# Shield with no SSL - Unable to login to Kibana

**URL:** <https://discuss.elastic.co/t/shield-with-no-ssl-unable-to-login-to-kibana/53733>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 23, 2016, 5:38am UTC](https://discuss.elastic.co/t/shield-with-no-ssl-unable-to-login-to-kibana/53733 "2016-06-23T05:38:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![missourian](https://avatars.discourse-cdn.com/v4/letter/m/a5b964/32.png) [@missourian](https://discuss.elastic.co/u/missourian)\
**Post date:** [June 23, 2016, 5:38am UTC](https://discuss.elastic.co/t/shield-with-no-ssl-unable-to-login-to-kibana/53733/1 "2016-06-23T05:38:36Z")

</div>

I am unable to log into Kibana, I have added below role  
\*\*\*\* esuser utility\*\*

my\_kibana\_user:  
cluster:  
- monitor  
indices:  
- names: 'logstash-_'  
privileges:  
- view\_index\_metadata  
- read  
- names: '.kibana_'  
privileges:  
- manage  
- read  
- index

\*\*\ ***Users.roles**  
my\_kibana\_user:mis###

\*\*\ ***Kibana.yml**

elasticsearch.username: "kibana"  
elasticsearch.password: "kibana123"

shield.encryptionKey: "secret"  
shield.skipSslCheck: true  
elasticsearch.ssl.verify: false

I restarted kibana and logging into my localhost:5601, asking for username and password; If I enter a wrong username password, UI showing me wrong user name or password. However, after successful authentication it simply stays in login page and not taking to Kibana dashboard. What I am doing wrong, any help please.

**Simply Stays in this page after successful authentication**

 ![](https://us1.discourse-cdn.com/elastic/original/2X/6/695f23847146fcd430c004c7e84d04d87d99a2b0.gif)

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 23, 2016, 10:08pm UTC](https://discuss.elastic.co/t/shield-with-no-ssl-unable-to-login-to-kibana/53733/2 "2016-06-23T22:08:14Z")

</div>

The Kibana plugin for shield requires SSL as it uses a cookie with a secure flag. This is taken directly from the documentation for `shield.skipSslCheck` at [https://www.elastic.co/guide/en/shield/current/kibana.html:](https://www.elastic.co/guide/en/shield/current/kibana.html:)

> Advanced setting. Set to true to enable Kibana to start if server.ssl.cert and server.ssl.key are not specified in kibana.yml. This should only be used if SSL is configured outside of Kibana—for example, you are routing requests through a load balancer or proxy. You must still connect to the Kibana server via HTTPS when using the Shield UI plugin. If you attempt to access Kibana via HTTP, you’ll be stuck at the login screen indefinitely.

---

<div class="post-metadata">

**Author:** ![missourian](https://avatars.discourse-cdn.com/v4/letter/m/a5b964/32.png) [@missourian](https://discuss.elastic.co/u/missourian)\
**Post date:** [June 23, 2016, 10:33pm UTC](https://discuss.elastic.co/t/shield-with-no-ssl-unable-to-login-to-kibana/53733/3 "2016-06-23T22:33:36Z")

</div>

> [@jaymode](#):
>
> [Using Kibana with Shield | Shield [2.4] | Elastic](https://www.elastic.co/guide/en/shield/current/kibana.html)

Appreciate it @jaymode , it seems like there is no way to work around SSL with shield. I will go and create a self signed certificate.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/shield-with-no-ssl-unable-to-login-to-kibana/53733/4 "2017-07-06T13:43:37Z")

</div>


