# Kibana unable to authenticate

**URL:** <https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 12, 2021, 1:18pm UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830 "2021-01-12T13:18:38Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daniel\_J1996](https://avatars.discourse-cdn.com/v4/letter/d/77aa72/32.png) [@Daniel\_J1996](https://discuss.elastic.co/u/Daniel_J1996)\
**Post date:** [January 12, 2021, 1:18pm UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830/1 "2021-01-12T13:18:39Z")

</div>

Hello,

I have been running into an issue with my Kibana dashboard. Currently, it shows "Kibana server is not ready yet". When I use the journalctl -xe command, I see the following error for Kibana:

```auto
["warning","plugins","licensing"],"pid":6937,"message":"License information could not be obtained from Elasticsearch due to [security_exception] unable to authenticate user [kibana] for REST request [/_xpack], with { header={ WWW-Authenticate=\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\" } }

```

It sounds like there is some sort of authentication error. I had setup the elasticsearch-setup-passwords tool before and everything had been working correctly before. But since I had setup the passwords for the elastic users prior to this issue, I am unable to reset those passwords. I tried using the elasticsearch-users passwd function and get the following error:

```auto
ERROR: Invalid username [elastic]... Username [elastic] is reserved and may not be used.

```

I get this error regardless of user (elastic, kibana, etc). I should note that this issue started occuring when I removed all prior indices to free space. The partition I had for the indices filled up very quickly and caused Elasticsearch and Kibana to crash. I should also note that I am unable to authenticate using cURL

```auto
curl -u elastic'http://localhost:9200/_xpack/security/_authenticate?pretty'

```

Result:  
{  
"error" : {  
"root\_cause" : [  
{  
"type" : "security\_exception",  
"reason" : "unable to authenticate user [elastic] for REST request [/\_xpack/security/\_authenticate?pretty]",  
"header" : {  
"WWW-Authenticate" : "Basic realm="security" charset="UTF-8""  
}  
}  
],  
"type" : "security\_exception",  
"reason" : "unable to authenticate user [elastic] for REST request [/\_xpack/security/\_authenticate?pretty]",  
"header" : {  
"WWW-Authenticate" : "Basic realm="security" charset="UTF-8""  
}  
},  
"status" : 401  
}

Is there anyway I can fix this error? Would I have to re-setup the passwords for the elastic users? I am running Elasticsearch Version 7.9.2

Thank you for any and all help

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [January 12, 2021, 8:53pm UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830/2 "2021-01-12T20:53:21Z")

</div>

Have you tried logging into Elasticsearch directly, with curl?  
Have you checked for more information in the Elasticsearch logs?

When you removed indices to clear space, were any system indices removed? I just want to rule out a possible accidental removal of the security index: you should have an index called `.security-7`

---

<div class="post-metadata">

**Author:** ![namballag2021](https://avatars.discourse-cdn.com/v4/letter/n/dc4da7/32.png) [@namballag2021](https://discuss.elastic.co/u/namballag2021)\
**Post date:** [January 12, 2021, 9:15pm UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830/3 "2021-01-12T21:15:30Z")

</div>

I am also having similar issue. not able to authenticate Kibana after installing kibana with searchguard. using basicauth and logging in with default user& pw as "kibanaserver". Any suggestions please.

"name":"Error","stack":"Error: 140254743959424:error:14094416:SSL routines:ssl3\_read\_bytes:sslv3 alert certificate unknown:../deps/openssl/openssl/ssl/record/rec\_layer\_s3.c:1407:SSL alert number 46\

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 12, 2021, 9:29pm UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830/4 "2021-01-12T21:29:07Z")

</div>

Please create your own topic for your question 🙂

---

<div class="post-metadata">

**Author:** ![Daniel\_J1996](https://avatars.discourse-cdn.com/v4/letter/d/77aa72/32.png) [@Daniel\_J1996](https://discuss.elastic.co/u/Daniel_J1996)\
**Post date:** [January 13, 2021, 7:17am UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830/5 "2021-01-13T07:17:34Z")

</div>

Hey Tim,

Here is the error within the elasticsearch.log:

