# Security

**URL:** <https://discuss.elastic.co/t/security/204731>\
**Category:** Kibana\
**Created:** [October 22, 2019, 9:12pm UTC](https://discuss.elastic.co/t/security/204731 "2019-10-22T21:12:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![gregorys](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregorys/32/67574_2.png) [@gregorys](https://discuss.elastic.co/u/gregorys)\
**Post date:** [October 22, 2019, 9:12pm UTC](https://discuss.elastic.co/t/security/204731/1 "2019-10-22T21:12:42Z")

</div>

Hi,

I have enabled security in elasticsearch and kibana.  
I have created a user with only the built-in kibana\_user role assigned to it.

It seems this user can create other users and assign whatever role he wants to them, also edit its own user roles like for example add the superuser role... this can't be normal?

Elasticsearch version 6.8.1  
Kibana runs on one of the master nodes

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [October 22, 2019, 9:28pm UTC](https://discuss.elastic.co/t/security/204731/2 "2019-10-22T21:28:50Z")

</div>

Hi @gregorys,

It is best if you create your own role with the privileges you want, check out the following, it will explain kibana\_user role access:  
[https://www.elastic.co/guide/en/elasticsearch/reference/6.8/built-in-roles.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/built-in-roles.html)

Thanks,  
Liza

---

<div class="post-metadata">

**Author:** ![gregorys](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregorys/32/67574_2.png) [@gregorys](https://discuss.elastic.co/u/gregorys)\
**Post date:** [October 22, 2019, 9:40pm UTC](https://discuss.elastic.co/t/security/204731/3 "2019-10-22T21:40:38Z")

</div>

Hey,

The problem remains.  
I have created a role with these privileges:

cluster: manage\_index\_templates, monitor  
index: dev-\*: all privileges  
kibana spaces: none

This user is able to logon and create users, assign any role (including superuser) to users,...

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [October 22, 2019, 9:46pm UTC](https://discuss.elastic.co/t/security/204731/4 "2019-10-22T21:46:05Z")

</div>

@Brandon_Kobel can you help give more details on how to setup a user role with more restricted access?

---

<div class="post-metadata">

**Author:** ![gregorys](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregorys/32/67574_2.png) [@gregorys](https://discuss.elastic.co/u/gregorys)\
**Post date:** [October 22, 2019, 9:46pm UTC](https://discuss.elastic.co/t/security/204731/5 "2019-10-22T21:46:18Z")

</div>

I was able to reproduce this on our staging environment, running 7.2.  
This occurs when anonymous access has been enabled in Elasticsearch.

xpack.security.authc:  
anonymous:  
roles: superuser  
authz\_exception: true

Apparently, when this is enabled, the user that is authenticating in Kibana also gets assigned the role that has been set for the anonymous user.  
Is this expected behaviour...?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [October 22, 2019, 10:28pm UTC](https://discuss.elastic.co/t/security/204731/6 "2019-10-22T22:28:05Z")

</div>

Hey @gregorys, it's "expected" in that it's a known bug we need to fix. [https://github.com/elastic/kibana/issues/35613](https://github.com/elastic/kibana/issues/35613) discusses some aspects of the current behavior, and why Kibana does what it does. Elasticsearch treats the anonymous user as the set of privileges that all users are granted. For example, if you enable the anonymous user in Elasticsearch and then you authenticate and provide the credentials for a user with no roles, they'll get the privileges of the anonymous user. The only way to overcome this behavior is to no longer use the anonymous user in Elasticsearch.

Ideally, would Kibana no longer require the end-user to login in your situation and automatically allow them to be authenticated as the anonymous user?

---

<div class="post-metadata">

**Author:** ![gregorys](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregorys/32/67574_2.png) [@gregorys](https://discuss.elastic.co/u/gregorys)\
**Post date:** [October 22, 2019, 10:42pm UTC](https://discuss.elastic.co/t/security/204731/7 "2019-10-22T22:42:49Z")

</div>

Thanks for the clarification.  
The anonymous access in our situation is just for a temporary period, to allow all integrations to add security to the elasticsearch output.

I'll create a new role with more strict permissions, and assign this role for anonymous access.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2019, 10:52pm UTC](https://discuss.elastic.co/t/security/204731/8 "2019-11-19T22:52:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
