# Elastic Search Basic Authentication

**URL:** <https://discuss.elastic.co/t/elastic-search-basic-authentication/153839>\
**Category:** Kibana\
**Created:** [October 24, 2018, 3:21pm UTC](https://discuss.elastic.co/t/elastic-search-basic-authentication/153839 "2018-10-24T15:21:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rifat\_Erdem\_Sahin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rifat_erdem_sahin/32/36560_2.png) [@Rifat\_Erdem\_Sahin](https://discuss.elastic.co/u/Rifat_Erdem_Sahin)\
**Post date:** [October 24, 2018, 3:21pm UTC](https://discuss.elastic.co/t/elastic-search-basic-authentication/153839/1 "2018-10-24T15:21:27Z")

</div>

After reading below i have decided to implement custom headers. I do not have x-pack security installed. Need a sample implementation as adding this did not sort out my issues

added this to kibana.yml  
elasticsearch.customHeaders: { Authorization: Basic base64encoded un:pw }

**##Option 2 - Kibana customHeaders**  
This solution is very similar to Option 1. Using the elasticsearch.customHeaders setting in the kibana.yml you can pass the same Basic Auth headers to Elasticsearch on every request. However, you'll have to disable X-Pack Security in Kibana for this option to work.  
This solution doesn't require a reverse proxy; however, you will be forced to use Kibana as the same user, and disable X-Pack Security.

**Reference**

> [@Kibana default basic auth](https://discuss.elastic.co/t/kibana-default-basic-auth/86045/2):
>
> @ccrecana this behavior has been changed in 5.2.0, as this wasn't an intentional behavior. There are a few options to do what you're looking for, but first it might help to explain a bit of the background/details of Kibana/Elasticsearch auth. The way that authentication/authorization works with Elasticsearch via Kibana is two-fold. There is an internal user that Kibana uses to setup the initial .kibana index, the reporting queue, and various administrative features which is controlled by settin…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2018, 3:21pm UTC](https://discuss.elastic.co/t/elastic-search-basic-authentication/153839/2 "2018-11-21T15:21:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
