Content Security Policy

i keep getting content-security-policy error while loading kibana in browser, so i put
csp.strict: false in my kibana.yml file but problem still remains.
Should i use csp.rules ?

Kibana version 7.3.0
OS: Ubuntu 18
browser: Chrome, Firefox

i am intended to run kibana on subdomain.

exact error:

kibana:1 Refused to load the script '' because it violates the following Content Security Policy directive: "script-src 'unsafe-eval' 'nonce-+ua1j/YIhocrsxxB'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.

How can i fix this ?

Interesting. I can ping our security folks, but first, you say you intended to run Kibana on a subdomain. I'm assuming the subdomain of the failing script matches the subdomain that Kibana is hosted on?


Hi chris, yes, it is on a VM that my subdomain pointed to. in fact, this is on local machine with local ip address which is accessible by a load balancer from outside through subdomain.