# Kibana login page (Access control)

**URL:** https://discuss.elastic.co/t/kibana-login-page-access-control/190248
**Category:** Kibana
**Created:** [July 12, 2019, 1:25pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248 "2019-07-12T13:25:28Z")
**Posts on this page:** 19
**Page:** 1

<div class="post-metadata">

### Author: ![Rozita\_Mirmotalebi\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rozita_mirmotalebi_u/32/47247_2.png) [@Rozita\_Mirmotalebi\_U](https://discuss.elastic.co/u/Rozita_Mirmotalebi_U)
#### Post date: [July 12, 2019, 1:25pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/1 "2019-07-12T13:25:28Z")

</div>

Hello there,  
I have Elasticsearch (Version 1.30.0) and Kibana (Version 3.2.3) on Rancher. I am trying to enable the login page for security purposes. I have added the x-pack configs in Kibana. Also I tied enabling (pack.security.enabled: true) in both elasticsearch and Kibana, but it wont come up after adding. I also tried elasticsearch.username: "kibana", elasticsearch.password: "kibanapassword" in Kibana.yaml but it seems it doesn't pick it up as if I put random entry still comes up. Can you please let me know what I am missing?

Thanks!

---

<div class="post-metadata">

### Author: ![areyja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/areyja/32/50060_2.png) [@areyja](https://discuss.elastic.co/u/areyja)
#### Post date: [July 13, 2019, 1:45pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/2 "2019-07-13T13:45:11Z")

</div>

I believe you will have to setup password for system users first. Which then will enforce security on you Kibana login and enable you to configure more user roles etc as well going forward -

Command - "elasticsearch-setup-passwords interactive"  
Location - elastic bin directory

Use this link to get started - [https://www.elastic.co/guide/en/elastic-stack-overview/current/security-getting-started.html](https://www.elastic.co/guide/en/elastic-stack-overview/current/security-getting-started.html)

/a

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [July 13, 2019, 1:47pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/3 "2019-07-13T13:47:36Z")

</div>

None of thise version of Kibana or Elasticsearch exists, so please have a closer look at exactly what you are using. Without knowing the version it is hard to help with this.

---

<div class="post-metadata">

### Author: ![Rozita\_Mirmotalebi\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rozita_mirmotalebi_u/32/47247_2.png) [@Rozita\_Mirmotalebi\_U](https://discuss.elastic.co/u/Rozita_Mirmotalebi_U)
#### Post date: [July 15, 2019, 1:06pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/4 "2019-07-15T13:06:27Z")

</div>

I have them on Rancher and that is the version it is showing, you can find it in the attachment

 ![Version](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d4310f5c1db1e234c5e216e9c0ced93e30e69714.png)

Also I think here is the correct version: Elastic Search: Elasticsearch 6.0. Kibana version 7.

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [July 15, 2019, 3:51pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/5 "2019-07-15T15:51:50Z")

</div>

Elasticsearch and Kibana need to be of the same version. That combination will not work.

---

<div class="post-metadata">

### Author: ![Rozita\_Mirmotalebi\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rozita_mirmotalebi_u/32/47247_2.png) [@Rozita\_Mirmotalebi\_U](https://discuss.elastic.co/u/Rozita_Mirmotalebi_U)
#### Post date: [July 17, 2019, 4:47pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/6 "2019-07-17T16:47:51Z")

</div>

Both of them are 6.7.0. Can you please tell me now how to do it? Thanks

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [July 17, 2019, 4:52pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/7 "2019-07-17T16:52:38Z")

</div>

Security is only part of the free basic license from version 6.8 and 7.1 so 6.7 will not have this. You also need to ensure you are using the default distribution and not the oss one.

