# Elasticsearch authentication failed error

**URL:** <https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 16, 2016, 5:47am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952 "2016-06-16T05:47:12Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajoealex](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@ajoealex](https://discuss.elastic.co/u/ajoealex)\
**Post date:** [June 16, 2016, 5:47am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/1 "2016-06-16T05:47:12Z")

</div>

I am using elasticsearch 2.3.3 , kibana 4.5 and shield for both. I set up everything in kibana.yml  
My kibana.yml file is pasted below. I am getting an error while running kibana.bat

**log [22:22:16.344] [error][status][plugin:elasticsearch] Status changed from yellow to red - Authentication Exception**  
I followed the steps as mentioned in[this](https://discuss.elastic.co/t/kibana-shield-configuration/45098) post. Can anyone please help?

# Kibana is served by a back end server. This controls which port to use.

server.port: 5601

# The host to bind the server to.

server.host: "0.0.0.0"

# If you are running kibana behind a proxy, and want to mount it at a path,

# specify that path here. The basePath can't end in a slash.

# server.basePath: ""

# The maximum payload size in bytes on incoming server requests.

# server.maxPayloadBytes: 1048576

# The Elasticsearch instance to use for all your queries.

elasticsearch.url: "[http://es\_admin:Test1234@localhost:9200](http://es_admin:Test1234@localhost:9200)"

# preserve\_elasticsearch\_host true will send the hostname specified in `elasticsearch`. If you set it to false,

# then the host you use to connect to _this_ Kibana instance will be sent.

# elasticsearch.preserveHost: true

# Kibana uses an index in Elasticsearch to store saved searches, visualizations

# and dashboards. It will create a new index if it doesn't already exist.

kibana.index: ".kibana"

# The default application to load.

# kibana.defaultAppId: "discover"

# If your Elasticsearch is protected with basic auth, these are the user credentials

# used by the Kibana server to perform maintenance on the kibana\_index at startup. Your Kibana

# users will still need to authenticate with Elasticsearch (which is proxied through

# the Kibana server)

elasticsearch.username: "kibana4-server"  
elasticsearch.password: "123456"

# SSL for outgoing requests from the Kibana Server to the browser (PEM formatted)

server.ssl.cert: "C:/Ajoe/OpenSSL/localhost.crt"  
server.ssl.key: "C:/Ajoe/OpenSSL/localhost.key"  
shield.encryptionKey: "123456"  
shield.sessionTimeout: 600000

# Optional setting to validate that your Elasticsearch backend uses the same key files (PEM formatted)

# elasticsearch.ssl.cert: /path/to/your/client.crt

# elasticsearch.ssl.key: /path/to/your/client.key

# If you need to provide a CA certificate for your Elasticsearch instance, put

# the path of the pem file here.

# [elasticsearch.ssl.ca](http://elasticsearch.ssl.ca): /path/to/your/CA.pem

# Set to false to have a complete disregard for the validity of the SSL

# certificate.

# elasticsearch.ssl.verify: true

# Time in milliseconds to wait for elasticsearch to respond to pings, defaults to

# request\_timeout setting

# elasticsearch.pingTimeout: 1500

# Time in milliseconds to wait for responses from the back end or elasticsearch.

# This must be \> 0

# elasticsearch.requestTimeout: 30000

# Time in milliseconds for Elasticsearch to wait for responses from shards.

# Set to 0 to disable.

# elasticsearch.shardTimeout: 0

# Time in milliseconds to wait for Elasticsearch at Kibana startup before retrying

# elasticsearch.startupTimeout: 5000

# Set the path to where you would like the process id file to be created.

# pid.file: /var/run/kibana.pid

# If you would like to send the log output to a file you can set the path below.

# logging.dest: stdout

# Set this to true to suppress all logging output.

# logging.silent: false

# Set this to true to suppress all logging output except for error messages.

# logging.quiet: false

# Set this to true to log all events, including system usage information and all requests.

# logging.verbose: false

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 16, 2016, 10:57am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/2 "2016-06-16T10:57:27Z")

</div>

What happens if you remove the authentication credentials from the value of elasticsearch.url?

