# Having trouble setting kerberos on Kibana

**URL:** <https://discuss.elastic.co/t/having-trouble-setting-kerberos-on-kibana/230038>\
**Category:** Kibana\
**Created:** [April 27, 2020, 9:49pm UTC](https://discuss.elastic.co/t/having-trouble-setting-kerberos-on-kibana/230038 "2020-04-27T21:49:08Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![lnitin12](https://avatars.discourse-cdn.com/v4/letter/l/b5e925/32.png) [@lnitin12](https://discuss.elastic.co/u/lnitin12)\
**Post date:** [April 27, 2020, 9:49pm UTC](https://discuss.elastic.co/t/having-trouble-setting-kerberos-on-kibana/230038/1 "2020-04-27T21:49:08Z")

</div>

```auto
There seems no proper documentation on setting up kerberos on kibana, 
on elasticsearch kerberos works fine with --negotiate user.
But on Kibana once we add xpack.security.authc.providers:[kerberos] 
and try to load kibana UI, we get error on authentication

2020-04-26T16:24:52,241][DEBUG][r.suppressed] [master] path: /_security/_authenticate, params: {} org.elasticsearch.ElasticsearchSecurityException: missing authentication credentials for REST request [/_security/_authenticate] at org.elasticsearch.xpack.core.security.support.Exceptions.authenticationError(Exceptions.java:18) ~[x-pack-core-7.5.2.jar:7.5.2] at org.elasticsearch.xpack.core.security.authc.DefaultAuthenticationFailureHandler.createAuthenticationError(DefaultAuthenticationFailureHandler.java:154) ~[x-pack-core-7.5.2.jar:7.5.2] at org.elasticsearch.xpack.core.security.authc.DefaultAuthenticationFailureHandler.missingToken(DefaultAuthenticationFailureHandler.java:104) ~[x-pack-core-7.5.2.jar:7.5.2].
Can anyone suggest how to --negotiate with AD user without providing credentials to browser..?

```

---

<div class="post-metadata">

**Author:** ![lnitin12](https://avatars.discourse-cdn.com/v4/letter/l/b5e925/32.png) [@lnitin12](https://discuss.elastic.co/u/lnitin12)\
**Post date:** [April 27, 2020, 9:50pm UTC](https://discuss.elastic.co/t/having-trouble-setting-kerberos-on-kibana/230038/2 "2020-04-27T21:50:26Z")

</div>

@elasticsearch

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [April 27, 2020, 11:05pm UTC](https://discuss.elastic.co/t/having-trouble-setting-kerberos-on-kibana/230038/3 "2020-04-27T23:05:15Z")

</div>

cc /

@Oleg/ @Larry_Gregory

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [April 28, 2020, 2:21pm UTC](https://discuss.elastic.co/t/having-trouble-setting-kerberos-on-kibana/230038/4 "2020-04-28T14:21:59Z")

</div>

Hi @lnitin12, welcome to the discussion boards.

Can you provide your `elasticsearch.yml` and `kibana.yml` configurations, redacting any sensitive information?

Can you also turn on debug logging for kibana by setting `logging.verbose: true` in your `kibana.yml`, and see if Kibana is reporting anything relevant in its log file when you try to authenticate?

---

<div class="post-metadata">

**Author:** ![lnitin12](https://avatars.discourse-cdn.com/v4/letter/l/b5e925/32.png) [@lnitin12](https://discuss.elastic.co/u/lnitin12)\
**Post date:** [April 28, 2020, 3:00pm UTC](https://discuss.elastic.co/t/having-trouble-setting-kerberos-on-kibana/230038/5 "2020-04-28T15:00:53Z")

</div>

Hi @Larry_Gregory  
I'll send you configurations in few mins for kerberos. Attached is the image from logs in kibana after adding above setting.

 ![IMG_3675](https://us1.discourse-cdn.com/elastic/original/3X/e/b/eb480b3335da4d60b38347912746e0c6315ee48a.jpeg)

---

<div class="post-metadata">

**Author:** ![lnitin12](https://avatars.discourse-cdn.com/v4/letter/l/b5e925/32.png) [@lnitin12](https://discuss.elastic.co/u/lnitin12)\
**Post date:** [April 28, 2020, 3:16pm UTC](https://discuss.elastic.co/t/having-trouble-setting-kerberos-on-kibana/230038/6 "2020-04-28T15:16:50Z")

</div>

Added configuration for kerberos  
elasticsearch.yml  
xpack.security.authc.realms.kerberos.kerb1.order: "3"  
xpack.security.authc.realms.kerberos.kerb1.order: /etc/elasticsearch/es.keytab  
xpack,security.authc.realms.kerberos.kerb1.remove\_realm\_name: 'true'  
xpack.security.authc.realms.kerberos.kerb1.krb.debug: 'true'

jvm.options  
-Djava.security.krb5.conf: /etc/krb5.conf  
-Dsun.security.krb5.debug: true  
-Dsun.security.krb5.spnego.debug: true  
-Dsun.security.krb5.rcache: none

kibana.yml  
xpack.security.authc.providers: [kerberos, basic]

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [April 28, 2020, 3:49pm UTC](https://discuss.elastic.co/t/having-trouble-setting-kerberos-on-kibana/230038/7 "2020-04-28T15:49:20Z")

</div>

Thanks for the update -- the full log file and full configuration files would be more helpful. It looks like there are other realms configured, so getting the full picture will help us help you.

When you try to authenticate against Elasticsearch directly, is that the same machine that you're accessing Kibana from?

What browser are you using to attempt authentication?

I see you have basic auth enabled as well. Can you make sure that Kibana allows you to login using a username/password? This will help us rule out other issues.

---

<div class="post-metadata">

**Author:** ![lnitin12](https://avatars.discourse-cdn.com/v4/letter/l/b5e925/32.png) [@lnitin12](https://discuss.elastic.co/u/lnitin12)\
**Post date:** [April 28, 2020, 3:56pm UTC](https://discuss.elastic.co/t/having-trouble-setting-kerberos-on-kibana/230038/8 "2020-04-28T15:56:45Z")

</div>

ok, let me send out log and config files.. Yes there is ldap configured with kerberos.  
I tried to access kibana UI on Chrome, firefox and internet explorer ans all of them get same error as below.  
with basic auth i'm able to login as ldap user and also as native user.

020-04-26T16:24:52,241][DEBUG][r.suppressed] [master] path: /\_security/\_authenticate, params: {} org.elasticsearch.ElasticsearchSecurityException: missing authentication credentials for REST request [/\_security/\_authenticate] at org.elasticsearch.xpack.core.security.support.Exceptions.authenticationError(Exceptions.java:18) ~[x-pack-core-7.5.1.jar:7.5.1] at org.elasticsearch.xpack.core.security.authc.DefaultAuthenticationFailureHandler.createAuthenticationError(DefaultAuthenticationFailureHandler.java:154) ~[x-pack-core-7.5.1.jar:7.5.1] at org.elasticsearch.xpack.core.security.authc.DefaultAuthenticationFailureHandler.missingToken(DefaultAuthenticationFailureHandler.java:104) ~[x-pack-core-7.5.1.jar:7.5.1]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2020, 3:56pm UTC](https://discuss.elastic.co/t/having-trouble-setting-kerberos-on-kibana/230038/9 "2020-05-26T15:56:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
