# Disabled xpack security plugin in Kibana 8

**URL:** <https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [April 28, 2023, 2:36pm UTC](https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065 "2023-04-28T14:36:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![pchakour](https://avatars.discourse-cdn.com/v4/letter/p/e36b37/32.png) [@pchakour](https://discuss.elastic.co/u/pchakour)\
**Post date:** [April 28, 2023, 2:36pm UTC](https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065/1 "2023-04-28T14:36:33Z")

</div>

Hello !

I want to migrate (from 7.16 to 8.6) my own plugin that manage Kibana security with a custom login page and a custom security strategy.

Unfortunately, I notice that the xpack.security.enabled configuration disapeared and I'm not able to disabled xpack.security anymore.

Is there an another way to disabled it ? If not, are we able to add a custom security strategy to the server ?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 28, 2023, 3:47pm UTC](https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065/2 "2023-04-28T15:47:57Z")

</div>

Perhaps take a look at this.

> [@Filebeat on local laptop does not talk to the Elasticsearch (also on local laptop) - dial tcp \[::1\]:9200: connect: cannot assign requested address](https://discuss.elastic.co/t/filebeat-on-local-laptop-does-not-talk-to-the-elasticsearch-also-on-local-laptop-dial-tcp-1-connect-cannot-assign-requested-address/317145/5):
>
> Alright, I finally managed to get a shiny new local setup up and running! Thank you Stephen for your suggestions! What I ended up doing is: -- downloaded and installed Elasticseach, Kibana and Filebeat, all of version 8.4.3 , all from gz archives -- before starting ES for the first time - updated its elasticsearch.yml - added the following settings (2 that Stephen suggested and one more I found online - for good measure slight_smile ): xpack.security.autoconfiguration.enabled: false xpack…

---

<div class="post-metadata">

**Author:** ![pchakour](https://avatars.discourse-cdn.com/v4/letter/p/e36b37/32.png) [@pchakour](https://discuss.elastic.co/u/pchakour)\
**Post date:** [April 28, 2023, 4:18pm UTC](https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065/3 "2023-04-28T16:18:52Z")

</div>

Nope, it's not working ☹

I took a look at the x-pack security code in Kibana. It seems to always add the security strategy to the Kibana server. The X-pack security strategy bypasses or authenticates the user depending on the license activation.

Since the security strategy has to be implemented only once and I can't deactivate the X-pack security strategy, I will try to use my own strategy in the "onPostAuth" lifecycle.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 28, 2023, 4:36pm UTC](https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065/4 "2023-04-28T16:36:42Z")

</div>

> [@pchakour](#):
>
> The X-pack security strategy bypasses or authenticates the user depending on the license activation.

Good luck you are in deeper than I am 🙂

As you get closer I would open a Topic with a Very Specific Subject line then perhaps we can get someone from Kibana to take a look.

---

<div class="post-metadata">

**Author:** ![pchakour](https://avatars.discourse-cdn.com/v4/letter/p/e36b37/32.png) [@pchakour](https://discuss.elastic.co/u/pchakour)\
**Post date:** [April 28, 2023, 4:51pm UTC](https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065/5 "2023-04-28T16:51:30Z")

</div>

OK, thank you!

I think many plugins depend on x-pack security, so it is probably be difficult to allow for a full disabling today.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 28, 2023, 4:55pm UTC](https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065/6 "2023-04-28T16:55:00Z")

</div>

Yes in general security is become more native / embedded... I think 8.X was a big shift there... as Elastic became secure OOTB...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2023, 4:55pm UTC](https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065/7 "2023-05-26T16:55:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
