# How kibana will connect to elasticsearch without built-in user and password

**URL:** <https://discuss.elastic.co/t/how-kibana-will-connect-to-elasticsearch-without-built-in-user-and-password/180284>\
**Category:** Kibana\
**Created:** [May 9, 2019, 6:00am UTC](https://discuss.elastic.co/t/how-kibana-will-connect-to-elasticsearch-without-built-in-user-and-password/180284 "2019-05-09T06:00:52Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ronnie16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ronnie16/32/66399_2.png) [@Ronnie16](https://discuss.elastic.co/u/Ronnie16)\
**Post date:** [May 9, 2019, 6:00am UTC](https://discuss.elastic.co/t/how-kibana-will-connect-to-elasticsearch-without-built-in-user-and-password/180284/1 "2019-05-09T06:00:52Z")

</div>

Hi team,

I have few queries for my elasticsearch cluster. It is TLS enabled and running on platinum license. I don't want to use any static username and password for built-in users, so I have setup LDAP realm and I'm able to access elasticsearch api with LDAP login.

1. Now I want to know how kibana will connect to elasticsearch ? I don't want to store any username password in kibana.yml. (I don't want to store password in keystore manually)

2. Is there a way by which kibana can connect to elasticsearch using any LDAP credentials ?

3. if I run setup-passwords auto will I still need to provide elasticsearch.username and password in kibana.yml or it takes automatically from .security index ?

Basically without putting any password references in kibana.yml, how kibana will access elasticsearch ?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [May 9, 2019, 4:00pm UTC](https://discuss.elastic.co/t/how-kibana-will-connect-to-elasticsearch-without-built-in-user-and-password/180284/2 "2019-05-09T16:00:00Z")

</div>

Hey @Ronnie16, if you don't want to store a hard-coded username/password in the kibana.yml, you could potentially use the PKI realm in Elasticsearch so that Kibana can authenticate using a certificate/key.

We're working on adding Kerberos support to Kibana, but the first phase is using Kerberos to authenticate the logged in end-user, not to authenticate the internal Kibana server user. We'd like to add Kerberos authentication for the server identity, but there are some additional technical hurdles we'll have to overcome before we get to that point.

How are you currently authenticating other systems which communicate with Elasticsearch?

---

<div class="post-metadata">

**Author:** ![Ronnie16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ronnie16/32/66399_2.png) [@Ronnie16](https://discuss.elastic.co/u/Ronnie16)\
**Post date:** [May 9, 2019, 4:03pm UTC](https://discuss.elastic.co/t/how-kibana-will-connect-to-elasticsearch-without-built-in-user-and-password/180284/3 "2019-05-09T16:03:27Z")

</div>

I'm trying to found a way to authenticate kibana and logstash system without hard-coded passwords. For end users I'm setting up ldap realm for elasticsearch and saml for kibana.

I tried with pki but this step doesn't work without giving kibana username and password.

\_xpack/security/\_authenticate?pretty

```
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "missing authentication token for REST request [/_xpack/security/_authenticate?pretty]",
        "header" : {
          "WWW-Authenticate" : [
            "Bearer realm=\"security\"",
            "ApiKey",
            "Basic realm=\"security\" charset=\"UTF-8\""
          ]
        }
      }
    ],
    "type" : "security_exception",
    "reason" : "missing authentication token for REST request [/_xpack/security/_authenticate?pretty]",
    "header" : {
      "WWW-Authenticate" : [
        "Bearer realm=\"security\"",
        "ApiKey",
        "Basic realm=\"security\" charset=\"UTF-8\""
      ]
    }
  },
  "status" : 401
```

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [May 9, 2019, 4:39pm UTC](https://discuss.elastic.co/t/how-kibana-will-connect-to-elasticsearch-without-built-in-user-and-password/180284/4 "2019-05-09T16:39:17Z")

</div>

I assume you have the PKI realm configured in Elasticsearch already? If so, you should be able to execute a curl similar to the following using the cert/keys specified in `elasticsearch.ssl.certificate` and `elasticsearch.ssl.key` and get a proper response:

```auto
curl --cert /path/to/elasticsearch.ssl.certificate --key /path/to/elasticsearch.ssl.key http://localhost:9200/_xpack/security/_authenticate

```

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [May 10, 2019, 4:09pm UTC](https://discuss.elastic.co/t/how-kibana-will-connect-to-elasticsearch-without-built-in-user-and-password/180284/6 "2019-05-10T16:09:19Z")

</div>

You can use the [PKI Realm](https://www.elastic.co/guide/en/elasticsearch/reference/7.0/configuring-pki-realm.html) in addition to the ldap and saml realms which you currently have enabled, so you can use certificates to authenticate instead of usernames/passwords.

---

<div class="post-metadata">

**Author:** ![Ronnie16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ronnie16/32/66399_2.png) [@Ronnie16](https://discuss.elastic.co/u/Ronnie16)\
**Post date:** [May 10, 2019, 4:13pm UTC](https://discuss.elastic.co/t/how-kibana-will-connect-to-elasticsearch-without-built-in-user-and-password/180284/7 "2019-05-10T16:13:36Z")

</div>

@Brandon_Kobel, this is what my issue is. I'm trying to authenticate it via certificates only but getting the mentioned error in previous reply. Can you check that ? also I have pasted my configuration . I'm configuring pki for kibana to authenticate to elasticsearch not for end users.  
I already have saml and ldap for end user authentication for kibana and elasticsearch respectively

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [May 10, 2019, 4:55pm UTC](https://discuss.elastic.co/t/how-kibana-will-connect-to-elasticsearch-without-built-in-user-and-password/180284/8 "2019-05-10T16:55:08Z")

</div>

Do your elasticsearch logs show anything when you're trying to execute the aforementioned curl?

Also, it might be worth double-checking the following setting

```auto
    xpack.security.http.ssl.certificate_authorities: ["/usr/share/elasticsearch/config/tls_server/crt.pem"]

```

it's using the same path as `xpack.security.http.ssl.certificate` and `xpack.security.http.ssl.certificate_authorities` should be the CA's certificate which was used to create Elasticsearch's certificate and Kibana's certificate.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2019, 4:55pm UTC](https://discuss.elastic.co/t/how-kibana-will-connect-to-elasticsearch-without-built-in-user-and-password/180284/9 "2019-06-07T16:55:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
