# Kibana not starting for enabling AD security

**URL:** <https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [September 13, 2019, 11:27am UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417 "2019-09-13T11:27:45Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![bharat1](https://avatars.discourse-cdn.com/v4/letter/b/49beb7/32.png) [@bharat1](https://discuss.elastic.co/u/bharat1)\
**Post date:** [September 13, 2019, 11:27am UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/1 "2019-09-13T11:27:45Z")

</div>

Dear All,  
Recently enabled elasticsearch with AD with xpack and able to authenticate successfully via curl command. Kibana is not properly starting up, any help will be appreciated. My intention is to have Kibana secured with AD

```auto
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","root"],"pid":10664,"message":"setting up root"}
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","server"],"pid":10664,"message":"setting up server"}
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","http"],"pid":10664,"message":"starting NotReady server"}
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","http","server","Kibana"],"pid":10664,"message":"registering route handler for [/core]"}
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","elasticsearch-service"],"pid":10664,"message":"Setting up elasticsearch service"}
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","elasticsearch-service"],"pid":10664,"message":"Creating elasticsearch clients"}
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","plugins-service"],"pid":10664,"message":"Setting up plugins service"}
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","plugins-discovery"],"pid":10664,"message":"Discovering plugins..."}
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","plugins-discovery"],"pid":10664,"message":"Scanning \"/usr/share/kibana/src/plugins\" for plugin sub-directories..."}
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","plugins-discovery"],"pid":10664,"message":"Scanning \"/usr/share/kibana/x-pack/plugins\" for plugin sub-directories..."}
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","plugins-discovery"],"pid":10664,"message":"Scanning \"/usr/share/kibana/plugins\" for plugin sub-directories..."}
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","plugins-discovery"],"pid":10664,"message":"Scanning \"/usr/share/kibana-extra\" for plugin sub-directories..."}
{"type":"log","@timestamp":"2019-09-12T18:35:13Z","tags":["debug","plugins-discovery"],"pid":10664,"message":"Successfully discovered plugin \"translations\" at \"/usr/share/kibana/x-pack/plugins/translations\""}
{"type":"log","@timestamp":"2019-09-12T18:35:14Z","tags":["debug","plugins","translations"],"pid":10664,"message":"\"/usr/share/kibana/x-pack/plugins/translations/server\" does not export \"config\"."}
{"type":"log","@timestamp":"2019-09-12T18:35:14Z","tags":["debug","plugins-service"],"pid":10664,"message":"Discovered 1 plugins."}
{"type":"log","@timestamp":"2019-09-12T18:35:14Z","tags":["info","plugins-system"],"pid":10664,"message":"Setting up [1] plugins: [translations]"}
{"type":"log","@timestamp":"2019-09-12T18:35:14Z","tags":["debug","plugins-system"],"pid":10664,"message":"Setting up plugin \"translations\"..."}
{"type":"log","@timestamp":"2019-09-12T18:35:14Z","tags":["debug","plugins","translations"],"pid":10664,"message":"Initializing plugin"}
{"type":"log","@timestamp":"2019-09-12T18:35:14Z","tags":["info","plugins","translations"],"pid":10664,"message":"Setting up plugin"}
{"type":"log","@timestamp":"2019-09-12T18:35:14Z","tags":["debug","root"],"pid":10664,"message":"starting root"}
{"type":"log","@timestamp":"2019-09-12T18:35:14Z","tags":["debug","plugins-service"],"pid":10664,"message":"Plugins service starts plugins"}
{"type":"log","@timestamp":"2019-09-12T18:35:14Z","tags":["info","plugins-system"],"pid":10664,"message":"Starting [1] plugins: [translations]"}
{"type":"log","@timestamp":"2019-09-12T18:35:14Z","tags":["debug","plugins-system"],"pid":10664,"message":"Starting plugin \"translations\"..."}
{"type":"log","@timestamp":"2019-09-12T18:35:14Z","tags":["debug","legacy-service"],"pid":10664,"message":"starting legacy service"}
{"type":"log","@timestamp":"2019-09-12T18:35:17Z","tags":["plugin","debug"],"pid":10664,"path":"/usr/share/kibana/x-pack","message":"Found plugin at /usr/share/kibana/x-pack"}
{"type":"log","@timestamp":"2019-09-12T18:35:17Z","tags":["plugin","debug"],"pid":10664,"path":"/usr/share/kibana/src/legacy/core_plugins/apm_oss","message":"Found plugin at /usr/share/kibana/src/legacy/core_plugins/apm_oss"}
{"type":"log","@timestamp":"2019-09-12T18:35:17Z","tags":["debug","root"],"pid":10664,"message":"shutting root down"}

