27, 2017, 4:34pm UTC](https://discuss.elastic.co/t/basic-authentication-of-es-without-x-pack/94840 "2017-07-27T16:34:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![smlbiobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smlbiobot/32/29622_2.png) [@smlbiobot](https://discuss.elastic.co/u/smlbiobot)\
**Post date:** [July 27, 2017, 4:34pm UTC](https://discuss.elastic.co/t/basic-authentication-of-es-without-x-pack/94840/1 "2017-07-27T16:34:00Z")

</div>

I was told that it is possible to do basic authentication of ElasticSearch without installing X-Pack, but I don’t see an option for it. Can you let me know how I can set it up with a simple u/p combo?

Thanks!

---

<div class="post-metadata">

**Author:** ![shanec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanec/32/4004_2.png) [@shanec](https://discuss.elastic.co/u/shanec)\
**Post date:** [July 27, 2017, 4:40pm UTC](https://discuss.elastic.co/t/basic-authentication-of-es-without-x-pack/94840/2 "2017-07-27T16:40:23Z")

</div>

X-Pack is the only official and recommended way to secure your Elasticsearch cluster. Occasionally we see people set up a reverse proxy external to Elasticsearch with username/password authentication, but that does only provide edge security (and nothing else really).

---

<div class="post-metadata">

**Author:** ![smlbiobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smlbiobot/32/29622_2.png) [@smlbiobot](https://discuss.elastic.co/u/smlbiobot)\
**Post date:** [July 27, 2017, 5:33pm UTC](https://discuss.elastic.co/t/basic-authentication-of-es-without-x-pack/94840/3 "2017-07-27T17:33:43Z")

</div>

Right so I was right then? Someone on the Elastic Team told me otherwise and I wonder why…

Or… it could be Kibana perhaps? Can you setup Kibana with basic authentication without x-pack?

---

<div class="post-metadata">

**Author:** ![shanec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanec/32/4004_2.png) [@shanec](https://discuss.elastic.co/u/shanec)\
**Post date:** [July 27, 2017, 5:36pm UTC](https://discuss.elastic.co/t/basic-authentication-of-es-without-x-pack/94840/4 "2017-07-27T17:36:32Z")

</div>

Kibana doesn't have any built in authentication either. X-Pack provides that.

On [https://www.elastic.co/subscriptions](https://www.elastic.co/subscriptions) we outline what comes with each subscription level. You can have a look at the "Open Source" vs the Gold/Platinum columns and see that native authentication, encrypted communications, and role based access control are in X-Pack rather than open source.

---

<div class="post-metadata">

**Author:** ![Dan\_Markhasin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dan_markhasin/32/14187_2.png) [@Dan\_Markhasin](https://discuss.elastic.co/u/Dan_Markhasin)\
**Post date:** [July 28, 2017, 3:20pm UTC](https://discuss.elastic.co/t/basic-authentication-of-es-without-x-pack/94840/5 "2017-07-28T15:20:54Z")

</div>

Using NGINX as a reverse proxy is a common practice for securing ElasticSearch with basic authentication, though it is difficult to achieve higher granularity than that (while you can construct a configuration that would limit access to specific URL patterns with specific HTTP methods to specific groups, it's not scalable and hard to maintain).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2017, 3:21pm UTC](https://discuss.elastic.co/t/basic-authentication-of-es-without-x-pack/94840/6 "2017-08-25T15:21:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
