# Shield authentication issue

**URL:** <https://discuss.elastic.co/t/shield-authentication-issue/44806>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 18, 2016, 8:15am UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806 "2016-03-18T08:15:06Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hilal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilal/32/7684_2.png) [@Hilal](https://discuss.elastic.co/u/Hilal)\
**Post date:** [March 18, 2016, 8:15am UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/1 "2016-03-18T08:15:06Z")

</div>

Hi,  
I have Elasticsearch 2.2.0 and Kibana 4.4.2.(Marvel Plugin 2.2.0 and Sense 2.2.0 beta3) I installed Shield plugin 2.2.0 in elasticsearch and kibana When I start elasticsearch`(http://localhost:9200/)` and kibana `(http://0.0.0.0:5601/app)` Elasticsearch is working true but kibana isn't working true.  
error:  
`{"statusCode": ​404,"error": "Not Found"}`

It is authenticate problems. What can I do? I think I didn't configure shield with kibana.

---

<div class="post-metadata">

**Author:** ![krushnat\_khawale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krushnat_khawale/32/6652_2.png) [@krushnat\_khawale](https://discuss.elastic.co/u/krushnat_khawale)\
**Post date:** [March 18, 2016, 8:18am UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/2 "2016-03-18T08:18:31Z")

</div>

Use, **[http://localhost:5601](http://localhost:5601)**

---

<div class="post-metadata">

**Author:** ![Hilal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilal/32/7684_2.png) [@Hilal](https://discuss.elastic.co/u/Hilal)\
**Post date:** [March 18, 2016, 8:27am UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/3 "2016-03-18T08:27:12Z")

</div>

I did but status is red.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/3/35ae447ebc67ecf1bd1c3210debdac3f8f400694.png)

---

<div class="post-metadata">

**Author:** ![krushnat\_khawale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krushnat_khawale/32/6652_2.png) [@krushnat\_khawale](https://discuss.elastic.co/u/krushnat_khawale)\
**Post date:** [March 18, 2016, 8:33am UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/4 "2016-03-18T08:33:15Z")

</div>

Have you created kibana4-server user/role in roles.yml configuration file?

You need to create a role for kibana first for accessing elasticsearch and  
then you can let others access it.

See this, [https://www.elastic.co/guide/en/shield/current/kibana.html](https://www.elastic.co/guide/en/shield/current/kibana.html)

---

<div class="post-metadata">

**Author:** ![Hilal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilal/32/7684_2.png) [@Hilal](https://discuss.elastic.co/u/Hilal)\
**Post date:** [March 18, 2016, 8:44am UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/5 "2016-03-18T08:44:03Z")

</div>

I created a user called kibana4-server for kibana in elasticsearch on open terminal.

`bin/shield/esusers useradd kibana4-server -r kibana4_server`

and I enter password.

What can I write roles.yml in configuration file? I know this link([https://www.elastic.co/guide/en/shield/current/kibana.html](https://www.elastic.co/guide/en/shield/current/kibana.html)) but I understatd exactly

---

<div class="post-metadata">

**Author:** ![Hilal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilal/32/7684_2.png) [@Hilal](https://discuss.elastic.co/u/Hilal)\
**Post date:** [March 18, 2016, 8:55am UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/6 "2016-03-18T08:55:22Z")

</div>

I installed shield 2.2.0 in kibana . I restarted elasticsearch and kibana.  
My error :  
.....

```
     FATAL { [Error: shield.encryptionKey is required in kibana.yml.]
      cause: [Error: shield.encryptionKey is required in kibana.yml.],
```

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [March 18, 2016, 9:45am UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/7 "2016-03-18T09:45:34Z")

</div>

Did you do Step 6b on this page [https://www.elastic.co/guide/en/shield/current/kibana.html](https://www.elastic.co/guide/en/shield/current/kibana.html) ?

---

<div class="post-metadata">

**Author:** ![Hilal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilal/32/7684_2.png) [@Hilal](https://discuss.elastic.co/u/Hilal)\
**Post date:** [March 18, 2016, 9:59am UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/8 "2016-03-18T09:59:19Z")

</div>

I just did `bin/kibana plugin --install kibana/shield/latest` in step 6

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [March 18, 2016, 10:01am UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/9 "2016-03-18T10:01:44Z")

</div>

That is step 6a, you need to look at the next part on that page to solve the error you pasted

---

<div class="post-metadata">

**Author:** ![Hilal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilal/32/7684_2.png) [@Hilal](https://discuss.elastic.co/u/Hilal)\
**Post date:** [March 18, 2016, 12:57pm UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/10 "2016-03-18T12:57:16Z")

</div>

I did other step. my new error :  
`[Error: HTTPS is required. Please set server.ssl.key and server.ssl.cert in kibana.yml.],`

what can I write in kibana.yml path?

server.ssl.key: `/path/to/your/`server.key  
server.ssl.cert:`/path/to/your/`server.crt

---

<div class="post-metadata">

**Author:** ![dfaropennetwork](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@dfaropennetwork](https://discuss.elastic.co/u/dfaropennetwork)\
**Post date:** [March 19, 2016, 2:15am UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/11 "2016-03-19T02:15:23Z")

</div>

I think you need read the documentation from the begin, you need configure many things

The following options are for the auth from elasticsearch againts the kibana server, only for shield plugin, and it's only optional.

bin/shield/esusers useradd kibana4-server -r kibana4\_server

(apply on the kibana.yml)  
elasticsearch.username:  
elasticsearch.password:

this options are for the apache ssl certification or nginx (https)

server.ssl.key: /path/to/your/server.key  
server.ssl.cert:/path/to/your/server.crt

I in your place would configure basics options first, catch problems from the beginning, step by step and read the docs carefully

---

<div class="post-metadata">

**Author:** ![Hilal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilal/32/7684_2.png) [@Hilal](https://discuss.elastic.co/u/Hilal)\
**Post date:** [March 22, 2016, 8:48am UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/12 "2016-03-22T08:48:48Z")

</div>

I removed Shield plugin for elasticsearch and I started again.

4 and 5 steps do I have to do? ([https://www.elastic.co/guide/en/shield/current/kibana.html](https://www.elastic.co/guide/en/shield/current/kibana.html)) I don't understand ssl and CA ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:45pm UTC](https://discuss.elastic.co/t/shield-authentication-issue/44806/13 "2017-07-06T13:45:52Z")

</div>


