# Setting up User Authentication

**URL:** <https://discuss.elastic.co/t/setting-up-user-authentication/169902>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 25, 2019, 8:34pm UTC](https://discuss.elastic.co/t/setting-up-user-authentication/169902 "2019-02-25T20:34:13Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![manoj\_faria](https://avatars.discourse-cdn.com/v4/letter/m/278dde/32.png) [@manoj\_faria](https://discuss.elastic.co/u/manoj_faria)\
**Post date:** [February 25, 2019, 8:34pm UTC](https://discuss.elastic.co/t/setting-up-user-authentication/169902/1 "2019-02-25T20:34:13Z")

</div>

Hi -

I am setting up user authentication on a docker based cluster (single node elasticsearch and a single kibana container at the moment)....per the documentation listed here:  
[https://www.elastic.co/guide/en/x-pack/current/setting-up-authentication.html](https://www.elastic.co/guide/en/x-pack/current/setting-up-authentication.html)

xpack.security.enabled is set to true in elasticsearch.yml file.

On cluster startup:

1. I was expecting that I should be able to setup the password(s) for built-in users via Kibana. However, I do not see any options within Kibana-\> Management to set password(s) for built-in users.
2. I was expecting that, I should be able to set up users using the native realm (which I understood is the default). However, I do not see any options to setup users using the native realm.

I bet i am missing some security setup steps/config. I tried following elastic documentation ..but it ain't helping me much.

Any pointers/thoughts on what I may be missing?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [February 25, 2019, 8:54pm UTC](https://discuss.elastic.co/t/setting-up-user-authentication/169902/2 "2019-02-25T20:54:24Z")

</div>

Hi there

1. The document you shared above includes instructions on how to set the passwords of the built in users : [https://www.elastic.co/guide/en/x-pack/current/setting-up-authentication.html#set-built-in-user-passwords](https://www.elastic.co/guide/en/x-pack/current/setting-up-authentication.html#set-built-in-user-passwords)  
It's nowhere mentioned that this can be done within Kibana ,and this is true.

2. When you navigate to Management -\> Users in kibana as you mention in 1. , you can setup ( create / edit / delete ) users in the native realm .

Hope this helps !

Unless you are using version 6.2 specifically, ( and given this is a new cluster you should better use the latest version - 6.6 at this time and) use the latest version of the documentation: [https://www.elastic.co/guide/en/elastic-stack-overview/current/elasticsearch-security.html](https://www.elastic.co/guide/en/elastic-stack-overview/current/elasticsearch-security.html)

---

<div class="post-metadata">

**Author:** ![manoj\_faria](https://avatars.discourse-cdn.com/v4/letter/m/278dde/32.png) [@manoj\_faria](https://discuss.elastic.co/u/manoj_faria)\
**Post date:** [February 25, 2019, 9:16pm UTC](https://discuss.elastic.co/t/setting-up-user-authentication/169902/3 "2019-02-25T21:16:39Z")

</div>

Thanks Ioannis.

Here is what worked for me.

1. enabled xpack security within elasticsearch.yml file
2. enabled 30-day trial license
3. setup bootstrap password using - bin/elasticsearch-keystore add "bootstrap.password"
4. configure kibana.yml to connect to elastic using elastic as the user name and the password set using step #3 listed above

With the above stated steps, I can now see the "Users" and "Roles" option under Kibana -\> Management -\> "Security".

---

<div class="post-metadata">

**Author:** ![manoj\_faria](https://avatars.discourse-cdn.com/v4/letter/m/278dde/32.png) [@manoj\_faria](https://discuss.elastic.co/u/manoj_faria)\
**Post date:** [February 25, 2019, 9:20pm UTC](https://discuss.elastic.co/t/setting-up-user-authentication/169902/4 "2019-02-25T21:20:49Z")

</div>

Is there a way to refer to the keystore password key from kibana.yml (instead of specifying the elastic search password in plain text within kibana.yml file)?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [February 26, 2019, 7:00am UTC](https://discuss.elastic.co/t/setting-up-user-authentication/169902/5 "2019-02-26T07:00:08Z")

</div>

Yes, this is also [described in our documentation](https://www.elastic.co/guide/en/kibana/current/secure-settings.html)

In general, more often than not, starting from [https://www.elastic.co/search](https://www.elastic.co/search) will get you most of the information/feedback you need - in our documentation. For whatever is missing or unclear, we'll be happy to answer here too

---

<div class="post-metadata">

**Author:** ![manoj\_faria](https://avatars.discourse-cdn.com/v4/letter/m/278dde/32.png) [@manoj\_faria](https://discuss.elastic.co/u/manoj_faria)\
**Post date:** [February 27, 2019, 1:56am UTC](https://discuss.elastic.co/t/setting-up-user-authentication/169902/6 "2019-02-27T01:56:17Z")

</div>

Thanks, Ioannis.

I was able to obscure the password and pass it via ${elasticsearch.password} within kibana.yml as follows:

1. For elasticsearch, setup passwords for built-in users using:  
bin/elasticsearch-setup-passwords interactive

For Kibana  
2. Create the kibana keystore  
bin/kibana-keystore create

1. Add the key "elasticsearch.password" to kibana keystore  
bin/kibana-keystore add "elasticsearch.password"

2. bin/kibana-keystore list  
elasticsearch.password

3. config/kibana.yml  
elasticsearch.password: ${elasticsearch.password}

Thanks!  
-Manoj

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2019, 2:01am UTC](https://discuss.elastic.co/t/setting-up-user-authentication/169902/7 "2019-03-27T02:01:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
