# Kibana not loading after providing credential, It is coming back to login page itself

**URL:** <https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086>\
**Category:** Kibana\
**Created:** [March 12, 2021, 12:47pm UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086 "2021-03-12T12:47:33Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![r\_aravind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/r_aravind/32/81763_2.png) [@r\_aravind](https://discuss.elastic.co/u/r_aravind)\
**Post date:** [March 12, 2021, 12:47pm UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086/1 "2021-03-12T12:47:33Z")

</div>

I have setup my ELK stack kibana instance in Azure kubernetes. I have exposed my kibana service to external load balancer and accessing the load balancer service using DNS from NGINX ingress.

I have tried accessing elastic search endpoint using below cmd , it is giving me resopnse  
curl --cacert tls.crt -u elastic:$PW https://:9200$NAME-es-http/

After clearing browser cache (I tried in both chrome and edge latest version browser)

When i try to hit the DNS

Welcome to Elastic page is loading correctly without any console error.

Then after i tried logging in using the username -elastic and corresponding generated password.

it again downloading some 21.5 MB resource in console again showing the same login page to enter credential.

Please help me to solve this

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [March 12, 2021, 3:46pm UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086/2 "2021-03-12T15:46:03Z")

</div>

What version of Chrome and what version of the stack you are using?  
Can you try in an incognito window /any other browser ? Do the logs say anything ?

---

<div class="post-metadata">

**Author:** ![r\_aravind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/r_aravind/32/81763_2.png) [@r\_aravind](https://discuss.elastic.co/u/r_aravind)\
**Post date:** [March 12, 2021, 5:29pm UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086/3 "2021-03-12T17:29:06Z")

</div>

My chrome version is Version 89.0.4389.82 (Official Build) (64-bit)

I also tried in incognito window same problem.

I checked kibana pod log also no errors.

As suggested in another discussion i have used  
xpack.security.sameSiteCookies : None

under my config section of my kibana yaml

That gives me internal server down so i removed it.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [March 12, 2021, 5:34pm UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086/4 "2021-03-12T17:34:05Z")

</div>

What do the kibana logs say ?  
Can you try in Firefox ?

---

<div class="post-metadata">

**Author:** ![r\_aravind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/r_aravind/32/81763_2.png) [@r\_aravind](https://discuss.elastic.co/u/r_aravind)\
**Post date:** [March 13, 2021, 5:05pm UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086/5 "2021-03-13T17:05:31Z")

</div>

Kibana pod log is continuously generating not able track the logs.

Is anyother place i need to check the log for kubernetes pod ??

---

<div class="post-metadata">

**Author:** ![r\_aravind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/r_aravind/32/81763_2.png) [@r\_aravind](https://discuss.elastic.co/u/r_aravind)\
**Post date:** [March 15, 2021, 9:41am UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086/6 "2021-03-15T09:41:33Z")

</div>

only error we are getting is in UI "Your browser does not meet the security requirements for Kibana."

And we also tried in firefox same issue,

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e9b824d2d6273b9f1096e3c9c469ede56795f9e7.png)

In console alone we are getting below warning

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fbbca289043d91ff32b336ac5e3dce9c64608533.png)

---

<div class="post-metadata">

**Author:** ![r\_aravind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/r_aravind/32/81763_2.png) [@r\_aravind](https://discuss.elastic.co/u/r_aravind)\
**Post date:** [March 15, 2021, 10:52am UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086/7 "2021-03-15T10:52:21Z")

</div>

Below message we got in kibana pod looks suspicious.

