# How to disable authentication in Kibana while still using SSL?

**URL:** <https://discuss.elastic.co/t/how-to-disable-authentication-in-kibana-while-still-using-ssl/82325>\
**Category:** Kibana\
**Created:** [April 13, 2017, 3:36pm UTC](https://discuss.elastic.co/t/how-to-disable-authentication-in-kibana-while-still-using-ssl/82325 "2017-04-13T15:36:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![tylermac92](https://avatars.discourse-cdn.com/v4/letter/t/b3f665/32.png) [@tylermac92](https://discuss.elastic.co/u/tylermac92)\
**Post date:** [April 13, 2017, 3:36pm UTC](https://discuss.elastic.co/t/how-to-disable-authentication-in-kibana-while-still-using-ssl/82325/1 "2017-04-13T15:36:07Z")

</div>

Is it possible to disable the need to log in to Kibana, while still running the instance over HTTPS? We have our own means of authentication that any user trying to access must go through first, so there is no need for us to need to login to Kibana as well. I was looking at disabling x-pack, but that looks like it also disables HTTPS. Any ideas?

Currently we are using Kibana 5.2.2, but are looking into 5.3.

Thanks!

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [April 13, 2017, 4:46pm UTC](https://discuss.elastic.co/t/how-to-disable-authentication-in-kibana-while-still-using-ssl/82325/2 "2017-04-13T16:46:08Z")

</div>

hi @tylermac92 ,

you'll need to set the SSL config:

[https://www.elastic.co/guide/en/kibana/current/production.html#enabling-ssl](https://www.elastic.co/guide/en/kibana/current/production.html#enabling-ssl)

thx!

---

<div class="post-metadata">

**Author:** ![tylermac92](https://avatars.discourse-cdn.com/v4/letter/t/b3f665/32.png) [@tylermac92](https://discuss.elastic.co/u/tylermac92)\
**Post date:** [April 17, 2017, 7:01pm UTC](https://discuss.elastic.co/t/how-to-disable-authentication-in-kibana-while-still-using-ssl/82325/3 "2017-04-17T19:01:36Z")

</div>

I have SSL enabled, and xpack is disabled. However, when I try to access Kibana, I'm still being prompted to enter credentials. Any way to disable this? I want users to have access without having to authenticate, but still pass traffic over HTTPS.

![](https://us1.discourse-cdn.com/elastic/original/3X/c/1/c18fcde5708b77d99bd85e3cc3c217d87192174f.png)

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [April 17, 2017, 7:16pm UTC](https://discuss.elastic.co/t/how-to-disable-authentication-in-kibana-while-still-using-ssl/82325/4 "2017-04-17T19:16:22Z")

</div>

Have you disabled security in the elasticsearch/kibana.yml files?

`xpack.security.enabled: false`

---

<div class="post-metadata">

**Author:** ![tylermac92](https://avatars.discourse-cdn.com/v4/letter/t/b3f665/32.png) [@tylermac92](https://discuss.elastic.co/u/tylermac92)\
**Post date:** [April 17, 2017, 7:34pm UTC](https://discuss.elastic.co/t/how-to-disable-authentication-in-kibana-while-still-using-ssl/82325/5 "2017-04-17T19:34:59Z")

</div>

I have that set in the kibana.yml file. I was hesitant to do so in elasticsearch.yml, because we still want to have elasticsearch run over HTTPS (and we want to have kibana authenticate with elasticsearch, just not require a user to authenticate in their browser).

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [April 17, 2017, 8:52pm UTC](https://discuss.elastic.co/t/how-to-disable-authentication-in-kibana-while-still-using-ssl/82325/6 "2017-04-17T20:52:22Z")

</div>

So it seems you are not really using X-pack as you're turning it of?

If not, you could add a reverse proxy (e.g. nginx) in front of Elasticsearch that adds basic authentication/SSL for Elasticsearch.

You can then configure Kibana to hit that server by setting the `elasticsearch.user` and `elasticsearch.password` parameters in the `kibana.yml` file.

Let me know if I'm missing something, thx

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2017, 8:59pm UTC](https://discuss.elastic.co/t/how-to-disable-authentication-in-kibana-while-still-using-ssl/82325/7 "2017-05-15T20:59:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
