# Kibana LDAP authentication via apache proxy

**URL:** <https://discuss.elastic.co/t/kibana-ldap-authentication-via-apache-proxy/312385>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [August 18, 2022, 12:33pm UTC](https://discuss.elastic.co/t/kibana-ldap-authentication-via-apache-proxy/312385 "2022-08-18T12:33:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![thirty2](https://avatars.discourse-cdn.com/v4/letter/t/a9a28c/32.png) [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Post date:** [August 18, 2022, 12:33pm UTC](https://discuss.elastic.co/t/kibana-ldap-authentication-via-apache-proxy/312385/1 "2022-08-18T12:33:31Z")

</div>

Hi,

with xpack and TLS for elasticserach + kibana disable i can use ldap authentication via apache. I can login to kibana with my ldap account.

Kibana config:

```auto
server.port: 5601
server.host: "myhost"
elasticsearch.hosts: ["http://myhost:9200"]

```

Apache config:

```auto
ProxyPreserveHost On
ProxyRequests On
ProxyPass / http://myhost:5601/
ProxyPassReverse / myhost:5601/

```

When i enable xpack + TSL for elasticserach , i got login prompt from Kibana but it doest not authenticate me and i am getting this error in kibana log:

_{"type":"log","@timestamp":"2022-08-18T08:52:06+00:00","tags":["info","plugins","security","authentication"],"pid":15222,"message":"Authentication attempt failed: {"error":{"root\_cause":[{"type":"security\_exception","reason":"unable to authenticate user [] for REST request [/\_security/\_authenticate]","header":{"WWW-Authenticate":["Basic realm=\"security\" charset=\"UTF-8\"","Bearer realm=\"security\"","ApiKey"]}}],"type":"security\_exception","reason":"unable to authenticate user [] for REST request [/\_security/\_authenticate]","header":{"WWW-Authenticate":["Basic realm=\"security\" charset=\"UTF-8\"","Bearer realm=\"security\"","ApiKey"]}},"status":401}"}_

and url then looks like this: _/login?msg=UNAUTHENTICATED&next=%2Fapp%2Fkibana_

Kibana config:

```auto
server.port: 5601
server.host: "myhost"
elasticsearch.hosts: ["https://myhost:9200"]
elasticsearch.username: "kibana_system"
elasticsearch.password: "password"
elasticsearch.ssl.certificateAuthorities: ["/etc/kibana/certs/elasticsearch-ca.pem"]
server.ssl.enabled: true
server.ssl.certificate: /etc/kibana/certs/myhost.crt
server.ssl.key: /etc/kibana/certs/myhost.key
xpack.encryptedSavedObjects.encryptionKey: 94b33f3aac75ff4de33e0f96d571d2ac1
xpack.reporting.encryptionKey: 5f2e646cb037823edr34af0841fa0e20
xpack.security.encryptionKey: 9024c01f834159c23aew23de5d8fd7d

```

What is wrong with my confiugration? did i forgot anything? Why ldap authnetication is working with xpack disable and not working with xpack enabled?

Thank you for any hint.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [August 22, 2022, 5:34am UTC](https://discuss.elastic.co/t/kibana-ldap-authentication-via-apache-proxy/312385/2 "2022-08-22T05:34:03Z")

</div>

> [@thirty2](#):
>
> with xpack and TLS for elasticserach + kibana disable i can use ldap authentication via apache. I can login to kibana with my ldap account.
> 
> Why ldap authnetication is working with xpack disable and not working with xpack enabled?

What do you mean by `xpack`? Do you mean xpack security? If it was disabled, I don't know how you were able to login with ldap.

---

<div class="post-metadata">

**Author:** ![thirty2](https://avatars.discourse-cdn.com/v4/letter/t/a9a28c/32.png) [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Post date:** [August 22, 2022, 6:44am UTC](https://discuss.elastic.co/t/kibana-ldap-authentication-via-apache-proxy/312385/3 "2022-08-22T06:44:56Z")

</div>

Yes, xpack.security. By ldap i mean not direct ldap intergration. In my case authentication is done via apache.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [August 22, 2022, 7:13am UTC](https://discuss.elastic.co/t/kibana-ldap-authentication-via-apache-proxy/312385/4 "2022-08-22T07:13:55Z")

</div>

You might want to consider elasticsearch's official support of LDAP integration [LDAP user authentication | Elasticsearch Guide [8.3] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/ldap-realm.html)

---

<div class="post-metadata">

**Author:** ![thirty2](https://avatars.discourse-cdn.com/v4/letter/t/a9a28c/32.png) [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Post date:** [August 22, 2022, 7:27am UTC](https://discuss.elastic.co/t/kibana-ldap-authentication-via-apache-proxy/312385/5 "2022-08-22T07:27:57Z")

</div>

Yes, but not with Free version.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2022, 7:28am UTC](https://discuss.elastic.co/t/kibana-ldap-authentication-via-apache-proxy/312385/6 "2022-09-19T07:28:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