{"type":"response","@timestamp":"2021-03-13T07:46:03Z","tags":,"pid":7,"method":"post","statusCode":401,"req":{"url":"/internal/security/login","method":"post","headers":{"host":"[xxx-dev-xxx.xxxxx.com](http://xxx-dev-xxx.xxxxx.com)","x-real-ip":"xx.x.x.xx","x-forwarded-for":"xx.0.5.xx","x-forwarded-host":"[xxxx-dev-xx.xxx.com](http://xxxx-dev-xx.xxx.com)","x-forwarded-port":"443","x-forwarded-proto":"https","connection":"close","content-length":"190","sec-ch-ua":""Google Chrome";v="89", "Chromium";v="89", ";Not A Brand";v="99"","sec-ch-ua-mobile":"?0","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.82 Safari/537.36 managedpc (xxxxxxx)","kbn-version":"7.10.1","content-type":"application/json","accept":"_/_","origin":"[https://xxxxx-dev-xx.xxxx.com](https://xxxxx-dev-xx.xxxx.com)","sec-fetch-site":"same-origin","sec-fetch-mode":"cors","sec-fetch-dest":"empty","referer":"[https://xxxx-dev-xx.xxxx.com/login?next=%2F","accept-encoding":"gzip](https://xxxx-dev-xx.xxxx.com/login?next=%2F%22,%22accept-encoding%22:%22gzip), deflate, br","accept-language":"en-US,en;q=0.9"},"remoteAddress":"xx.0.5.xx","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.82 Safari/537.36 managedpc (xxxxxxx)","referer":"[https://xx-dev-xx.xxxx.com/login?next=%2F"},"res":{"statusCode":401,"responseTime":24,"contentLength":9},"message":"POST](https://xx-dev-xx.xxxx.com/login?next=%2F%22%7D,%22res%22:%7B%22statusCode%22:401,%22responseTime%22:24,%22contentLength%22:9%7D,%22message%22:%22POST) /internal/security/login 401 24ms - 9.0B"}

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [March 15, 2021, 3:01pm UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086/8 "2021-03-15T15:01:01Z")

</div>

Kibana shows this message if a browser doesn't support [content-security-policy](https://w3c.github.io/webappsec-csp/). Which shouldn't be a problem for all the modern browsers except IE11.

Do you have a proxy in front of Kibana that could affect set CSP headers?  
More details: [Provide a doc link to IE 11 users when showing "Your browser does not meet the security requirements.." · Issue #38781 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/38781)

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![r\_aravind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/r_aravind/32/81763_2.png) [@r\_aravind](https://discuss.elastic.co/u/r_aravind)\
**Post date:** [March 17, 2021, 6:10pm UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086/9 "2021-03-17T18:10:35Z")

</div>

yes we have defined below set of proxy rules,

annotations:  
[kubernetes.io/ingress.class:](http://kubernetes.io/ingress.class:) nginx  
[nginx.org/client-max-body-size:](http://nginx.org/client-max-body-size:) 4m  
[nginx.org/proxy-connect-timeout:](http://nginx.org/proxy-connect-timeout:) 30s  
[nginx.org/proxy-read-timeout:](http://nginx.org/proxy-read-timeout:) 20s  
#[nginx.ingress.kubernetes.io/backend-protocol:](http://nginx.ingress.kubernetes.io/backend-protocol:) "HTTPS"  
#[nginx.org/redirect-to-https:](http://nginx.org/redirect-to-https:) "True"  
#[ingress.kubernetes.io/ssl-redirect:](http://ingress.kubernetes.io/ssl-redirect:) "True"  
[nginx.org/server-snippets:](http://nginx.org/server-snippets:) |  
add\_header X-Frame-Options SAMEORIGIN always;  
add\_header X-Content-Type-Options nosniff always;  
add\_header Cache-Control "private, max-age=31536000" always;  
add\_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;  
add\_header Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval'; connect-src https://_.XXX.com https://_.elastic.co [https://grafana.com](https://grafana.com) 'unsafe-inline' blob:; worker-src https://\*.XXX.com 'unsafe-inline' blob:; img-src 'self' data:; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' ; font-src 'self' data:; block-all-mixed-content; upgrade-insecure-requests" always;  
add\_header X-XSS-Protection "1; mode=block" always;  
location = /robots.txt {  
return 200 "User-agent: \*\nDisallow: /\n";  
}

```
nginx.org/location-snippets: |
  proxy_hide_header Cache-Control;
  proxy_hide_header Content-Security-Policy;

```

pls let me know if above headers are blocking anything

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2021, 6:11pm UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086/10 "2021-04-14T18:11:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [May 3, 2021, 5:06pm UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086/11 "2021-05-03T17:06:17Z")

</div>

@LeeDr / @jbudz - any idea why this would be ?

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [May 3, 2021, 7:53pm UTC](https://discuss.elastic.co/t/kibana-not-loading-after-providing-credential-it-is-coming-back-to-login-page-itself/267086/12 "2021-05-03T19:53:43Z")

</div>

I would advise removing the CSP headers at the proxy level as a starting point. The error occurs during a CSP validation phase from Kibana. Kibana willl attach it's own requirements if they're forwarded.

Is there a requirement to have these enforced by the proxy?
