# Kibana 7.5 disable authentication

**URL:** <https://discuss.elastic.co/t/kibana-7-5-disable-authentication/213935>\
**Category:** Kibana\
**Created:** [January 6, 2020, 6:31pm UTC](https://discuss.elastic.co/t/kibana-7-5-disable-authentication/213935 "2020-01-06T18:31:02Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![J\_Warner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/j_warner/32/47016_2.png) [@J\_Warner](https://discuss.elastic.co/u/J_Warner)\
**Post date:** [January 6, 2020, 6:31pm UTC](https://discuss.elastic.co/t/kibana-7-5-disable-authentication/213935/1 "2020-01-06T18:31:02Z")

</div>

Hey

I've configured Elasticsearch for Anonymous access which works.  
but because of this I can't login inside of my kibana instance is there a way to disable the login auth screen for kibana ?

---

<div class="post-metadata">

**Author:** ![J\_Warner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/j_warner/32/47016_2.png) [@J\_Warner](https://discuss.elastic.co/u/J_Warner)\
**Post date:** [January 6, 2020, 6:32pm UTC](https://discuss.elastic.co/t/kibana-7-5-disable-authentication/213935/2 "2020-01-06T18:32:09Z")

</div>

🙂 its not my password but good catch

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [January 6, 2020, 7:21pm UTC](https://discuss.elastic.co/t/kibana-7-5-disable-authentication/213935/3 "2020-01-06T19:21:59Z")

</div>

I believe you are running into this issue: [https://github.com/elastic/kibana/issues/35613](https://github.com/elastic/kibana/issues/35613) There are some other related issues: [https://github.com/elastic/kibana/issues/18331](https://github.com/elastic/kibana/issues/18331) [https://github.com/elastic/kibana/issues/54023](https://github.com/elastic/kibana/issues/54023)

Reading through all of those, it seems like we are not recommending setting `xpack.security.disabled: false` in Kibana, but it's possible that that is what you are looking for.

---

<div class="post-metadata">

**Author:** ![J\_Warner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/j_warner/32/47016_2.png) [@J\_Warner](https://discuss.elastic.co/u/J_Warner)\
**Post date:** [January 6, 2020, 7:49pm UTC](https://discuss.elastic.co/t/kibana-7-5-disable-authentication/213935/4 "2020-01-06T19:49:59Z")

</div>

these are my setting for kibana.yaml

```
apiVersion: kibana.k8s.elastic.co/v1beta1
kind: Kibana
metadata:
  name: kibana
spec:
  version: 7.5.1
  count: 1
  elasticsearchRef:
    name: "elasticsearch"
  config:
    #xpack.security.anonymous.enable: true 
    elasticsearch.hosts: http://elasticsearch-es-http.<namespace>.local:9200
    # elasticsearch.username: "jamal"
    # elasticsearch.password: "jamal"
  http:
    tls:
      selfSignedCertificate:
        disabled: true

```

These are the setting for elasticsearch.yaml

```
apiVersion: elasticsearch.k8s.elastic.co/v1beta1
kind: Elasticsearch
metadata:
  name: elasticsearch
spec:
  version: 7.5.1
  nodeSets:
  - name: elastic
    count: 3
    volumeClaimTemplates:
    - metadata:
        name: elasticsearch-data
        parameters:
          type: pd-standard
      spec:
        accessModes:
        - ReadWriteOnce
        resources:
          requests:
            storage: 500Gi
        storageClassName: standard
    config:
      node.master: true
      node.data: true
      node.ingest: true
      node.store.allow_mmap: false
      xpack.security.authc: 
          anonymous:
            username: elastic
            roles: superuser, kibana_user
            authz_exception: false
  http:
    tls:
      selfSignedCertificate:
        disabled: true

```

but I can't login with any of the passwords ? even after I create a new user in elasticsearch with role kibana\_user

kibana doesn't allow you to authenticate the newly created user ?

---

<div class="post-metadata">

**Author:** ![J\_Warner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/j_warner/32/47016_2.png) [@J\_Warner](https://discuss.elastic.co/u/J_Warner)\
**Post date:** [January 6, 2020, 7:53pm UTC](https://discuss.elastic.co/t/kibana-7-5-disable-authentication/213935/5 "2020-01-06T19:53:19Z")

</div>

> [@J\_Warner](#):
>
> xpack.security.anonymous.enable: true

xpack.security.anonymous.enable: true  
this configuration is not actually valid and it doesn't work

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [January 6, 2020, 8:31pm UTC](https://discuss.elastic.co/t/kibana-7-5-disable-authentication/213935/6 "2020-01-06T20:31:53Z")

</div>

I'm going to ask some of the folks who work on this to take a look. Please change your password as you've pasted it here.

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [January 6, 2020, 8:54pm UTC](https://discuss.elastic.co/t/kibana-7-5-disable-authentication/213935/7 "2020-01-06T20:54:57Z")

</div>

Okay, got some more clarity.

> As a workaround, we generally recommend that users configure a reverse-proxy that hard-codes a username/password in the Authorization header so when accessing Kibana via the reverse-proxy they're automatically authenticated and can continue to use the user/role management screens and all of the other Kibana RBAC work

It seems like you're using the K8s operator, which might be why you can't disable the the security plugin. You may need to use a reverse proxy as suggested here.

---

<div class="post-metadata">

**Author:** ![J\_Warner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/j_warner/32/47016_2.png) [@J\_Warner](https://discuss.elastic.co/u/J_Warner)\
**Post date:** [January 6, 2020, 9:16pm UTC](https://discuss.elastic.co/t/kibana-7-5-disable-authentication/213935/8 "2020-01-06T21:16:35Z")

</div>

sounds good two things

there's an optional flag in the kibana.yaml file  
`xpack.security.enabled: false`

I'm guessing this is not valid cause I'm using the operator

At the end I don't want to authenticate whenever I'm making request to elasticsearch is there a way to only allow authentication from kibana and not from logstash

Unidirectional instead bidirectional

auth kibana ----\> elasticsearch ----\> no auth \<----- logstash

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [January 6, 2020, 11:24pm UTC](https://discuss.elastic.co/t/kibana-7-5-disable-authentication/213935/9 "2020-01-06T23:24:16Z")

</div>

If you don't use our official operator, you would be allowed to remove the security requirement. This is a leading source of unintentional data breaches due to having publicly available ES endpoints.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2020, 11:24pm UTC](https://discuss.elastic.co/t/kibana-7-5-disable-authentication/213935/10 "2020-02-03T23:24:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
