# Shield 2.3.3 & Kibana

**URL:** <https://discuss.elastic.co/t/shield-2-3-3-kibana/65038>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 4, 2016, 6:06pm UTC](https://discuss.elastic.co/t/shield-2-3-3-kibana/65038 "2016-11-04T18:06:31Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [November 15, 2016, 5:56pm UTC](https://discuss.elastic.co/t/shield-2-3-3-kibana/65038/2 "2016-11-15T17:56:01Z")

</div>

Hi Vivien,

--\> authenticate user without the use of SSL

you cannot use Shield in that version without SSL. Here's another post on it;

> [@Problem shield - kibana](https://discuss.elastic.co/t/problem-shield-kibana/40954/3):
>
> I've not configured to use ssl. If I insert shield.encryptionKey kibana ask me to insert info for ssl authentication, but I've not said kibana to use ssl and neither to elasticsearch. How can I check really that kibana doesn't use ssl? because seems that is use it...I'm just a bit confused

In the 5.0 stack SSL is not required.

--\> allow or not to use the discover part of kibana

There is not any supported way to disable Discover. I think some people have put a proxy in front of Kibana to block requests to /discover, but I don't know any details on that approach.

--\> allow or not to use the view of some visualization

I think you could use document level security to create a role which does not have access to some visualizations. I'll try to do this and update with the results.

--\> Use the plugin shield for kibana (actually i can't when i launch kibana an error occur on the existence of ssl option)

Yes, you must use SSL with the Kibana Shield plugin in Kibana 4.x.

Regards,  
Lee

---

_[View the full topic](https://discuss.elastic.co/t/shield-2-3-3-kibana/65038)._
