# Security Section Not Listed

**URL:** <https://discuss.elastic.co/t/security-section-not-listed/185919>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [June 15, 2019, 1:10am UTC](https://discuss.elastic.co/t/security-section-not-listed/185919 "2019-06-15T01:10:54Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [June 15, 2019, 1:10am UTC](https://discuss.elastic.co/t/security-section-not-listed/185919/1 "2019-06-15T01:10:54Z")

</div>

I see that in version 7.1.0, the security module was made available to basic licenses but I am not seeing it in my 7.1.1 install. Do I have to setup transport and http security first for those features to expose themselves?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/b/eb0bad4740ac38ac92d49283ce7a31f19d3eb859.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 15, 2019, 1:32am UTC](https://discuss.elastic.co/t/security-section-not-listed/185919/2 "2019-06-15T01:32:19Z")

</div>

Did you download the default distribution or the `-oss` one?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [June 15, 2019, 1:43am UTC](https://discuss.elastic.co/t/security-section-not-listed/185919/3 "2019-06-15T01:43:51Z")

</div>

Default distribution from [elastic.co](http://elastic.co)

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [June 16, 2019, 2:29pm UTC](https://discuss.elastic.co/t/security-section-not-listed/185919/4 "2019-06-16T14:29:24Z")

</div>

Do I need to use the -oss one??

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 17, 2019, 4:57am UTC](https://discuss.elastic.co/t/security-section-not-listed/185919/5 "2019-06-17T04:57:37Z")

</div>

What does `GET _xpack?pretty` return?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [June 17, 2019, 2:23pm UTC](https://discuss.elastic.co/t/security-section-not-listed/185919/6 "2019-06-17T14:23:12Z")

</div>

Below is my output

```auto
{
  "build" : {
    "hash" : "7a013de",
    "date" : "2019-05-23T14:05:50.009976Z"
  },
  "license" : {
    "uid" : "381c5986-9fb8-4e14-a6bc-fc98f3a6f245",
    "type" : "basic",
    "mode" : "basic",
    "status" : "active"
  },
  "features" : {
    "ccr" : {
      "description" : "Cross Cluster Replication",
      "available" : false,
      "enabled" : true
    },
    "graph" : {
      "description" : "Graph Data Exploration for the Elastic Stack",
      "available" : false,
      "enabled" : true
    },
    "ilm" : {
      "description" : "Index lifecycle management for the Elastic Stack",
      "available" : true,
      "enabled" : true
    },
    "logstash" : {
      "description" : "Logstash management component for X-Pack",
      "available" : false,
      "enabled" : true
    },
    "ml" : {
      "description" : "Machine Learning for the Elastic Stack",
      "available" : false,
      "enabled" : true,
      "native_code_info" : {
        "version" : "7.1.1",
        "build_hash" : "fd619a36eb77df"
      }
    },
    "monitoring" : {
      "description" : "Monitoring for the Elastic Stack",
      "available" : true,
      "enabled" : true
    },
    "rollup" : {
      "description" : "Time series pre-aggregation and rollup",
      "available" : true,
      "enabled" : true
    },
    "security" : {
      "description" : "Security for the Elastic Stack",
      "available" : true,
      "enabled" : false
    },
    "sql" : {
      "description" : "SQL access to Elasticsearch",
      "available" : true,
      "enabled" : true
    },
    "watcher" : {
      "description" : "Alerting, Notification and Automation for the Elastic Stack",
      "available" : false,
      "enabled" : true
    }
  },
  "tagline" : "You know, for X"
}

```

So I looked at my elasticsearch.yml configuration and saw that I had `xpack.security.enabled: false`. Not sure when/why I did that, but I changed it to `true` and the following events were logged:

```auto
[2019-06-17T09:20:22,962][INFO][o.e.b.BootstrapChecks] [ESIPS1] bound or publishing to a non-loopback address, enforcing bootstrap checks
[2019-06-17T09:20:23,008][ERROR][o.e.b.Bootstrap] [ESIPS1] node validation exception
[1] bootstrap checks failed
[1]: Transport SSL must be enabled if security is enabled on a [basic] license. Please set [xpack.security.transport.ssl.enabled] to [true] or disable security by setting [xpack.security.enabled] to [false]

```

So I set ssl.enabled to true and xpack.security to true and restarted elasticsearch. It starts up, but I see a ton of closed connections and handshake failures, which leads me to believe it's because I haven't configured SSL on the transport.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [June 17, 2019, 11:58pm UTC](https://discuss.elastic.co/t/security-section-not-listed/185919/7 "2019-06-17T23:58:51Z")

</div>

@warkolm, does this mean transport security needs to be configured before I can enable Kibana user access, or do I need to configure both HTTPS and transport security? I realize the benefits of doing so, I just want to step into this as methodically as possible.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 17, 2019, 11:59pm UTC](https://discuss.elastic.co/t/security-section-not-listed/185919/8 "2019-06-17T23:59:40Z")

</div>

My understanding is that it all needs to be configured.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 15, 2019, 11:59pm UTC](https://discuss.elastic.co/t/security-section-not-listed/185919/9 "2019-07-15T23:59:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