---

<div class="post-metadata">

### Author: ![Rozita\_Mirmotalebi\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rozita_mirmotalebi_u/32/47247_2.png) [@Rozita\_Mirmotalebi\_U](https://discuss.elastic.co/u/Rozita_Mirmotalebi_U)
#### Post date: [July 17, 2019, 9:49pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/8 "2019-07-17T21:49:59Z")

</div>

I have them on Rancher, any version (7.1.1 and 7.2.0) that I try fails for Elasticsearch. I can somehow update the Kibana but Elasticsearch fails. any idea please?

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [July 18, 2019, 4:57am UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/9 "2019-07-18T04:57:39Z")

</div>

What is the output if you go to Elasticsearch\_node:9200 ? I suspect you are using the OSS distribution.

---

<div class="post-metadata">

### Author: ![Rozita\_Mirmotalebi\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rozita_mirmotalebi_u/32/47247_2.png) [@Rozita\_Mirmotalebi\_U](https://discuss.elastic.co/u/Rozita_Mirmotalebi_U)
#### Post date: [July 18, 2019, 5:33pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/10 "2019-07-18T17:33:47Z")

</div>

Yes I am using oss: [docker.elastic.co/elasticsearch/elasticsearch-oss:7.1.1](http://docker.elastic.co/elasticsearch/elasticsearch-oss:7.1.1).  
I tried from Apps, Elasticsearch upgrade didnt work. Below is by upgrading workloads, Elasticsearch-client which failed as well.  
In [sysctl] log: vm.max\_map\_count = 262144 (shows terminated)  
in elastic search log: (shows notready)

7/18/2019 1:31:37 PM "at org.elasticsearch.cluster.ClusterStateObserver$ObserverClusterStateListener.onTimeout(ClusterStateObserver.java:249) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:37 PM "at org.elasticsearch.cluster.service.ClusterApplierService$NotifyTimeout.run(ClusterApplierService.java:555) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:37 PM "at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:681) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:37 PM "at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128) [?:?]",

7/18/2019 1:31:37 PM "at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628) [?:?]",

7/18/2019 1:31:37 PM "at java.lang.Thread.run(Thread.java:835) [?:?]"] }

7/18/2019 1:31:41 PM {"type": "server", "timestamp": "2019-07-18T17:31:41,405+0000", "level": "WARN", "component": "o.e.c.c.ClusterFormationFailureHelper", "cluster.name": "elasticsearch", "node.name": "elasticsearch-client-6d6ffbcc4c-4lt6d", "message": "master not discovered yet: have discovered ; discovery will continue using [10.42.2.10:9300, 10.42.0.13:9300, 10.42.1.23:9300] from hosts providers and [{elasticsearch-client-6d6ffbcc4c-4lt6d}{IBxQXRF5QIqCFi7ftdU9Qg}{OHXriPA5RD6YE0rV6tUXIg}{10.42.1.86}{10.42.1.86:9300}] from last-known cluster state; node term 0, last-accepted version 0 in term 0" }

7/18/2019 1:31:47 PM {"type": "server", "timestamp": "2019-07-18T17:31:47,299+0000", "level": "DEBUG", "component": "o.e.a.a.c.h.TransportClusterHealthAction", "cluster.name": "elasticsearch", "node.name": "elasticsearch-client-6d6ffbcc4c-4lt6d", "message": "no known master node, scheduling a retry" }

7/18/2019 1:31:47 PM {"type": "server", "timestamp": "2019-07-18T17:31:47,299+0000", "level": "DEBUG", "component": "o.e.a.a.c.h.TransportClusterHealthAction", "cluster.name": "elasticsearch", "node.name": "elasticsearch-client-6d6ffbcc4c-4lt6d", "message": "timed out while retrying [cluster:monitor/health] after failure (timeout [30s])" }

7/18/2019 1:31:47 PM {"type": "server", "timestamp": "2019-07-18T17:31:47,300+0000", "level": "WARN", "component": "r.suppressed", "cluster.name": "elasticsearch", "node.name": "elasticsearch-client-6d6ffbcc4c-4lt6d", "message": "path: /\_cluster/health, params: {}" ,