---

<div class="post-metadata">

**Author:** ![ajoealex](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@ajoealex](https://discuss.elastic.co/u/ajoealex)\
**Post date:** [June 16, 2016, 11:05am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/3 "2016-06-16T11:05:37Z")

</div>

Thank you for pointing out the credentials, I made a mistake with my password. Now its working fine

---

<div class="post-metadata">

**Author:** ![sukesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukesh/32/10890_2.png) [@sukesh](https://discuss.elastic.co/u/sukesh)\
**Post date:** [July 20, 2016, 8:46am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/4 "2016-07-20T08:46:33Z")

</div>

hi Aj, iam sorry i didnot get what you have changed in credentials ! could you please explain me that?

---

<div class="post-metadata">

**Author:** ![ajoealex](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@ajoealex](https://discuss.elastic.co/u/ajoealex)\
**Post date:** [July 21, 2016, 2:01am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/5 "2016-07-21T02:01:50Z")

</div>

@sukesh I gave wrong username.

---

<div class="post-metadata">

**Author:** ![sukesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukesh/32/10890_2.png) [@sukesh](https://discuss.elastic.co/u/sukesh)\
**Post date:** [July 21, 2016, 5:35am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/6 "2016-07-21T05:35:16Z")

</div>

what procedure you followed there , i did every thing but kibana throwing the authentication exception  
?

---

<div class="post-metadata">

**Author:** ![ajoealex](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@ajoealex](https://discuss.elastic.co/u/ajoealex)\
**Post date:** [July 21, 2016, 5:57am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/7 "2016-07-21T05:57:47Z")

</div>

I followed the steps mentioned in [Kibana Shield Configuration](https://discuss.elastic.co/t/kibana-shield-configuration/45098).  
Have u created the ssl certificates? Also check roles.yml file.Even the space alignment will create problem.

# The required permissions for the kibana 4 server

kibana4\_server:  
cluster:  
- all  
indices:  
- names: '\*'  
privileges:  
- all

# The required permissions for the kibana4\_monitoring server

kibana4\_monitoring:  
cluster:  
- all  
indices:  
- names: '\*'  
privileges:  
- all

---

<div class="post-metadata">

**Author:** ![sukesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukesh/32/10890_2.png) [@sukesh](https://discuss.elastic.co/u/sukesh)\
**Post date:** [July 21, 2016, 6:07am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/8 "2016-07-21T06:07:36Z")

</div>

i didnt created the ssl certificates because i did not understand how to do that!  
will you helo me in that

---

<div class="post-metadata">

**Author:** ![ajoealex](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@ajoealex](https://discuss.elastic.co/u/ajoealex)\
**Post date:** [July 21, 2016, 7:49am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/9 "2016-07-21T07:49:06Z")

</div>

Download openssl for your system and

```
openssl genrsa -des3 -out localhost.key 1024
openssl req -new -key localhost.key -out localhost.csr
openssl x509 -req -days 365 -in localhost.csr -signkey localhost.key -out localhost.crt
openssl rsa -in localhost.key -out localhost.key
```

---

<div class="post-metadata">

**Author:** ![sukesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukesh/32/10890_2.png) [@sukesh](https://discuss.elastic.co/u/sukesh)\
**Post date:** [July 21, 2016, 9:05am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/10 "2016-07-21T09:05:00Z")

</div>

this is the first time i am installing this ,how to download the open ssl, is it possible to download in internet ?  
it will be very help full that if you suggest me this! and i used shield.skipSslCheck: true this command in kibana.yml to skip this ssl certificate thing!

is ssl certificate settings only the reason to authentication failed exception in kibana??

---

<div class="post-metadata">

**Author:** ![ajoealex](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@ajoealex](https://discuss.elastic.co/u/ajoealex)\
**Post date:** [July 21, 2016, 10:36am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/11 "2016-07-21T10:36:46Z")

</div>

I am not an expert in elasticsearch. But I think certificate is required. You need to download OpenSSL and do what I mentioned earlier in command prompt.

---

<div class="post-metadata">

**Author:** ![sukesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukesh/32/10890_2.png) [@sukesh](https://discuss.elastic.co/u/sukesh)\
**Post date:** [July 22, 2016, 5:48am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/12 "2016-07-22T05:48:29Z")

</div>

Ok , i will try to do that

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952/13 "2017-07-06T13:42:36Z")

</div>


