# Kibana can't reach Elasticsearch cluster with security enabled

**URL:** <https://discuss.elastic.co/t/kibana-cant-reach-elasticsearch-cluster-with-security-enabled/198841>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [September 10, 2019, 7:51am UTC](https://discuss.elastic.co/t/kibana-cant-reach-elasticsearch-cluster-with-security-enabled/198841 "2019-09-10T07:51:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![BenP](https://avatars.discourse-cdn.com/v4/letter/b/c37758/32.png) [@BenP](https://discuss.elastic.co/u/BenP)\
**Post date:** [September 10, 2019, 7:51am UTC](https://discuss.elastic.co/t/kibana-cant-reach-elasticsearch-cluster-with-security-enabled/198841/1 "2019-09-10T07:51:07Z")

</div>

Hi,

Since I reverted from my trial license to a basic one, Kibana can't reach my Elasticsearch cluster as long as "xpack.security.enabled: true". From what I understood, I must configure "at least" TLS between my nodes and I followed the instructions here : [Encrypting communications in Elasticsearch](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/configuring-tls.html) but I still have the same error.  
I'm probably missing something simple but I can't find it.

kibana.log :

> {"type":"log","@timestamp":"2019-09-10T07:46:43Z","tags":["warning","elasticsearch","admin"],"pid":1275,"message":"No living connections"}  
> {"type":"log","@timestamp":"2019-09-10T07:46:43Z","tags":["warning","elasticsearch","admin"],"pid":1275,"message":"Unable to revive connection: [http://10.1.0.4:9200/](http://10.1.0.4:9200/)"}

kibana.yml :

> elasticsearch.hosts: "[http://10.1.0.4:9200](http://10.1.0.4:9200)"  
> server.host: 10.1.0.7  
> logging.dest: /var/log/kibana.log  
> logging.quiet: false  
> elasticsearch.username: "kibana"  
> elasticsearch.password: "mypassword"  
> xpack.security.encryptionKey: "longkey"  
> xpack.reporting.encryptionKey: "longkey"

elasticsearch.hosts point to my internal load balancer.  
Do I have to use TLS between Kibana and my nodes too ?

elasticsearch.yml :

> cluster.name: "elastic-dev"  
> node.name: "devdata-0"  
> path.logs: /var/log/elasticsearch  
> path.data: /datadisks/disk1/elasticsearch/data  
> discovery.zen.ping.unicast.hosts: ["devdata-0:9300","devdata-1:9300","devdata-2:9300"]  
> node.master: true  
> node.data: true  
> discovery.zen.minimum\_master\_nodes: 2  
> #network.host: [_site_, _local_]  
> network.host: 0.0.0.0  
> node.max\_local\_storage\_nodes: 1  
> node.attr.fault\_domain: 0  
> node.attr.update\_domain: 0  
> cluster.routing.allocation.awareness.attributes: fault\_domain,update\_domain  
> xpack.license.self\_generated.type: basic  
> xpack.security.enabled: true  
> xpack.security.transport.ssl.enabled: true  
> xpack.security.transport.ssl.verification\_mode: full  
> xpack.security.transport.ssl.keystore.path: ${node.name}.p12  
> xpack.security.transport.ssl.truststore.path: ${node.name}.p12  
> bootstrap.memory\_lock: true

Everything is hosted on Azure and have been deployed thanks to the deployment template on Azure Marketplace.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 10, 2019, 8:15am UTC](https://discuss.elastic.co/t/kibana-cant-reach-elasticsearch-cluster-with-security-enabled/198841/2 "2019-09-10T08:15:42Z")

</div>

Is Elasticsearch running at all ? If it is please check the logs, I would assume you will find a few errors in there that would point you to the actual issue at hand.

---

<div class="post-metadata">

**Author:** ![BenP](https://avatars.discourse-cdn.com/v4/letter/b/c37758/32.png) [@BenP](https://discuss.elastic.co/u/BenP)\
**Post date:** [September 10, 2019, 8:58am UTC](https://discuss.elastic.co/t/kibana-cant-reach-elasticsearch-cluster-with-security-enabled/198841/3 "2019-09-10T08:58:56Z")

</div>

Look like you were right, I had a permission issue on my .p12 files preventing Elasticsearch to start.

I resolved it and now I it looks like I have messed up the password I entered when I ran :  
`bin/elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure_password`

Since I'm getting in elasticsearch logs :

> java.io.IOException: keystore password was incorrect

---

<div class="post-metadata">

**Author:** ![BenP](https://avatars.discourse-cdn.com/v4/letter/b/c37758/32.png) [@BenP](https://discuss.elastic.co/u/BenP)\
**Post date:** [September 10, 2019, 12:37pm UTC](https://discuss.elastic.co/t/kibana-cant-reach-elasticsearch-cluster-with-security-enabled/198841/4 "2019-09-10T12:37:21Z")

</div>

I solved my certificate problem but now Kibana is throwing an error when I'm logging in with the kibana user :  
`{"statusCode":403,"error":"Forbidden","message":"Forbidden"}`

The kibana user permissions haven't changed so I don't get why it would throw a "Forbidden".

EDIT: I just tried to login with the elastic user and it works.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 10, 2019, 1:07pm UTC](https://discuss.elastic.co/t/kibana-cant-reach-elasticsearch-cluster-with-security-enabled/198841/5 "2019-09-10T13:07:47Z")

</div>

Just so that this is clear for others reading the forums, you are not supposed to log in with the `kibana` user. This is the internal user that Kibana server uses to communicate with Elasticsearch.

One should log in with the `elastic` user first and then create all the necessary users they would need to operate/administer/use the cluster and log in with those from then on.

---

<div class="post-metadata">

**Author:** ![BenP](https://avatars.discourse-cdn.com/v4/letter/b/c37758/32.png) [@BenP](https://discuss.elastic.co/u/BenP)\
**Post date:** [September 10, 2019, 1:13pm UTC](https://discuss.elastic.co/t/kibana-cant-reach-elasticsearch-cluster-with-security-enabled/198841/6 "2019-09-10T13:13:53Z")

</div>

Well, thanks a lot for your time, my problem is solved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 8, 2019, 1:13pm UTC](https://discuss.elastic.co/t/kibana-cant-reach-elasticsearch-cluster-with-security-enabled/198841/7 "2019-10-08T13:13:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
