# Not able enter into the kibana with correct credentials

**URL:** <https://discuss.elastic.co/t/not-able-enter-into-the-kibana-with-correct-credentials/56281>\
**Category:** Kibana\
**Created:** [July 25, 2016, 10:03am UTC](https://discuss.elastic.co/t/not-able-enter-into-the-kibana-with-correct-credentials/56281 "2016-07-25T10:03:47Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![sukesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukesh/32/10890_2.png) [@sukesh](https://discuss.elastic.co/u/sukesh)\
**Post date:** [July 25, 2016, 10:03am UTC](https://discuss.elastic.co/t/not-able-enter-into-the-kibana-with-correct-credentials/56281/1 "2016-07-25T10:03:47Z")

</div>

Hi , i activated the kibana , asking username and password , if i enter wrong credentials it is throwing invalid username password please give me the solution for this! but if it is correct not able enter into the kibana

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [July 25, 2016, 6:11pm UTC](https://discuss.elastic.co/t/not-able-enter-into-the-kibana-with-correct-credentials/56281/2 "2016-07-25T18:11:14Z")

</div>

Sounds like you have the Shield plugin for Kibana installed. Do you also have the Shield plugin for Elasticsearch installed?

If so, let us know the steps you did to install the plugins for Elasticsearch and Kibana, and how you added the user accounts.

The versions for the software you are using could help too.

---

<div class="post-metadata">

**Author:** ![sukesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukesh/32/10890_2.png) [@sukesh](https://discuss.elastic.co/u/sukesh)\
**Post date:** [July 27, 2016, 4:16am UTC](https://discuss.elastic.co/t/not-able-enter-into-the-kibana-with-correct-credentials/56281/3 "2016-07-27T04:16:18Z")

</div>

Yes @tsullivan ullivan , i was installed shield for kibana and elasticsearch , the version of ES is 2.3.1 and kibana 4.5.0 window ,shield 2.3.1 .

steps : first i was installed the shiled for elasticsearch  
as per this link [https://www.elastic.co/guide/en/shield/current/installing-shield.html](https://www.elastic.co/guide/en/shield/current/installing-shield.html)

after that i installed shield for kibana but while kibana installation i did not set the ssl certicate path because that is sounds me bit confused so i used  
shield.skipSslCheck: true  
this command to skip the ssl check

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [July 27, 2016, 7:45pm UTC](https://discuss.elastic.co/t/not-able-enter-into-the-kibana-with-correct-credentials/56281/4 "2016-07-27T19:45:52Z")

</div>

Try adding `shield.useUnsafeSessions: true` in your Kibana.yml.

Shield plugin with 2.3 is only supported with SSL, and the skip SSL option is just to terminate SSL outside the kibana server, not bypass SSL altogether.

---

<div class="post-metadata">

**Author:** ![sukesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukesh/32/10890_2.png) [@sukesh](https://discuss.elastic.co/u/sukesh)\
**Post date:** [July 28, 2016, 5:38am UTC](https://discuss.elastic.co/t/not-able-enter-into-the-kibana-with-correct-credentials/56281/5 "2016-07-28T05:38:47Z")

