# FATAL ValidationError: child "xpack" fails because \[child "security" fails because \["anonymous" is not allowed\]\]

**URL:** <https://discuss.elastic.co/t/fatal-validationerror-child-xpack-fails-because-child-security-fails-because-anonymous-is-not-allowed/193273>\
**Category:** Kibana\
**Created:** [August 1, 2019, 8:10am UTC](https://discuss.elastic.co/t/fatal-validationerror-child-xpack-fails-because-child-security-fails-because-anonymous-is-not-allowed/193273 "2019-08-01T08:10:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![KIKON](https://avatars.discourse-cdn.com/v4/letter/k/f05b48/32.png) [@KIKON](https://discuss.elastic.co/u/KIKON)\
**Post date:** [August 1, 2019, 8:10am UTC](https://discuss.elastic.co/t/fatal-validationerror-child-xpack-fails-because-child-security-fails-because-anonymous-is-not-allowed/193273/1 "2019-08-01T08:10:02Z")

</div>

Hello, When I set xpack.security.anonymous.enabled: true in my kibana.yml, Kibana does not start.

Show the error "FATAL ValidationError: child "xpack" fails because [child "security" fails because ["anonymous" is not allowed]]"

Thanks!

---

<div class="post-metadata">

**Author:** ![dgonzalezp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dgonzalezp/32/50804_2.png) [@dgonzalezp](https://discuss.elastic.co/u/dgonzalezp)\
**Post date:** [August 1, 2019, 8:33am UTC](https://discuss.elastic.co/t/fatal-validationerror-child-xpack-fails-because-child-security-fails-because-anonymous-is-not-allowed/193273/2 "2019-08-01T08:33:23Z")

</div>

Hi @KIKON

Looks like you are trying log with a anonymos user.  
Have you added the next lines in kibana.yml file?

> elasticsearch.username: "kibana"  
> elasticsearch.password: "kibana"

---

<div class="post-metadata">

**Author:** ![KIKON](https://avatars.discourse-cdn.com/v4/letter/k/f05b48/32.png) [@KIKON](https://discuss.elastic.co/u/KIKON)\
**Post date:** [August 1, 2019, 10:32am UTC](https://discuss.elastic.co/t/fatal-validationerror-child-xpack-fails-because-child-security-fails-because-anonymous-is-not-allowed/193273/3 "2019-08-01T10:32:36Z")

</div>

OK, I disabled xpack in kibana and logging with the anonymous user, the anonymous user only can see dashboard in one space, kibana didn't start.

I added at the user the role kibana\_system, Kibana starts without login, bat the user see all spaces, and can create dashboards.

I am workin in a new role that keep starts kibana but not access many options.

---

<div class="post-metadata">

**Author:** ![KIKON](https://avatars.discourse-cdn.com/v4/letter/k/f05b48/32.png) [@KIKON](https://discuss.elastic.co/u/KIKON)\
**Post date:** [August 2, 2019, 7:40am UTC](https://discuss.elastic.co/t/fatal-validationerror-child-xpack-fails-because-child-security-fails-because-anonymous-is-not-allowed/193273/4 "2019-08-02T07:40:08Z")

</div>

Well, if you disabled xpack, the roles limit the UI are disabled. The user view all options and can use it, but when the user try save anything if you give only read roles, fail the operation. I dont like the solution. The only option for use the roles limit the UI of kibana is make a proxyrevers that authenticate in kibana. mmm Bad.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2019, 7:40am UTC](https://discuss.elastic.co/t/fatal-validationerror-child-xpack-fails-because-child-security-fails-because-anonymous-is-not-allowed/193273/5 "2019-08-30T07:40:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