7/18/2019 1:31:47 PM "stacktrace": ["org.elasticsearch.discovery.MasterNotDiscoveredException: null",

7/18/2019 1:31:47 PM "at org.elasticsearch.action.support.master.TransportMasterNodeAction$AsyncSingleAction$4.onTimeout(TransportMasterNodeAction.java:259) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:47 PM "at org.elasticsearch.cluster.ClusterStateObserver$ContextPreservingListener.onTimeout(ClusterStateObserver.java:322) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:47 PM "at org.elasticsearch.cluster.ClusterStateObserver$ObserverClusterStateListener.onTimeout(ClusterStateObserver.java:249) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:47 PM "at org.elasticsearch.cluster.service.ClusterApplierService$NotifyTimeout.run(ClusterApplierService.java:555) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:47 PM "at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:681) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:47 PM "at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128) [?:?]",

7/18/2019 1:31:47 PM "at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628) [?:?]",

7/18/2019 1:31:47 PM "at java.lang.Thread.run(Thread.java:835) [?:?]"] }

7/18/2019 1:31:51 PM {"type": "server", "timestamp": "2019-07-18T17:31:51,405+0000", "level": "WARN", "component": "o.e.c.c.ClusterFormationFailureHelper", "cluster.name": "elasticsearch", "node.name": "elasticsearch-client-6d6ffbcc4c-4lt6d", "message": "master not discovered yet: have discovered ; discovery will continue using [10.42.2.10:9300, 10.42.0.13:9300, 10.42.1.23:9300] from hosts providers and [{elasticsearch-client-6d6ffbcc4c-4lt6d}{IBxQXRF5QIqCFi7ftdU9Qg}{OHXriPA5RD6YE0rV6tUXIg}{10.42.1.86}{10.42.1.86:9300}] from last-known cluster state; node term 0, last-accepted version 0 in term 0" }

7/18/2019 1:31:57 PM {"type": "server", "timestamp": "2019-07-18T17:31:57,299+0000", "level": "DEBUG", "component": "o.e.a.a.c.h.TransportClusterHealthAction", "cluster.name": "elasticsearch", "node.name": "elasticsearch-client-6d6ffbcc4c-4lt6d", "message": "no known master node, scheduling a retry" }

7/18/2019 1:31:57 PM {"type": "server", "timestamp": "2019-07-18T17:31:57,302+0000", "level": "DEBUG", "component": "o.e.a.a.c.h.TransportClusterHealthAction", "cluster.name": "elasticsearch", "node.name": "elasticsearch-client-6d6ffbcc4c-4lt6d", "message": "timed out while retrying [cluster:monitor/health] after failure (timeout [30s])" }

7/18/2019 1:31:57 PM {"type": "server", "timestamp": "2019-07-18T17:31:57,302+0000", "level": "WARN", "component": "r.suppressed", "cluster.name": "elasticsearch", "node.name": "elasticsearch-client-6d6ffbcc4c-4lt6d", "message": "path: /\_cluster/health, params: {}" ,

7/18/2019 1:31:57 PM "stacktrace": ["org.elasticsearch.discovery.MasterNotDiscoveredException: null",

7/18/2019 1:31:57 PM "at org.elasticsearch.action.support.master.TransportMasterNodeAction$AsyncSingleAction$4.onTimeout(TransportMasterNodeAction.java:259) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:57 PM "at org.elasticsearch.cluster.ClusterStateObserver$ContextPreservingListener.onTimeout(ClusterStateObserver.java:322) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:57 PM "at org.elasticsearch.cluster.ClusterStateObserver$ObserverClusterStateListener.onTimeout(ClusterStateObserver.java:249) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:57 PM "at org.elasticsearch.cluster.service.ClusterApplierService$NotifyTimeout.run(ClusterApplierService.java:555) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:57 PM "at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:681) [elasticsearch-7.1.1.jar:7.1.1]",

7/18/2019 1:31:57 PM "at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128) [?:?]",

7/18/2019 1:31:57 PM "at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628) [?:?]",

