# How to config kibana if xpack.security.http.ssl.enabled is false

**URL:** <https://discuss.elastic.co/t/how-to-config-kibana-if-xpack-security-http-ssl-enabled-is-false/307350>\
**Category:** Kibana\
**Tags:** elastic-stack-security, docker\
**Created:** [June 16, 2022, 7:01am UTC](https://discuss.elastic.co/t/how-to-config-kibana-if-xpack-security-http-ssl-enabled-is-false/307350 "2022-06-16T07:01:34Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![yjm17865195865](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yjm17865195865/32/107103_2.png) [@yjm17865195865](https://discuss.elastic.co/u/yjm17865195865)\
**Post date:** [June 16, 2022, 7:01am UTC](https://discuss.elastic.co/t/how-to-config-kibana-if-xpack-security-http-ssl-enabled-is-false/307350/1 "2022-06-16T07:01:34Z")

</div>

I'm starting a Elasticsearch v8.2.2 throuth docker images. After started i found that TLS/SSL is enabled in default and I want to disable that( however it's fine that between es'node keep using the TLS/SSL to communicate). I changed xpack.security.http.ssl.enabled to false while keeping xpack.security.enabled to be true for I want to keep the simple username/password mode. Here is my Elasticsearch.yml

```auto
cluster.name: "docker-cluster"
network.host: 0.0.0.0

#----------------------- BEGIN SECURITY AUTO CONFIGURATION -----------------------
#
# The following settings, TLS certificates, and keys have been automatically
# generated to configure Elasticsearch security features on 15-06-2022 05:15:58
#
# --------------------------------------------------------------------------------

# Enable security features
xpack.security.enabled: true

xpack.security.enrollment.enabled: true

# Enable encryption for HTTP API client connections, such as Kibana, Logstash, and Agents
xpack.security.http.ssl:
  enabled: false
  keystore.path: certs/http.p12

# Enable encryption and mutual authentication between cluster nodes
xpack.security.transport.ssl:
  enabled: true
  verification_mode: certificate
  keystore.path: certs/transport.p12
  truststore.path: certs/transport.p12
# Create a new cluster with the current node only
# Additional nodes can still join the cluster later
cluster.initial_master_nodes: ["c363a61256ab"]

#----------------------- END SECURITY AUTO CONFIGURATION -------------------------

```

Then i started kibana via docker like

```auto
docker run --name kibana --net elastic -p 5601:5601 kibana:8.2.2

```

I found kibana started failed. througth browser i only got an error like 'Kibana server is not ready yet.'  
I checked the docker log and here is what i got.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/5/15ba41f50b905f409bbe527365e84c1f87c4eddf.png)

so how could i config the kibana to suit this condition?

---

<div class="post-metadata">

**Author:** ![Tre\_Seymour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tre_seymour/32/46507_2.png) [@Tre\_Seymour](https://discuss.elastic.co/u/Tre_Seymour)\
**Post date:** [June 16, 2022, 10:03am UTC](https://discuss.elastic.co/t/how-to-config-kibana-if-xpack-security-http-ssl-enabled-is-false/307350/2 "2022-06-16T10:03:03Z")

</div>

> [@yjm17865195865](#):
>
> ```auto
> 
> ```

Hello @ [yjm17865195865](https://discuss.elastic.co/u/yjm17865195865) , can we try adding the following stanza to your `kibana.yml`:

```yml
xpack.security.authc:
    providers:
      basic.basic1: 
          order: 0

```

?  
While you try that, I am going to ask around to see if anyone else has seen this issue.

---

<div class="post-metadata">

**Author:** ![Tre\_Seymour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tre_seymour/32/46507_2.png) [@Tre\_Seymour](https://discuss.elastic.co/u/Tre_Seymour)\
**Post date:** [June 16, 2022, 10:06am UTC](https://discuss.elastic.co/t/how-to-config-kibana-if-xpack-security-http-ssl-enabled-is-false/307350/3 "2022-06-16T10:06:27Z")

</div>

@yjm17865195865 how many nodes are you running? I'm curious.

---

<div class="post-metadata">

**Author:** ![yjm17865195865](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yjm17865195865/32/107103_2.png) [@yjm17865195865](https://discuss.elastic.co/u/yjm17865195865)\
**Post date:** [June 17, 2022, 12:34am UTC](https://discuss.elastic.co/t/how-to-config-kibana-if-xpack-security-http-ssl-enabled-is-false/307350/4 "2022-06-17T00:34:59Z")

</div>

just one node without using standalone mode. I found out that the main problem is kibana need a password to contact with Elasticsearch, so i go into the Elasticsearch docker container and reset the password for user 'kibana'

```auto
./elasticsearch-reset-password -u kibana

```

then i re-config the kibana like this, set the Elasticsearch node to link and the user-pass, and it succeed !

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c9f07e78bf9d9915ed84c9ab39edffc8cbedfbd1.png)  
thx for the reply , i wonder if my issue is a common one because i think it's normal that we dont  
really need this TLS/SSL feature on production but its unclear how to close it.

---

<div class="post-metadata">

**Author:** ![Tre\_Seymour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tre_seymour/32/46507_2.png) [@Tre\_Seymour](https://discuss.elastic.co/u/Tre_Seymour)\
**Post date:** [June 17, 2022, 12:04pm UTC](https://discuss.elastic.co/t/how-to-config-kibana-if-xpack-security-http-ssl-enabled-is-false/307350/5 "2022-06-17T12:04:25Z")

</div>

Hey I'm glad it worked out.

It almost looks like you set it to an empty password here:  
`./elasticsearch-reset-password -u kibana`

Is that the case?

---

<div class="post-metadata">

**Author:** ![yjm17865195865](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yjm17865195865/32/107103_2.png) [@yjm17865195865](https://discuss.elastic.co/u/yjm17865195865)\
**Post date:** [June 20, 2022, 12:03am UTC](https://discuss.elastic.co/t/how-to-config-kibana-if-xpack-security-http-ssl-enabled-is-false/307350/6 "2022-06-20T00:03:29Z")

</div>

actually, the reset-password script will generate a random password for whoever the -u command follows.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 21, 2022, 1:41am UTC](https://discuss.elastic.co/t/how-to-config-kibana-if-xpack-security-http-ssl-enabled-is-false/307350/7 "2022-06-21T01:41:21Z")

</div>

In future please don't post pictures of text, logs or code. They are difficult to read, impossible to search and replicate (if it's code), and some people may not be even able to see them 🙂

---

<div class="post-metadata">

**Author:** ![yjm17865195865](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yjm17865195865/32/107103_2.png) [@yjm17865195865](https://discuss.elastic.co/u/yjm17865195865)\
**Post date:** [June 21, 2022, 11:55pm UTC](https://discuss.elastic.co/t/how-to-config-kibana-if-xpack-security-http-ssl-enabled-is-false/307350/8 "2022-06-21T23:55:22Z")

</div>

ok, sorry for my rookie behavior

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2022, 11:55pm UTC](https://discuss.elastic.co/t/how-to-config-kibana-if-xpack-security-http-ssl-enabled-is-false/307350/9 "2022-07-19T23:55:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
