# How to disable Kibana security warning message

**URL:** <https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [May 30, 2021, 6:34am UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421 "2021-05-30T06:34:08Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![csaltos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/csaltos/32/89464_2.png) [@csaltos](https://discuss.elastic.co/u/csaltos)\
**Post date:** [May 30, 2021, 6:34am UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/1 "2021-05-30T06:34:08Z")

</div>

Kibana shows this message:

```
Elasticsearch built-in security features are not enabled. Without authentication, your cluster could be accessible to anyone. See https://www.elastic.co/guide/en/elasticsearch/reference/7.13/security-minimal-setup.html to enable security.

```

I cannot find any way of disabling this message. Is there an option on kibana.yml settings to disable that message warning ?

NOTE: obviously activating ElasticSearch security will fix it but I have the servers behind a VPN and two firewall layers so adding SSL/TLS is not necessary and it only will make it slow)  
IMPORTANT: do NOT disable ElasticSearch security if you are not on a sandboxed secure context

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 31, 2021, 6:47am UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/2 "2021-05-31T06:47:51Z")

</div>

Welcome to our community! 😃  
I don't know how to disable this other than by setting up Security. But,

> [@csaltos](#):
>
> adding SSL/TLS is not necessary and it only will make it slow

Uhhh, huh?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 31, 2021, 6:51am UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/3 "2021-05-31T06:51:42Z")

</div>

What does your Kibana config look like? Have you tried enabling security in Kibana but not in Elasticsearch?

---

<div class="post-metadata">

**Author:** ![csaltos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/csaltos/32/89464_2.png) [@csaltos](https://discuss.elastic.co/u/csaltos)\
**Post date:** [May 31, 2021, 7:53am UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/4 "2021-05-31T07:53:44Z")

</div>

Thanks !! ... it's a nice community.

Let me explain that more:

HTTPS is slower than HTTP (the CPU suffers encrypting and decrypting all the time) ... the use of HTTPS is mandatory in the traditional ElasticSearch security recommendations (for example with user and password authentication) ... but with VPN (and other encryption and security options like IPSEC) the tradicional ElasticSearch is not required and even slower (if forced with HTTPS encryption on top of the already VPN encryption) ... thus my question -\> how to disable the security warning of the traditional ElasticSearch message

---

<div class="post-metadata">

**Author:** ![csaltos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/csaltos/32/89464_2.png) [@csaltos](https://discuss.elastic.co/u/csaltos)\
**Post date:** [May 31, 2021, 8:00am UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/5 "2021-05-31T08:00:04Z")

</div>

Good idea, I will try to add security on the Kibana piece only, thanks !!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 31, 2021, 8:05am UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/6 "2021-05-31T08:05:17Z")

</div>

Kibana security relies on Elasticsearch security which in turn requires TLS to be enabled within the cluster for multi-node clusters. The reason I asked about Kibana config was to ee if you had any setting requiring security to be enabled.

---

<div class="post-metadata">

**Author:** ![csaltos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/csaltos/32/89464_2.png) [@csaltos](https://discuss.elastic.co/u/csaltos)\
**Post date:** [May 31, 2021, 8:35am UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/7 "2021-05-31T08:35:18Z")

</div>

no, nothing about security activated on Kibana, just the plain vanilla installation pointing to my ElasticSearch cluster.

I'm trying to follow these instructions -\> [Securing access to Kibana | Kibana Guide [7.13] | Elastic](https://www.elastic.co/guide/en/kibana/current/tutorial-secure-access-to-kibana.html) but I cannot find the `Security > Roles` section on my Kibana installation.

I'm using Kibana 7.13 and this is my config/kibana.yml file:

```auto
elasticsearch.hosts: ["http://cs-es-node1:9200", "http://cs-es-node2:9200", "http://cs-es-node3:9200"]
telemetry.enabled: false

```

Thanks for your help

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 31, 2021, 8:39am UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/8 "2021-05-31T08:39:10Z")

</div>

Are you using Elasticsearch 7.13 as well?

---

<div class="post-metadata">

**Author:** ![csaltos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/csaltos/32/89464_2.png) [@csaltos](https://discuss.elastic.co/u/csaltos)\
**Post date:** [May 31, 2021, 8:39am UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/9 "2021-05-31T08:39:31Z")

</div>

Yes, ElasticSearch 7.13 too

---

<div class="post-metadata">

**Author:** ![csaltos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/csaltos/32/89464_2.png) [@csaltos](https://discuss.elastic.co/u/csaltos)\
**Post date:** [May 31, 2021, 8:57am UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/10 "2021-05-31T08:57:47Z")

</div>

Here a snapshot of the Stack Management mentioned at [Securing access to Kibana | Kibana Guide [7.13] | Elastic](https://www.elastic.co/guide/en/kibana/current/tutorial-secure-access-to-kibana.html)

 ![Screenshot from 2021-05-31 11-55-18](https://us1.discourse-cdn.com/elastic/original/3X/6/7/6761b93a7674c65649a197d0cae9adc63d0855c3.png)

where I cannot find the `Secure > Roles` section nor the `Secure > Users` section

So, question -\> How can I add users to Kibana 7.13 ?

For sure I'm missing something very obvious but I'm lost now.

Or even better how can I just remove the security warning message ... everything is working nice now with VPN.

Thank you for your help !!

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [May 31, 2021, 12:01pm UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/11 "2021-05-31T12:01:34Z")

</div>

> [@csaltos](#):
>
> Or even better how can I just remove the security warning message ... everything is working nice now with VPN.

@csaltos In short, you can disable the warning message by explicitly turning off security, i.e. add the following in `elasticsearch.yml`:

```yaml
xpack.security.enabled: false

```

**Some more context**  
The warning is shown when the security is implicitly disabled, that is, there is no config for `xpack.security.enabled` in `elasticsearch.yml`, and your license is either `basic` or `trial`. This is new in 7.13. You can remove the warning by either enable or disable security **explicitly**. We'd recommend you to **enable** security since it gives you better protection. But in the meantime, you can choose to opt out explicilty. Again, we recommend enabling security since your data could be at risk without it. The new [step-by-step guide](https://www.elastic.co/guide/en/elasticsearch/reference/7.13/security-minimal-setup.html) should provide you a straightforward path. Thanks!

---

<div class="post-metadata">

**Author:** ![csaltos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/csaltos/32/89464_2.png) [@csaltos](https://discuss.elastic.co/u/csaltos)\
**Post date:** [May 31, 2021, 12:38pm UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/12 "2021-05-31T12:38:11Z")

</div>

Great !! ... that does the trick !! ... thank you very much Yang and Christian and Mark for your help and support, a great community indeed ... now I just need to ensure the IPSec and the VPN works correctly for having all this actually secure for production.

Best regards,

Carlos

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2021, 12:38pm UTC](https://discuss.elastic.co/t/how-to-disable-kibana-security-warning-message/274421/13 "2021-06-28T12:38:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
