# How to configure Single sign on in Kibana GUI Authenticated by LDAP

**URL:** https://discuss.elastic.co/t/how-to-configure-single-sign-on-in-kibana-gui-authenticated-by-ldap/207653
**Category:** Kibana
**Tags:** elastic-stack-security
**Created:** [November 13, 2019, 8:26am UTC](https://discuss.elastic.co/t/how-to-configure-single-sign-on-in-kibana-gui-authenticated-by-ldap/207653 "2019-11-13T08:26:37Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![ksarkar](https://avatars.discourse-cdn.com/v4/letter/k/ee7513/32.png) [@ksarkar](https://discuss.elastic.co/u/ksarkar)
#### Post date: [November 13, 2019, 8:26am UTC](https://discuss.elastic.co/t/how-to-configure-single-sign-on-in-kibana-gui-authenticated-by-ldap/207653/1 "2019-11-13T08:26:38Z")

</div>

Hi,

I have enabled x-pack 30 days trial and able to connect and validate user while authenticated by openLDAP platform.  
i.e Kibana GUI is opening using the user/pass configured at LDAP.

Now I am trying one step ahead to enable Single Sign in Kibana GUI.  
Expectation is, if I open Kibana GUI from browser then it should take my user windows login credentials and (validate it in LDAP) directly open GUI as per role (Group) configured.

Could you please help me with a sample configuration on the same.

---

<div class="post-metadata">

### Author: ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)
#### Post date: [November 13, 2019, 8:42am UTC](https://discuss.elastic.co/t/how-to-configure-single-sign-on-in-kibana-gui-authenticated-by-ldap/207653/2 "2019-11-13T08:42:51Z")

</div>

> [@ksarkar](#):
>
> Now I am trying one step ahead to enable Single Sign in Kibana GUI.  
> Expectation is, if I open Kibana GUI from browser then it should take my user windows login credentials and (validate it in LDAP) directly open GUI as per role (Group) configured.

This is not something that can happen automatically. The closest thing I can think to match your expectations is Kerberos/SPNEGO but you need to have a kerberos implementation on your side first ( using the same openldap server as a backend ) .  
See [Configuring a Kerberos realm | Elasticsearch Guide [7.4] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/configuring-kerberos-realm.html)

---

<div class="post-metadata">

### Author: ![ksarkar](https://avatars.discourse-cdn.com/v4/letter/k/ee7513/32.png) [@ksarkar](https://discuss.elastic.co/u/ksarkar)
#### Post date: [November 13, 2019, 1:44pm UTC](https://discuss.elastic.co/t/how-to-configure-single-sign-on-in-kibana-gui-authenticated-by-ldap/207653/3 "2019-11-13T13:44:43Z")

</div>

Thanks, will try to explore the same.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 11, 2019, 1:44pm UTC](https://discuss.elastic.co/t/how-to-configure-single-sign-on-in-kibana-gui-authenticated-by-ldap/207653/4 "2019-12-11T13:44:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
