# Local Setup Elasticsearch 7.2 and Kibana with Security

**URL:** <https://discuss.elastic.co/t/local-setup-elasticsearch-7-2-and-kibana-with-security/199526>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 15, 2019, 9:43am UTC](https://discuss.elastic.co/t/local-setup-elasticsearch-7-2-and-kibana-with-security/199526 "2019-09-15T09:43:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dinesh.gupta](https://avatars.discourse-cdn.com/v4/letter/d/e68b1a/32.png) [@dinesh.gupta](https://discuss.elastic.co/u/dinesh.gupta)\
**Post date:** [September 15, 2019, 9:43am UTC](https://discuss.elastic.co/t/local-setup-elasticsearch-7-2-and-kibana-with-security/199526/1 "2019-09-15T09:43:30Z")

</div>

I installed few days back Elastic & Kibana version 7.2 on my local laptop virtual machine( vmware with Centos 7.6).  
I want to enable the security for elastic & kibana but unable to do.

In Elasticsearch '/etc/elasticsearch/elasticsearch.yml' have below config

> discovery.type: single-node  
> xpack.security.enabled: true  
> #xpack.security.transport.ssl.enabled: false  
> #xpack.security.transport.ssl.verification\_mode: certificate  
> #xpack.security.transport.ssl.keystore.path: elastic-certificates.p12  
> #xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

I commented few last lines because I don't have SSL or cert.

Also I configured the user name & password for all(Elastic, Kibana, logsatch etc)  
(Run below command)

> /usr/share/elasticsearch/bin/elasticsearch-setup-passwords interactive  
> and choose same password for all  
> Password is 'elastic'

In Kabana '/etc/kibana/kibana.yml'

> elasticsearch.username: "kibana"  
> elasticsearch.password: "elastic"

When I run elastic curl got below error

> curl -u elastic '[http://localhost:9200/\_xpack/security/\_authenticate?pretty](http://localhost:9200/_xpack/security/_authenticate?pretty)'  
> {  
> "error" : {  
> "root\_cause" : [  
> {  
> "type" : "security\_exception",  
> "reason" : "failed to authenticate user [elastic]",  
> "header" : {  
> "WWW-Authenticate" : "Basic realm="security" charset="UTF-8""  
> }  
> }  
> ],  
> "type" : "security\_exception",  
> "reason" : "failed to authenticate user [elastic]",  
> "header" : {  
> "WWW-Authenticate" : "Basic realm="security" charset="UTF-8""  
> }  
> },  
> "status" : 401  
> }

and Kibana error log show as:

> Please check the Kibana Reporting settings. [security\_exception] failed to authenticate user [kibana], with { header={ WWW-Authenticate="Basic realm=\"security\" charset=\"UTF-8\"" } } :: {"path":"/\_cluster/settings","query":{"include\_defaults":true},"statusCode":401,"response":"{\"error\":{\"root\_cause\":[{\"type\":\"security\_exception\",\"reason\":\"failed to authenticate user [kibana]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}}],\"type\":\"security\_exception\",\"reason\":\"failed to authenticate user [kibana]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}},\"status\":401}","wwwAuthenticateDirective":"Basic realm=\"security\" charset=\"UTF-8\""}"}  
> {"type":"log","@timestamp":"2019-09-15T09:05:21Z","tags":["warning","task\_manager"],"pid":15330,"message":"PollError [security\_exception] failed to authenticate user [kibana], with { header={ WWW-Authenticate="Basic realm=\"security\" charset=\"UTF-8\"" } }"}  
> {"type":"log","@timestamp":"2019-09-15T09:05:21Z","tags":["warning","maps"],"pid":15330,"message":"Error scheduling telemetry task, received NotInitialized: Tasks cannot be scheduled until after task manager is initialized!"}  
> {"type":"log","@timestamp":"2019-09-15T09:05:21Z","tags":["warning","telemetry"],"pid":15330,"message":"Error scheduling task, received NotInitialized: Tasks cannot be scheduled until after task manager is initialized!"}

**Please help me.**

Thanks,  
Dinesh

---

<div class="post-metadata">

**Author:** ![aravindputrevu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aravindputrevu/32/24816_2.png) [@aravindputrevu](https://discuss.elastic.co/u/aravindputrevu)\
**Post date:** [September 15, 2019, 9:47am UTC](https://discuss.elastic.co/t/local-setup-elasticsearch-7-2-and-kibana-with-security/199526/2 "2019-09-15T09:47:51Z")

</div>

Welcome to Elastic forums!

Did you follow [this](https://www.elastic.co/blog/getting-started-with-elasticsearch-security) blog post?

We recommend enabling TLS for node to node encryption and for all communications btw Kibana and ES. It is clearly given step by step in the above blog post.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 16, 2019, 1:50am UTC](https://discuss.elastic.co/t/local-setup-elasticsearch-7-2-and-kibana-with-security/199526/3 "2019-09-16T01:50:47Z")

</div>

What does the elasticsearch log say?  
It is very hard to debug an authentication problem from outside the ES node - you need to read the logs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2019, 1:50am UTC](https://discuss.elastic.co/t/local-setup-elasticsearch-7-2-and-kibana-with-security/199526/4 "2019-10-14T01:50:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
