# KIbana Basic Auth Login

**URL:** <https://discuss.elastic.co/t/kibana-basic-auth-login/135894>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 14, 2018, 10:09am UTC](https://discuss.elastic.co/t/kibana-basic-auth-login/135894 "2018-06-14T10:09:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rob\_Davidson](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@Rob\_Davidson](https://discuss.elastic.co/u/Rob_Davidson)\
**Post date:** [June 14, 2018, 10:09am UTC](https://discuss.elastic.co/t/kibana-basic-auth-login/135894/1 "2018-06-14T10:09:13Z")

</div>

I'm looking to use the free version of Kibana, elastic, logstash stack. Will be using it to search for logs and eventually produce visualizations.

I would like the Kibana screen to have some basic authentication.

The docker compose I used is based on this one

> **[elastic/stack-docker](https://github.com/elastic/stack-docker)**
>
> stack-docker - The Elastic Stack, on Docker, right now.

However I changed the docker image from  
[docker.elastic.co/elasticsearch/elasticsearch-platinum](http://docker.elastic.co/elasticsearch/elasticsearch-platinum)

to this  
[docker.elastic.co/elasticsearch/elasticsearch](http://docker.elastic.co/elasticsearch/elasticsearch)

After doing this the login screen dissapeared from Kibana. Is the kibana login screen only available in platinum version?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [June 14, 2018, 10:14am UTC](https://discuss.elastic.co/t/kibana-basic-auth-login/135894/2 "2018-06-14T10:14:22Z")

</div>

Hi Rob,

XPack security is available, starting on GOLD license. Please take a look at our [subscriptions page](https://www.elastic.co/subscriptions) to see what features are available for each license.

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [June 15, 2018, 5:32am UTC](https://discuss.elastic.co/t/kibana-basic-auth-login/135894/3 "2018-06-15T05:32:30Z")

</div>

The simplest solution is to put NGiNX in front of it on the same host as Kibana. Have Kibana only listen to 127.0.0.1 and configure NGiNX to forward to it and handle authentication. You can do the same for Elasticsearch. Although we try to convince customers to use something commercial like X-Pack or ReadonlyREST, we will at a minimum use NGiNX.

Assuming normal linux setup for NGiNX you would but a file like this in `/etc/nginx/conf.d` :

```auto
server {
  listen 45601;
  server_name localhost;

  location / {
    proxy_pass http://localhost:5601;
  }  
  auth_basic "Please login...";
  auth_basic_user_file /etc/nginx/conf.d/elastic.passwd;
}

server {
  listen 49200;
  server_name localhost;
 
  location / {
    proxy_pass http://localhost:9200;
  }
  auth_basic "Please login...";
  auth_basic_user_file /etc/nginx/conf.d/elastic.passwd;
}

```

Use OpenSSL to generate passwords:

```auto
openssl passwd -crypt YOURPASS

```

Depending on your version of OpenSSL passwords may be limited to 8 characters.

Put these in the `elastic.passwd` file, specified above in the NGiNX config, like this:

```auto
youruser:yourpass
anotheruser:theirpass

```

Restart NGiNX.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2018, 5:32am UTC](https://discuss.elastic.co/t/kibana-basic-auth-login/135894/4 "2018-07-13T05:32:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