```

Another thing noticed that '.security' index is also not present/available not sure whether it had been created initially when ES was enabled for security

```auto
[2019-09-13T04:21:22,099][INFO][o.e.x.s.a.s.m.NativeRoleMappingStore] [eshost] The security index is not yet available - no role mappings can be loaded
[2019-09-13T04:21:22,100][DEBUG][o.e.x.s.a.s.m.NativeRoleMappingStore] [eshost] Security Index [.security] [exists: false] [available: false] [mapping up to date: true]

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 13, 2019, 12:04pm UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/2 "2019-09-13T12:04:32Z")

</div>

I doubt this has anything to do with Active Directory in Elasticsearch, but please share your `kibana.yml` configuration with us. Is the above all you can see in the kibana logs?

---

<div class="post-metadata">

**Author:** ![bharat1](https://avatars.discourse-cdn.com/v4/letter/b/49beb7/32.png) [@bharat1](https://discuss.elastic.co/u/bharat1)\
**Post date:** [September 13, 2019, 2:45pm UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/3 "2019-09-13T14:45:14Z")

</div>

Yes these are the logs getting repeated

```auto
server.port: 8882
server.host: "eshost"
server.name: "eshost"
elasticsearch.hosts: ["http://eshost:9200"]
kibana.index: ".kibana"
kibana.defaultAppId: "discover"
logging.dest: /var/log/kibana.log
logging.verbose: true
xpack.security.enabled: true
xpack.security.audit.enabled: true

```

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [September 13, 2019, 3:35pm UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/4 "2019-09-13T15:35:07Z")

</div>

Kibana doesn't have support for AD authentication yet, so you still need to have native realm users specified in your kibana.yml as your ES username and password. Is that the case for you?

---

<div class="post-metadata">

**Author:** ![bharat1](https://avatars.discourse-cdn.com/v4/letter/b/49beb7/32.png) [@bharat1](https://discuss.elastic.co/u/bharat1)\
**Post date:** [September 13, 2019, 4:15pm UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/5 "2019-09-13T16:15:59Z")

</div>

ok I do not know about its limitations yet. Yes I have my elasticsearch integrated with AD.  
So what changes required to get the kibana also follow similar pattern so that only ELKadmins can have admin access to entire cluster, and different groups & users to have access to their respective indices where some users/groups have full control of their index and some users have only read only mode.

> [@Marius\_Dragomir](#):
>
> need to have native realm users specified in your kibana.yml as your ES username and password

Do you mean the user using which the ES was integrated that user name should be mentioned in kibana.yml as well as kibana keystore? secondly I am using keystore in ES so in that case how to mention keystore in kibana.yml?

Please note - since my kibana is not up I need to make changes in config files only

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [September 13, 2019, 4:17pm UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/6 "2019-09-13T16:17:50Z")

</div>

The first answer here is still valid for 7.x regarding AD and Kibana: [Kibana 5.3.0 Active Directory authentication](https://discuss.elastic.co/t/kibana-5-3-0-active-directory-authentication/82289)

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 13, 2019, 6:49pm UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/7 "2019-09-13T18:49:41Z")

</div>

You need to [setup the passwords of the built in users](https://www.elastic.co/guide/en/elastic-stack-overview/current/built-in-users.html#set-built-in-user-passwords) \*\*, `kibana` user is one of them.

Once you have set the password for it, then you would add

