# Mutual TLS authentication between Kibana and Elasticsearch keeping client\_authentication "required"

**URL:** <https://discuss.elastic.co/t/mutual-tls-authentication-between-kibana-and-elasticsearch-keeping-client-authentication-required/322529>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [January 5, 2023, 10:19am UTC](https://discuss.elastic.co/t/mutual-tls-authentication-between-kibana-and-elasticsearch-keeping-client-authentication-required/322529 "2023-01-05T10:19:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alex\_kuz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_kuz/32/115598_2.png) [@alex\_kuz](https://discuss.elastic.co/u/alex_kuz)\
**Post date:** [January 5, 2023, 10:19am UTC](https://discuss.elastic.co/t/mutual-tls-authentication-between-kibana-and-elasticsearch-keeping-client-authentication-required/322529/1 "2023-01-05T10:19:37Z")

</div>

I'm trying to enable mutual TLS between all the components. I managed to set up TLS between Kibana and Elasticsearch. But it doesn't work as I would expect.

I want to keep _"xpack.security.http.ssl.client\_authentication"_ setting _"required"_. However, in the [documentation](https://www.elastic.co/guide/en/kibana/current/elasticsearch-mutual-tls.html) in order to allow end users to authenticate using credentials, this setting has to be set to "optional".  
When I keep _"xpack.security.http.ssl.client\_authentication"_ setting _"required"_, I cannot log in to Kibana. When it's _"optional"_, I can access Elastic using only CA and credentials.

Is there any way to require all the ELK components to request a certificate from client connections but log in to Kibana using only credentials?

---

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [January 6, 2023, 7:57am UTC](https://discuss.elastic.co/t/mutual-tls-authentication-between-kibana-and-elasticsearch-keeping-client-authentication-required/322529/2 "2023-01-06T07:57:23Z")

</div>

Have you updated Kibana configmap to make sure it is using SSL, verifying certificates and presenting its own certificate for handshake?  
I have setup my cluster similar to yours and configured following in my kibana.yml:

```auto
elasticsearch.ssl.verificationMode: true
elasticsearch.ssl.alwaysPresentCertificate: true

```

---

<div class="post-metadata">

**Author:** ![alex\_kuz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_kuz/32/115598_2.png) [@alex\_kuz](https://discuss.elastic.co/u/alex_kuz)\
**Post date:** [January 6, 2023, 1:34pm UTC](https://discuss.elastic.co/t/mutual-tls-authentication-between-kibana-and-elasticsearch-keeping-client-authentication-required/322529/3 "2023-01-06T13:34:59Z")

</div>

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2023, 1:35pm UTC](https://discuss.elastic.co/t/mutual-tls-authentication-between-kibana-and-elasticsearch-keeping-client-authentication-required/322529/4 "2023-02-03T13:35:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