org.elasticsearch.action.UnavailableShardsException: at least one primary shard for the index [.security-7] is unavailable  
at org.elasticsearch.xpack.security.support.SecurityIndexManager.getUnavailableReason(SecurityIndexManager.java:181) ~[x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.esnative.NativeUsersStore.getReservedUserInfo(NativeUsersStore.java:525) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.esnative.ReservedRealm.getUserInfo(ReservedRealm.java:225) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.esnative.ReservedRealm.doAuthenticate(ReservedRealm.java:99) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.support.CachingUsernamePasswordRealm.authenticateWithCache(CachingUsernamePasswordRealm.java:167) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.support.CachingUsernamePasswordRealm.authenticate(CachingUsernamePasswordRealm.java:104) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lambda$consumeToken$15(AuthenticationService.java:448) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.core.common.IteratingActionListener.run(IteratingActionListener.java:102) [x-pack-core-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.consumeToken(AuthenticationService.java:503) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lambda$extractToken$11(AuthenticationService.java:415) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.extractToken(AuthenticationService.java:425) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lambda$checkForApiKey$3(AuthenticationService.java:366) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:63) [elasticsearch-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.ApiKeyService.authenticateWithApiKeyIfPresent(ApiKeyService.java:345) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.checkForApiKey(AuthenticationService.java:347) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lambda$authenticateAsync$0(AuthenticationService.java:329) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:63) [elasticsearch-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.TokenService.getAndValidateToken(TokenService.java:405) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lambda$authenticateAsync$2(AuthenticationService.java:325) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lambda$lookForExistingAuthentication$6(AuthenticationService.java:384) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lookForExistingAuthentication(AuthenticationService.java:395) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.authenticateAsync(AuthenticationService.java:320) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.access$000(AuthenticationService.java:261) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService.authenticate(AuthenticationService.java:141) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.authc.AuthenticationService.authenticate(AuthenticationService.java:126) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.xpack.security.rest.SecurityRestFilter.handleRequest(SecurityRestFilter.java:63) [x-pack-security-7.9.2.jar:7.9.2]  
at org.elasticsearch.rest.RestController.dispatchRequest(RestController.java:236) [elasticsearch-7.9.2.jar:7.9.2]  
at org.elasticsearch.rest.RestController.tryAllHandlers(RestController.java:318) [elasticsearch-7.9.2.jar:7.9.2]  
at org.elasticsearch.rest.RestController.dispatchRequest(RestController.java:176) [elasticsearch-7.9.2.jar:7.9.2]  
at org.elasticsearch.http.AbstractHttpServerTransport.dispatchRequest(AbstractHttpServerTransport.java:318) [elasticsearch-7.9.2.jar:7.9.2]  
at org.elasticsearch.http.AbstractHttpServerTransport.handleIncomingRequest(AbstractHttpServerTransport.java:372) [elasticsearch-7.9.2.jar:7.9.2]  
at org.elasticsearch.http.AbstractHttpServerTransport.incomingRequest(AbstractHttpServerTransport.java:308) [elasticsearch-7.9.2.jar:7.9.2]  
at org.elasticsearch.http.netty4.Netty4HttpRequestHandler.channelRead0(Netty4HttpRequestHandler.java:42) [transport-netty4-client-7.9.2.jar:7.9.2]  
at org.elasticsearch.http.netty4.Netty4HttpRequestHandler.channelRead0(Netty4HttpRequestHandler.java:28) [transport-netty4-client-7.9.2.jar:7.9.2]  
at io.netty.channel.SimpleChannelInboundHandler.channelRead(SimpleChannelInboundHandler.java:99) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:379) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:365) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:357) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at org.elasticsearch.http.netty4.Netty4HttpPipeliningHandler.channelRead(Netty4HttpPipeliningHandler.java:58) [transport-netty4-client-7.9.2.jar:7.9.2]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:379) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:365) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:357) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.handler.codec.MessageToMessageDecoder.channelRead(MessageToMessageDecoder.java:103) [netty-codec-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:379) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:365) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:357) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.handler.codec.MessageToMessageDecoder.channelRead(MessageToMessageDecoder.java:103) [netty-codec-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.handler.codec.MessageToMessageCodec.channelRead(MessageToMessageCodec.java:111) [netty-codec-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:379) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:365) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:357) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.handler.codec.MessageToMessageDecoder.channelRead(MessageToMessageDecoder.java:103) [netty-codec-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:379) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:365) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:357) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.handler.codec.MessageToMessageDecoder.channelRead(MessageToMessageDecoder.java:103) [netty-codec-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:379) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:365) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:357) [netty-transport-4.1.49.Final.jar:4.1.49.Final]  
at io.netty.handler.codec.ByteToMessageDecoder.fireChannelRead(ByteToMessageDecoder.java:324) [netty-codec-4.1.49.Final.jar:4.1.49.Final]

It is my understanding that we removed all indices, including the security index.

Thanks,

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [January 13, 2021, 5:13pm UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830/6 "2021-01-13T17:13:30Z")

</div>

Hi Daniel, unfortunately, it looks like Elastic Security is not going to work until you restore the .security-7 index. Did you create backups of the data before removing indices?

Since this is more of an Elasticsearch operations issue, you may have better luck talking to the experts in the Elasticsearch category: [https://discuss.elastic.co/c/elastic-stack/elasticsearch/6](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6)

The `_cat/allocation` and `_cat/shards` APIs are going to be your friend:

- `https://www.elastic.co/guide/en/elasticsearch/reference/current/cat-shards.html`
- `https://www.elastic.co/guide/en/elasticsearch/reference/current/cat-allocation.html`

---

<div class="post-metadata">

**Author:** ![Daniel\_J1996](https://avatars.discourse-cdn.com/v4/letter/d/77aa72/32.png) [@Daniel\_J1996](https://discuss.elastic.co/u/Daniel_J1996)\
**Post date:** [January 16, 2021, 6:26am UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830/7 "2021-01-16T06:26:40Z")

</div>

Hey Tim,

Thank you so much for helping me understand this issue. It looks like we did not take back ups of those indices. Foolish, I know. Is there any way I can recreate a new .security-7 index? If I can, I would like to try to avoid re-installing ElasticSearch, but if I have to then so be it.