```auto
elasticsearch.username: kibana 
elasticsearch.password: thepasswordyousethere

```

in kibana.yml and start it again.

\*\* doing so will also automatically create the .security index as we discussed in the other post .

---

<div class="post-metadata">

**Author:** ![bharat1](https://avatars.discourse-cdn.com/v4/letter/b/49beb7/32.png) [@bharat1](https://discuss.elastic.co/u/bharat1)\
**Post date:** [September 13, 2019, 7:48pm UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/8 "2019-09-13T19:48:41Z")

</div>

> [@ikakavas](#):
>
> You need to [setup the passwords of the built in users](https://www.elastic.co/guide/en/elastic-stack-overview/current/built-in-users.html#set-built-in-user-passwords)

But these steps are for local user authentication only right? If i want to use custom user accounts and we have those in AD then how do I give every individual access to kibana dashboards? Consider I have 50 users

One more question clicked here, are all these account names mentioned in link that you posted are service accounts? and they should also be created in AD as is?

> [@ikakavas](#):
>
> elasticsearch.password: thepasswordyousethere

1. If I want to use keystore then how do I mention here?
2. In previous response by 'marius\_dragomir'

> [@Marius\_Dragomir](#):
>
> so you still need to have native realm users specified in your kibana.yml as your ES username and password.

When he refers 'native realm' does it mean service account name such as 'elastic' , 'kibana' , 'logstash\_user' etc... or the one who is authorized to tie a knot in AD with elasticsearch like we used the account for elasticsearch present in AD as administrator?

I do have several other questions revolving around these should I ask?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 13, 2019, 8:01pm UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/10 "2019-09-13T20:01:11Z")

</div>

Starting of, I think you will find our documentation very helpful. Most of your questions can be answered with information from there and this will also enhance your understanding of how and why things are set up in a certain way. You can search on [www.elastic.co](http://www.elastic.co) for any topic that you want to learn more about !

> But these steps are for local user authentication only right?

These are builtin users which are kind of special local users ,not users of the native realm. Our documentation covers both in detail, please read through [User authentication | Elastic Stack Overview [7.4] | Elastic](https://www.elastic.co/guide/en/elastic-stack-overview/current/setting-up-authentication.html)

You need to configure at least one so that kibana can communicate with elasticsearch, this user is the `kibana` user.

> If i want to use custom user accounts and we have those in AD then how do I give every individual access to kibana dashboards? Consider I have 50 users

You would need to give the users the necessary roles .read through [Granting access to Kibana | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/xpack-security-authorization.html). when you have the roles ready, you can assign the roles to users in your roles.yml file that you already have

> One more question clicked here, are all these account names mentioned in link that you posted are service accounts? and they should also be created in AD as is?

No, these are builtin users ,they exist in elasticsearch, you dont need to create them in AD.

> If I want to use keystore then how do I mention here?

> **[Secure settings | Kibana Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/kibana/current/secure-settings.html)**

> [@bharat1](#):
>
> When he refers 'native realm' does it mean service account name such as 'elastic' , 'kibana' , 'logstash\_user' etc...

I think he meant to say reserved realm == builtin users

> [@bharat1](#):
>
> I do have several other questions revolving around these should I ask?

You can ask here or your support engineer if you have a subscription. People im this forums will try to answer when we have time, but it's on a best effort basis !

---

<div class="post-metadata">

**Author:** ![bharat1](https://avatars.discourse-cdn.com/v4/letter/b/49beb7/32.png) [@bharat1](https://discuss.elastic.co/u/bharat1)\
**Post date:** [September 15, 2019, 4:48pm UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/11 "2019-09-15T16:48:29Z")

</div>

> [@ikakavas](#):
>
> \*\* doing so will also automatically create the .security index as we discussed in the other post

[root@eshost kibana]# /usr/share/kibana/bin/kibana-keystore --allow-root list  
kibana  
elasticsearch.username  
elasticsearch.password  
[root@eshost kibana]#

#elasticsearch.username: "kibana"  
#elasticsearch.password: ${elasticsearch.password}

It did not created .security index and below are the list of indices

