# "This Elastic installation has strict security requirements enabled that your current browser does not meet

**URL:** <https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/259006>\
**Category:** Kibana\
**Created:** [December 17, 2020, 3:08pm UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/259006 "2020-12-17T15:08:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![J\_Stan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/j_stan/32/78332_2.png) [@J\_Stan](https://discuss.elastic.co/u/J_Stan)\
**Post date:** [December 17, 2020, 3:08pm UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/259006/1 "2020-12-17T15:08:16Z")

</div>

Hi All

I am not able to access the Kibana UI .

I am using Google Chrome (ver 87). The error I am getting is

"This Elastic installation has strict security requirements enabled that your current browser does not meet."  
I have tried other browsers (Edge, firefox etc) without any success.

This is a new installation 0f version 7.10

```auto
# rpm -qa|grep -i -E "elastic|kibana|logstash|fileb"
elasticsearch-7.10.0-1.x86_64
kibana-7.10.0-1.x86_64
filebeat-7.10.0-1.x86_64
logstash-7.10.0-1.x86_64

```

I have confirmed Elasticsearch is running

```auto
# netstat -tulpn|grep -e java -e node
tcp 0 0 127.0.0.1:9600 0.0.0.0:* LISTEN 1327/java
tcp 0 0 111.111.111.111:5601 0.0.0.0:* LISTEN 5866/node
tcp 0 0 111.111.111.111:9200 0.0.0.0:* LISTEN 1696/java
tcp 0 0 0.0.0.0:5044 0.0.0.0:* LISTEN 1327/java
tcp 0 0 111.111.111.111:9300 0.0.0.0:* LISTEN 1696/java

# curl -k -XGET https://FQDN:9200/_cluster/health?pretty -u elastic:password
{
  "cluster_name" : "cluster",
  "status" : "yellow",
  "timed_out" : false,
  "number_of_nodes" : 1,
  "number_of_data_nodes" : 1,
  "active_primary_shards" : 14,
  "active_shards" : 14,
  "relocating_shards" : 0,
  "initializing_shards" : 0,
  "unassigned_shards" : 2,
  "delayed_unassigned_shards" : 0,
  "number_of_pending_tasks" : 0,
  "number_of_in_flight_fetch" : 0,
  "task_max_waiting_in_queue_millis" : 0,
  "active_shards_percent_as_number" : 87.5
}

```

kibana.yml looks like the following

```auto
# grep -v -e ^$ -e ^# kibana.yml
logging.dest: /var/log/kibana/kibana.log
logging.silent: false
logging.quiet: false
logging.verbose: false
telemetry.optIn: false
telemetry.enabled: false
xpack.reporting.capture.browser.chromium.disableSandbox: false
xpack.security.enabled: true
server.name: kibana
server.host: MYSERVER.example.com
server.ssl.enabled: true
server.ssl.certificate: /etc/kibana/config/certs/MYSERVER.crt
server.ssl.key: /etc/kibana/config/certs/MYSERVER.key
server.ssl.certificateAuthorities: ["/etc/kibana/config/certs/ca.pem"]
elasticsearch.hosts: ["https://MYSERVER.example.com:9200"]
elasticsearch.username: kibana_system
elasticsearch.password: password
elasticsearch.ssl.certificateAuthorities: ["/etc/kibana/config/certs/ca.pem"]
elasticsearch.ssl.verificationMode: none
csp.strict: true
csp.rules:
 - "script-src https://MYSERVER.example.com 'self' 'unsafe-inline' 'unsafe-eval' https://*"
 - "child-src 'MYSERVER'"

```

Can any one help ?

---

<div class="post-metadata">

**Author:** ![Mikhail\_Shustov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mikhail_shustov/32/49186_2.png) [@Mikhail\_Shustov](https://discuss.elastic.co/u/Mikhail_Shustov)\
**Post date:** [December 17, 2020, 4:40pm UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/259006/2 "2020-12-17T16:40:02Z")

</div>

> [@J\_Stan](#):
>
> "This Elastic installation has strict security requirements enabled that your current browser does not meet."

Kibana shows this message when a browser doesn't satisfy the CSP requirements (namely, it doesn't specify `unsafe-inline`) in strict mode (`csp.strict: true`). There seems to be a problem with configured `csp.rules`.

---

<div class="post-metadata">

**Author:** ![J\_Stan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/j_stan/32/78332_2.png) [@J\_Stan](https://discuss.elastic.co/u/J_Stan)\
**Post date:** [December 17, 2020, 5:03pm UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/259006/3 "2020-12-17T17:03:30Z")

</div>

Can you suggest what should be the rules please ?

This is what I have now

```auto
csp.rules:
 - "script-src https://MYSERVER.example.com 'self' 'unsafe-inline' 'unsafe-eval' https://*"
 - "child-src 'MYSERVER'"
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2021, 5:03pm UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/259006/4 "2021-01-14T17:03:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