Again, thank you so much for the assistance.

Best,

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [January 21, 2021, 5:34am UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830/8 "2021-01-21T05:34:14Z")

</div>

Based on a thread I found in the Elasticsearch category, you can restart the cluster set the user passwords for built-in users. See [Accidentally deleted .security index for x-pack](https://discuss.elastic.co/t/accidentally-deleted-security-index-for-x-pack/69844/3)

---

<div class="post-metadata">

**Author:** ![Daniel\_J1996](https://avatars.discourse-cdn.com/v4/letter/d/77aa72/32.png) [@Daniel\_J1996](https://discuss.elastic.co/u/Daniel_J1996)\
**Post date:** [January 23, 2021, 7:56am UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830/9 "2021-01-23T07:56:37Z")

</div>

Hey Tim,

Thanks for showing me that thread. I am still have issues trying to reset the kibana password however. I tried to restart my cluster based on this doc I found:

> **[Full-cluster restart and rolling restart | Elasticsearch Reference \[7.10\] |...](https://www.elastic.co/guide/en/elasticsearch/reference/current/restart-cluster.html)**

I'm not sure if I did something wrong here, when I try to do a synced-flush, I get these results:

".kibana-event-log-7.9.2-000001" : {  
"total" : 1,  
"successful" : 0,  
"failed" : 1,  
"failures" : [  
{  
"shard" : 0,  
"reason" : "no active shards"  
}  
]  
},  
"wazuh-monitoring-3.x-2020.10.10" : {  
"total" : 2,  
"successful" : 0,  
"failed" : 2,  
"failures" : [  
{  
"shard" : 0,  
"reason" : "no active shards"  
},  
{  
"shard" : 1,  
"reason" : "no active shards"  
}  
]  
},  
".kibana-event-log-7.9.2-000004" : {  
"total" : 1,  
"successful" : 1,  
"failed" : 0  
},  
".kibana-event-log-7.9.2-000002" : {  
"total" : 1,  
"successful" : 0,  
"failed" : 1,  
"failures" : [  
{  
"shard" : 0,  
"reason" : "no active shards"  
}  
]  
},  
".kibana-event-log-7.9.2-000003" : {  
"total" : 1,  
"successful" : 0,  
"failed" : 1,  
"failures" : [  
{  
"shard" : 0,  
"reason" : "no active shards"  
}  
]  
},

I follow the instructions from there and I am unable to reset the passwords per the instructions:

> **[Setting Up User Authentication | X-Pack for the Elastic Stack \[6.2\] | Elastic](https://www.elastic.co/guide/en/x-pack/current/setting-up-authentication.html#built-in-users)**

I created my own super user and tried to rest the elastic and kibana passwords via this curl command:

```auto
curl -u my_admin -XPUT 'http://localhost:9200/_xpack/security/user/elastic/_password?pretty' -H 'Content-Type: application/json' -d'
{
  "password" : "new_password"
}
' 

```

This returns the following results:

{  
"error" : {  
"root\_cause" : [  
{  
"type" : "unavailable\_shards\_exception",  
"reason" : "[.security-7][0] [1] shardIt, [0] active : Timeout waiting for [1m], request: indices:data/write/update"  
}  
],  
"type" : "unavailable\_shards\_exception",  
"reason" : "[.security-7][0] [1] shardIt, [0] active : Timeout waiting for [1m], request: indices:data/write/update"  
},  
"status" : 503  
}

I even attempted to try to set a bootstrap password for elasticsearch and no luck there being able to authenticate:

```auto
bin/elasticsearch-keystore add "bootstrap.password"

```

{  
"error" : {  
"root\_cause" : [  
{  
"type" : "security\_exception",  
"reason" : "unable to authenticate user [elastic] for REST request [/\_xpack/security/\_authenticate?pretty]",  
"header" : {  
"WWW-Authenticate" : "Basic realm="security" charset="UTF-8""  
}  
}  
],  
"type" : "security\_exception",  
"reason" : "unable to authenticate user [elastic] for REST request [/\_xpack/security/\_authenticate?pretty]",  
"header" : {  
"WWW-Authenticate" : "Basic realm="security" charset="UTF-8""  
}  
},  
"status" : 401  
}

Any guidance here?

Thanks

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [January 29, 2021, 8:08pm UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830/10 "2021-01-29T20:08:29Z")

</div>

Hi, I think your cluster is in an unhealthy state because the the cluster state thinks that indices still exist, for which there are no shards. You'll need to get the cluster into `green` state again before doing the full cluster restart.

I suggest starting a new topic and share the output of

- `/_cat/health?v`
- `/_cat/allocation?v`
- `/_cat/shards?v`.

If this was a Kibana question I might be able to help more, but we know the reason why Kibana can't authenticate and it seems to be because of Elasticsearch cluster health.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2021, 8:09pm UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate/260830/11 "2021-02-26T20:09:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