```auto
[root@eshost kibana]# curl -u elkadmin2 "http://192.168.1.1:9200/_cat/indices?pretty"
Enter host password for user 'elkadmin2':
green open .kibana_task_manager 5Zp52pe2T1SYKuRDaOb1xA 1 1 2 0 59.2kb 29.6kb
green open .monitoring-es-7-2019.09.11 hf7UQg01QIOG6xjO8lWcTQ 1 1 11 0 122.8kb 61.4kb
green open .monitoring-es-7-2019.09.12 FWkWRE6PTg-3jeOIl-qJuA 1 1 1036 0 725.5kb 362.7kb
green open .monitoring-es-7-2019.09.13 HGGuzXqaTDy5IcPn8Klw9Q 1 1 1440 0 1017.7kb 508.8kb
green open .monitoring-es-7-2019.09.14 yE67sngGRwyyDGou9HZ4gw 1 1 1439 0 1mb 534.8kb
green open .monitoring-es-7-2019.09.15 4lmahB9aRm2GEf-oXE_LRw 1 1 1 0 254kb 126.9kb
green open .kibana_1 3LmFlua7SMmANjEBq94ndg 1 1 4 1 47.9kb 23.9kb
[root@eshost kibana]#

```

Next disabled security properties, changed from hostnames to IP address but still kibana does not comes up

```auto
{"type":"log","@timestamp":"2019-09-15T16:25:32Z","tags":["info","plugins","translations"],"pid":1855,"message":"Setting up plugin"}
{"type":"log","@timestamp":"2019-09-15T16:25:32Z","tags":["info","plugins-system"],"pid":1855,"message":"Starting [1] plugins: [translations]"}
{"type":"log","@timestamp":"2019-09-15T16:25:36Z","tags":["fatal","root"],"pid":1855,"message":"{ ValidationError: child \"kibana\" fails because [\"kibana\" must be an object]\n at Object.exports.process (/usr/share/kibana/node_modules/joi/lib/errors.js:196:19)\n at internals.Object._validateWithOptions (/usr/share/kibana/node_modules/joi/lib/types/any/index.js:675:31)\n at module.exports.internals.Any.root.validate (/usr/share/kibana/node_modules/joi/lib/index.js:146:23)\n at Config._commit (/usr/share/kibana/src/legacy/server/config/config.js:132:34)\n at Config.set (/usr/share/kibana/src/legacy/server/config/config.js:102:10)\n at Config.extendSchema (/usr/share/kibana/src/legacy/server/config/config.js:74:10)\n at extendConfigService (/usr/share/kibana/src/legacy/plugin_discovery/plugin_config/extend_config_service.js:45:10) name: 'ValidationError' }"}
{"type":"log","@timestamp":"2019-09-15T16:25:39Z","tags":["info","plugins-system"],"pid":1879,"message":"Setting up [1] plugins: [translations]"}
{"type":"log","@timestamp":"2019-09-15T16:25:39Z","tags":["info","plugins","translations"],"pid":1879,"message":"Setting up plugin"}
{"type":"log","@timestamp":"2019-09-15T16:25:39Z","tags":["info","plugins-system"],"pid":1879,"message":"Starting [1] plugins: [translations]"}
{"type":"log","@timestamp":"2019-09-15T16:25:43Z","tags":["fatal","root"],"pid":1879,"message":"{ ValidationError: child \"kibana\" fails because [\"kibana\" must be an object]\n at Object.exports.process (/usr/share/kibana/node_modules/joi/lib/errors.js:196:19)\n at internals.Object._validateWithOptions (/usr/share/kibana/node_modules/joi/lib/types/any/index.js:675:31)\n at module.exports.internals.Any.root.validate (/usr/share/kibana/node_modules/joi/lib/index.js:146:23)\n at Config._commit (/usr/share/kibana/src/legacy/server/config/config.js:132:34)\n at Config.set (/usr/share/kibana/src/legacy/server/config/config.js:102:10)\n at Config.extendSchema (/usr/share/kibana/src/legacy/server/config/config.js:74:10)\n at extendConfigService (/usr/share/kibana/src/legacy/plugin_discovery/plugin_config/extend_config_service.js:45:10) name: 'ValidationError' }"}
{"type":"log","@timestamp":"2019-09-15T16:25:46Z","tags":["info","plugins-system"],"pid":1902,"message":"Setting up [1] plugins: [translations]"}
{"type":"log","@timestamp":"2019-09-15T16:25:46Z","tags":["info","plugins","translations"],"pid":1902,"message":"Setting up plugin"}
{"type":"log","@timestamp":"2019-09-15T16:25:46Z","tags":["info","plugins-system"],"pid":1902,"message":"Starting [1] plugins: [translations]"}
{"type":"log","@timestamp":"2019-09-15T16:25:50Z","tags":["fatal","root"],"pid":1902,"message":"{ ValidationError: child \"kibana\" fails because [\"kibana\" must be an object]\n at Object.exports.process (/usr/share/kibana/node_modules/joi/lib/errors.js:196:19)\n at internals.Object._validateWithOptions (/usr/share/kibana/node_modules/joi/lib/types/any/index.js:675:31)\n at module.exports.internals.Any.root.validate (/usr/share/kibana/node_modules/joi/lib/index.js:146:23)\n at Config._commit (/usr/share/kibana/src/legacy/server/config/config.js:132:34)\n at Config.set (/usr/share/kibana/src/legacy/server/config/config.js:102:10)\n at Config.extendSchema (/usr/share/kibana/src/legacy/server/config/config.js:74:10)\n at extendConfigService (/usr/share/kibana/src/legacy/plugin_discovery/plugin_config/extend_config_service.js:45:10) name: 'ValidationError' }"}
{"type":"log","@timestamp":"2019-09-15T16:25:54Z","tags":["info","plugins-system"],"pid":1926,"message":"Setting up [1] plugins: [translations]"}
{"type":"log","@timestamp":"2019-09-15T16:25:54Z","tags":["info","plugins","translations"],"pid":1926,"message":"Setting up plugin"}
{"type":"log","@timestamp":"2019-09-15T16:25:54Z","tags":["info","plugins-system"],"pid":1926,"message":"Starting [1] plugins: [translations]"}