</div>

Hi @tsullivan ,

i tried shield.useUnsafeSessions: true but it is throwing the fatal error  
like  
FATAL { [ValidationError: child "shield" fails because ["useUnsafeSessions" is n  
ot allowed]]  
name: 'ValidationError',  
details:  
[ { message: '"useUnsafeSessions" is not allowed',  
path: 'shield.useUnsafeSessions',  
type: 'object.allowUnknown',  
context: [Object] } ],  
\_object:  
{ pkg:  
{ version: '4.5.0',  
buildNum: 9889,  
buildSha: 'ff5cfc5d05a58e53f7acaa762428fa803318d31e' },  
pid: { exclusive: false },  
server:  
{ host: '0.0.0.0',  
port: 5601,  
maxPayloadBytes: 1048576,  
autoListen: true,  
basePath: '',  
ssl: {},  
cors: false,  
xsrf: [Object] },  
logging:  
{ silent: false,  
quiet: false,  
verbose: false,  
events: {},  
dest: 'stdout',  
filter: {},  
json: false },  
plugins: { scanDirs: [Object], paths: [], initialize: true },  
optimize:  
{ enabled: true,  
bundleFilter: '!tests',  
bundleDir: 'C:\Users\**_\Downloads\kibana-4.5.0-windows\kibana-4  
.5.0-windows\optimize\bundles',  
viewCaching: true,  
lazy: false,  
lazyPort: 5602,  
lazyHost: 'localhost',  
lazyPrebuild: false,  
lazyProxyTimeout: 300000,  
useBundleCache: true,  
unsafeCache: '/\/\\[\/\\]/',  
sourceMaps: false,  
profile: false },  
sense:  
{ enabled: true,  
defaultServerUrl: 'http://_**_:9200',  
proxyFilter: [Object],  
ssl: {},  
proxyConfig: [Object] },  
shield:  
{ useUnsafeSessions: true,  
skipSslCheck: true,  
encryptionKey: '_\*\*\*\*\*\*',  
sessionTimeout: 600000 } },  
annotate: [Function] }

so i removed it ,and run the kibana it is showing exception like

FATAL { [Error: HTTPS is required. Please set server.ssl.key and server.ssl.cert  
in kibana.yml.]  
cause: [Error: HTTPS is required. Please set server.ssl.key and server.ssl.cer  
t in kibana.yml.],  
isOperational: true }

now i got the "openssl-1.0.2.tar " but dont know how to set and where i can get the path to server.key ,server.crt please help in this .

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [July 28, 2016, 8:05pm UTC](https://discuss.elastic.co/t/not-able-enter-into-the-kibana-with-correct-credentials/56281/6 "2016-07-28T20:05:09Z")

</div>

I apologize. the `useUnsafeSessions` will be available in version 2.4

Have you seen these documentation pages about setting up encryption with Shield? You have an option to use self-signed certificates if you do not need to have your certificate signed by a trusted CA.

- [https://www.elastic.co/guide/en/shield/2.3/ssl-tls.html](https://www.elastic.co/guide/en/shield/2.3/ssl-tls.html)
- [https://www.elastic.co/guide/en/shield/2.3/kibana.html](https://www.elastic.co/guide/en/shield/2.3/kibana.html)

---

<div class="post-metadata">

**Author:** ![sukesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sukesh/32/10890_2.png) [@sukesh](https://discuss.elastic.co/u/sukesh)\
**Post date:** [July 29, 2016, 5:11am UTC](https://discuss.elastic.co/t/not-able-enter-into-the-kibana-with-correct-credentials/56281/7 "2016-07-29T05:11:52Z")

</div>

Yes @tsullivan , i gone through that ,but i did not understand anything , i can do up to user creation but SSL certification thing is bit confusing .i have openssl 1.0.2 in that where i can get the server.key,server.crt file paths ?

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [August 1, 2016, 5:06pm UTC](https://discuss.elastic.co/t/not-able-enter-into-the-kibana-with-correct-credentials/56281/8 "2016-08-01T17:06:09Z")

</div>

> i have openssl 1.0.2 in that where i can get the server.key,server.crt file paths ?

The `openssl` command generates those files. There are a lot of ways to generate the private key and certificate, and we don't cover how to do it in our documentation. But this site gives the openssl commands you can run to generate those files: [Creating a Self-Signed SSL Certificate | Heroku Dev Center](https://devcenter.heroku.com/articles/ssl-certificate-self)

To summarize it:

1. Generate a private key:

```auto
openssl genrsa -des3 -passout pass:x -out server.pass.key 2048
openssl rsa -passin pass:x -in server.pass.key -out server.key

```

1. Generate a certificate signing request:

```auto
openssl req -new -key server.key -out server.csr

```

1. Generate an SSL certificate:

```auto
openssl x509 -req -sha256 -days 365 -in server.csr -signkey server.key -out server.crt

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/not-able-enter-into-the-kibana-with-correct-credentials/56281/9 "2017-07-06T13:42:49Z")

</div>


