# Kibana sessionTimeout doesn't take effect

**URL:** <https://discuss.elastic.co/t/kibana-sessiontimeout-doesnt-take-effect/168995>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [February 19, 2019, 10:29am UTC](https://discuss.elastic.co/t/kibana-sessiontimeout-doesnt-take-effect/168995 "2019-02-19T10:29:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tomeri](https://avatars.discourse-cdn.com/v4/letter/t/71c47a/32.png) [@tomeri](https://discuss.elastic.co/u/tomeri)\
**Post date:** [February 19, 2019, 10:29am UTC](https://discuss.elastic.co/t/kibana-sessiontimeout-doesnt-take-effect/168995/1 "2019-02-19T10:29:04Z")

</div>

Hi,

We are using Kibana 6.5.4 with X-Pack enabled (w/ trial license).  
I am trying to change the default session duration according to the [documentation](https://www.elastic.co/guide/en/kibana/current/security-settings-kb.html#security-ui-settings) but seems like the parameter doesn't get applied and the session still gets expired after the browser close.

This is the relevant configuration from kibana.yaml:

> elasticsearch.ssl.certificateAuthorities: /etc/kibana/certs/kibana.pem  
> elasticsearch.ssl.verificationMode: certificate  
> server.ssl.certificate: /etc/kibana/certs/kibana.crt  
> server.ssl.enabled: true  
> server.ssl.key: /etc/kibana/certs/kibana.key  
> xpack.security.authProviders: [basic]  
> xpack.security.public.hostname: [mydomain.net](http://mydomain.net)  
> xpack.security.public.port: 443  
> xpack.security.public.protocol: https  
> xpack.security.encryptionKey: "aaflkhsiodjhfh9ji3phnklsndlfknsg"  
> xpack.security.sessionTimeout: 600000  
> xpack.security.cookieName: "myCookieName" (i changed this just to check if the conf gets loaded)

Looking at the Chrome cookie:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/0/302c0144eea36ec01fcc2b2bf7c81087d9563c6c.png)  
As you can see, the Expires field indicates that the parameter didn't affect the cookies expiration time.

From the dev tools:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a6efd3f757e5174c22e209fe8c7cb1da5cff1a83.png)

Just to be clear, I tried many variations of the above configuration, after each changed I restarted the kibana of course.  
Also, I use nginx as a reversed proxy, for debugging purpose I worked only with one kibana though.

Thanks,

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 19, 2019, 2:51pm UTC](https://discuss.elastic.co/t/kibana-sessiontimeout-doesnt-take-effect/168995/2 "2019-02-19T14:51:50Z")

</div>

Hey @tomeri, this is the intended behavior. The wording for the docs is awkward, and Kibana sessions are always bound to the browser session, so closing the browser will always cause you to have log back in again.

---

<div class="post-metadata">

**Author:** ![tomeri](https://avatars.discourse-cdn.com/v4/letter/t/71c47a/32.png) [@tomeri](https://discuss.elastic.co/u/tomeri)\
**Post date:** [February 19, 2019, 7:50pm UTC](https://discuss.elastic.co/t/kibana-sessiontimeout-doesnt-take-effect/168995/3 "2019-02-19T19:50:12Z")

</div>

I wonder why this is the intended behavior, is it common with such applications?  
Isn't possible to configure it differently somehow?

Thanks,

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 19, 2019, 8:14pm UTC](https://discuss.elastic.co/t/kibana-sessiontimeout-doesnt-take-effect/168995/4 "2019-02-19T20:14:53Z")

</div>

Hey @tomeri, there's the potential for us to add an additional setting which creates persistent session cookies so that users don't have to log back in every time that they close and re-open the browser. Feel free to open up a feature request in our github repo here: [https://github.com/elastic/kibana/issues/new/choose](https://github.com/elastic/kibana/issues/new/choose)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2019, 8:15pm UTC](https://discuss.elastic.co/t/kibana-sessiontimeout-doesnt-take-effect/168995/5 "2019-03-19T20:15:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