[root@eshost kibana]# {"type":"log","@timestamp":"2019-09-15T16:25:58Z","tags":["fatal","root"],"pid":1926,"message":"{ ValidationError: child \"kibana\" fails because [\"kibana\" must be an object]\n at Object.exports.process (/usr/share/kibana/node_modules/joi/lib/errors.js:196:19)\n at internals.Object._validateWithOptions (/usr/share/kibana/node_modules/joi/lib/types/any/index.js:675:31)\n at module.exports.internals.Any.root.validate (/usr/share/kibana/node_modules/joi/lib/index.js:146:23)\n at Config._commit (/usr/share/kibana/src/legacy/server/config/config.js:132:34)\n at Config.set (/usr/share/kibana/src/legacy/server/config/config.js:102:10)\n at Config.extendSchema (/usr/share/kibana/src/legacy/server/config/config.js:74:10)\n at extendConfigService (/usr/share/kibana/src/legacy/plugin_discovery/plugin_config/extend_config_service.js:45:10) name: 'ValidationError' }"}

current simple config without security:

```

```auto
server.host: "192.168.1.1"
server.name: "eshost"
elasticsearch.hosts: "http://192.168.1.1:9200"
kibana.index: ".kibana"
kibana.defaultAppId: "discover"
logging.dest: /var/log/kibana.log

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 15, 2019, 8:44pm UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/12 "2019-09-15T20:44:14Z")

</div>

> [@bharat1](#):
>
> It did not created .security index and below are the list of indices

I never said that setting a password in kibana keystore will create the security index. I said that setting the password for the built in users will.  
Please do not fixate on the security index, we have established this is unrelated. I only mentioned it as something worth knowing since you were worried about it in the other thread. Let's leave this aside for now.

