# Kerberos, LDAP - Kibana

**URL:** <https://discuss.elastic.co/t/kerberos-ldap-kibana/200011>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 18, 2019, 1:02pm UTC](https://discuss.elastic.co/t/kerberos-ldap-kibana/200011 "2019-09-18T13:02:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ivanavi](https://avatars.discourse-cdn.com/v4/letter/i/ac91a4/32.png) [@ivanavi](https://discuss.elastic.co/u/ivanavi)\
**Post date:** [September 18, 2019, 1:02pm UTC](https://discuss.elastic.co/t/kerberos-ldap-kibana/200011/1 "2019-09-18T13:02:38Z")

</div>

Hello, is it possible to configure Kerberos for authentication and use AD/LDAP for authorization (user group membership is read from LDAP for assigning roles?

When will be Kibana - Kerberos feature available?

Thanks.

---

<div class="post-metadata">

**Author:** ![cknoell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cknoell/32/47353_2.png) [@cknoell](https://discuss.elastic.co/u/cknoell)\
**Post date:** [September 19, 2019, 9:33am UTC](https://discuss.elastic.co/t/kerberos-ldap-kibana/200011/2 "2019-09-19T09:33:07Z")

</div>

Feature is already there: [https://www.elastic.co/guide/en/elastic-stack-overview/current/kerberos-realm.html](https://www.elastic.co/guide/en/elastic-stack-overview/current/kerberos-realm.html)

---

<div class="post-metadata">

**Author:** ![ivanavi](https://avatars.discourse-cdn.com/v4/letter/i/ac91a4/32.png) [@ivanavi](https://discuss.elastic.co/u/ivanavi)\
**Post date:** [September 19, 2019, 9:57am UTC](https://discuss.elastic.co/t/kerberos-ldap-kibana/200011/3 "2019-09-19T09:57:22Z")

</div>

Kerberos is working fine with Elasticsearch.

How should I implement Kerberos in Kibana?

I have not find any documentation about it....

---

<div class="post-metadata">

**Author:** ![cknoell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cknoell/32/47353_2.png) [@cknoell](https://discuss.elastic.co/u/cknoell)\
**Post date:** [September 19, 2019, 10:47am UTC](https://discuss.elastic.co/t/kerberos-ldap-kibana/200011/4 "2019-09-19T10:47:49Z")

</div>

This feature covers the complete Elastic Stack, not only Elasticsearch...

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 24, 2019, 8:52pm UTC](https://discuss.elastic.co/t/kerberos-ldap-kibana/200011/5 "2019-09-24T20:52:25Z")

</div>

> [@ivanavi](#):
>
> Hello, is it possible to configure Kerberos for authentication

> [@ivanavi](#):
>
> When will be Kibana - Kerberos feature available?

We're in the process of updating our docs, but Kerberos is available for authentication in Kibana since 7.3. If you follow the referenced docs above to configure the necessary parts in Elasticsearch, you'd only additionally need to set

```auto
xpack.security.authc.providers: [kerberos]

```

in `kibana.yml`.

> [@ivanavi](#):
>
> and use AD/LDAP for authorization (user group membership is read from LDAP for assigning roles?

Yes, you can do that too. You can see the preview for this documentation in [Configuring authorization delegation | Elasticsearch Guide [7.4] | Elastic](https://www.elastic.co/guide/en/elastic-stack-overview/7.4/configuring-authorization-delegation.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2019, 8:52pm UTC](https://discuss.elastic.co/t/kerberos-ldap-kibana/200011/6 "2019-10-22T20:52:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
