# Native authentication showing up even if it is disabled

**URL:** <https://discuss.elastic.co/t/native-authentication-showing-up-even-if-it-is-disabled/91446>\
**Category:** Elasticsearch\
**Created:** [June 30, 2017, 2:16pm UTC](https://discuss.elastic.co/t/native-authentication-showing-up-even-if-it-is-disabled/91446 "2017-06-30T14:16:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![g-vamp](https://avatars.discourse-cdn.com/v4/letter/g/7993a0/32.png) [@g-vamp](https://discuss.elastic.co/u/g-vamp)\
**Post date:** [June 30, 2017, 2:16pm UTC](https://discuss.elastic.co/t/native-authentication-showing-up-even-if-it-is-disabled/91446/1 "2017-06-30T14:16:04Z")

</div>

Hi guys,

I currently have an ELK stack running with x-pack installed on both Elasticsearch and Kibana. My elasticsearch.yml config looks a bit like this:

```
xpack.graph.enabled: false
xpack.ml.enabled: false
xpack.monitoring.enabled: false
#xpack.reporting.enabled: false
xpack.watcher.enabled: false
xpack.security.enabled: true
xpack.security.audit.enabled: true
xpack.security.authc.accept_default_password: false
#defining realm chain
xpack.security.authc.realms:
 custom-realm:
  type: custom
  order: 0
  enabled: true
  config:
   superusers: blah@blah.com
   admin_roles: superuser
   default_roles: audit_read

```

Authentication of the custom realm seems to work nicely however, after authenticating my user via my custom x-pack plugin, Kibana will display the U/P basic form. What is the proper way to fully disable it? Or is it the way I do my custom authentication that makes it show up?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [July 4, 2017, 7:58am UTC](https://discuss.elastic.co/t/native-authentication-showing-up-even-if-it-is-disabled/91446/2 "2017-07-04T07:58:11Z")

</div>

Hi @g-vamp,

It sounds very similar to what had been discussed here: [Disable login in Kibana 5.3](https://discuss.elastic.co/t/disable-login-in-kibana-5-3/82998).

In short, there are only 2 main possibilities to bypass Kibana login screen at the moment:

- Disable security entirely, likely it's not an option for you;
- Attribute your every request with proper `Authorization: Basic ***` HTTP header (if your realm supports `Basic` authentication of course). See the post above that explains how to do that with the help of reverse proxy.

Let me know if you still have questions.

Thanks,  
Oleg

---

<div class="post-metadata">

**Author:** ![g-vamp](https://avatars.discourse-cdn.com/v4/letter/g/7993a0/32.png) [@g-vamp](https://discuss.elastic.co/u/g-vamp)\
**Post date:** [July 5, 2017, 2:05pm UTC](https://discuss.elastic.co/t/native-authentication-showing-up-even-if-it-is-disabled/91446/3 "2017-07-05T14:05:53Z")

</div>

Hi Oleg, thanks for your help, this does the trick!

I need both native and custom realm auth. But native auth is only needed as fall back when Kibana is not accessed via the proxy (i.e. via a vpn), in which case I want it enabled. With the proxy config trick it will just work nicely.

Thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2017, 2:06pm UTC](https://discuss.elastic.co/t/native-authentication-showing-up-even-if-it-is-disabled/91446/4 "2017-08-02T14:06:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