Did you set the passwords for the built-in users as suggested in my previous post ?

> [@bharat1](#):
>
> changed from hostnames to IP address

This sounds unrelated. It would be great if you could refrain from unrelated changes , while we are trying to troubleshoot an existing issue, as it is making it really hard for the folks that try to assist.

> [@bharat1](#):
>
> Next disabled security properties

You can't have security if you disable security. We can't keep troubleshooting your security related issues if you disable security.

> [@bharat1](#):
>
> but still kibana does not comes up

It fails because you added a setting in your keystore named 'kibana' which is not allowed. The error you get describes that

---

<div class="post-metadata">

**Author:** ![bharat1](https://avatars.discourse-cdn.com/v4/letter/b/49beb7/32.png) [@bharat1](https://discuss.elastic.co/u/bharat1)\
**Post date:** [September 16, 2019, 7:56am UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/13 "2019-09-16T07:56:52Z")

</div>

> [@ikakavas](#):
>
> It fails because you added a setting in your keystore named 'kibana' which is not allowed

absolutely correct. I removed kibana from keystore and kibana started successfully. I noticed I was able to login via elastic user but not with kibana user (gave me error - "{"statusCode":403,"error":"Forbidden","message":"Forbidden"}" ) though the roles are not defined for both users. How come?

I used elasticsearch.username as kibana and in configuration I have used below, does this mean though kibana user is mentioned it will not be allowed to login in first instance rather to do some backend work and do more to give privileges to login as kibana user?

```auto
elasticsearch.username: kibana
elasticsearch.password: ${elasticsearch.password}
--------
[root@eshost kibana]# /usr/share/kibana/bin/kibana-keystore --allow-root list
elasticsearch.username
elasticsearch.password
[root@eshost kibana]#

```

> [@ikakavas](#):
>
> Did you set the passwords for the built-in users as suggested in my previous post ?

yes

A question, since we have this cluster integrated with AD, for all users in AD to give them access to various dashboards, do I need to create all those AD users here in Kibana? I assume not so because it may be tedious job to create huge number of users here in Kibana. Then what is the way out?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 16, 2019, 8:33am UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/14 "2019-09-16T08:33:43Z")

</div>

> [@bharat1](#):
>
> I noticed I was able to login via elastic user but not with kibana user (gave me error - "{"statusCode":403,"error":"Forbidden","message":"Forbidden"}" )

`kibana` user is meant to be used for kibana to communicate to elasticsearch and not to be used by end users. This is expected behavior and it works as it's designed to work, no need to worry.

> [@bharat1](#):
>
> I used elasticsearch.username as kibana and in configuration I have used below, does this mean though kibana user is mentioned it will not be allowed to login in first instance rather to do some backend work and do more to give privileges to login as kibana user?

No, it doesn't mean that. it will work fine, no need to worry.

> [@bharat1](#):
>
> A question, since we have this cluster integrated with AD, for all users in AD to give them access to various dashboards, do I need to create all those AD users here in Kibana? I assume not so because it may be tedious job to create huge number of users here in Kibana. Then what is the way out?

I replied to this in [Kibana not starting for enabling AD security - #10 by ikakavas](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/10)

> [@ikakavas](#):
>
> You would need to give the users the necessary roles .read through [Granting access to Kibana | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/xpack-security-authorization.html). when you have the roles ready, you can assign the roles to users in your roles.yml file that you already have

Please read through the docs.

---

<div class="post-metadata">

**Author:** ![bharat1](https://avatars.discourse-cdn.com/v4/letter/b/49beb7/32.png) [@bharat1](https://discuss.elastic.co/u/bharat1)\
**Post date:** [September 17, 2019, 1:51pm UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/15 "2019-09-17T13:51:03Z")

</div>

Finally all authentication issues are resolved. Many thanks to @ikakavas for guiding, assisting on the solutions. Your suggestions are helpful

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2019, 2:01pm UTC](https://discuss.elastic.co/t/kibana-not-starting-for-enabling-ad-security/199417/16 "2019-10-15T14:01:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