7/18/2019 1:31:57 PM "at java.lang.Thread.run(Thread.java:835) [?:?]"] }

---

<div class="post-metadata">

### Author: ![Rozita\_Mirmotalebi\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rozita_mirmotalebi_u/32/47247_2.png) [@Rozita\_Mirmotalebi\_U](https://discuss.elastic.co/u/Rozita_Mirmotalebi_U)
#### Post date: [July 18, 2019, 5:50pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/11 "2019-07-18T17:50:28Z")

</div>

Also I tried clonning, this time by passing the appVersion and image.tag. But get below error now:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/b/3b7c91bb568030c55ae55b4b41dea348dd9519e9.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/7/b70981e2c652e380cebeef0d4a6f22f1547752fd.png)

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [July 18, 2019, 6:19pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/12 "2019-07-18T18:19:13Z")

</div>

You need to use the default distribution. I do not know Rancher though, so can not give any specific advise there.

---

<div class="post-metadata">

### Author: ![Rozita\_Mirmotalebi\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rozita_mirmotalebi_u/32/47247_2.png) [@Rozita\_Mirmotalebi\_U](https://discuss.elastic.co/u/Rozita_Mirmotalebi_U)
#### Post date: [July 22, 2019, 8:11pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/13 "2019-07-22T20:11:30Z")

</div>

Thanks a lot.

---

<div class="post-metadata">

### Author: ![Rozita\_Mirmotalebi\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rozita_mirmotalebi_u/32/47247_2.png) [@Rozita\_Mirmotalebi\_U](https://discuss.elastic.co/u/Rozita_Mirmotalebi_U)
#### Post date: [July 23, 2019, 6:08pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/14 "2019-07-23T18:08:11Z")

</div>

Quick question, now I am trying EFK, with version oss:7.2.0. Does this version have the login page enabled? Thanks

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [July 23, 2019, 6:55pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/15 "2019-07-23T18:55:05Z")

</div>

No, it does not.

---

<div class="post-metadata">

### Author: ![Rozita\_Mirmotalebi\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rozita_mirmotalebi_u/32/47247_2.png) [@Rozita\_Mirmotalebi\_U](https://discuss.elastic.co/u/Rozita_Mirmotalebi_U)
#### Post date: [July 23, 2019, 7:20pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/16 "2019-07-23T19:20:38Z")

</div>

Thanks, so these are the versions I am using and they don't have Access login enabled there:  
[docker.elastic.co/kibana/kibana-oss:7.2.0](http://docker.elastic.co/kibana/kibana-oss:7.2.0)  
[docker.elastic.co/elasticsearch/elasticsearch-oss:7.2.0](http://docker.elastic.co/elasticsearch/elasticsearch-oss:7.2.0)  
I was wondering if I can get the licensed version on Rancher (like trial) and try it there? Any idea please? Thanks

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [July 23, 2019, 7:25pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/17 "2019-07-23T19:25:27Z")

</div>

Anyone can download them from the Elastic website. If you need to get it from Rancher I guess it is up to them. You may have to ask there.

---

<div class="post-metadata">

### Author: ![Rozita\_Mirmotalebi\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rozita_mirmotalebi_u/32/47247_2.png) [@Rozita\_Mirmotalebi\_U](https://discuss.elastic.co/u/Rozita_Mirmotalebi_U)
#### Post date: [August 16, 2019, 8:32pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/18 "2019-08-16T20:32:10Z")

</div>

Hi Christian,  
Thanks a lot for the reply. So, I finally could install Elasticsearch and Kibana (7.2.0) on Rancher. I have the trial version of the Kibana and I am trying to add the xpack.security.enabled: true on Elasticsearch and for some reason after adding this it fails and won't start. Can you please help me if I am missing anything here? Thanks

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 13, 2019, 8:32pm UTC](https://discuss.elastic.co/t/kibana-login-page-access-control/190248/19 "2019-09-13T20:32:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
