# This Elastic installation has strict security requirements enabled that your current browser does not meet

**URL:** <https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/355298>\
**Category:** Kibana\
**Created:** [March 13, 2024, 9:36am UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/355298 "2024-03-13T09:36:27Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![nkf\_123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nkf_123/32/125692_2.png) [@nkf\_123](https://discuss.elastic.co/u/nkf_123)\
**Post date:** [March 13, 2024, 9:36am UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/355298/1 "2024-03-13T09:36:27Z")

</div>

I tried in Chrome, edge and Firefox after updating the browser version but not working. Please see the screenshot attached.

Getting this : " **This Elastic installation has strict security requirements enabled that your current browser does not meet.**"

The only difference I see is the Windows version. My client is using Windows Pro whereas we use the enterprise version.

 ![image (1)](https://us1.discourse-cdn.com/elastic/original/3X/4/9/49b72b30340708e8d00c3a26a12b97062d311f91.png)

We identified a potential method to enable access by manipulating the CSP settings, specifically by setting Kibana's strict mode for CSP to false. However, it's essential to note that disabling Kibana's strict CSP mode increases the risk of security vulnerabilities.

Kindly provide some way out for this.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [March 14, 2024, 10:40am UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/355298/2 "2024-03-14T10:40:13Z")

</div>

Hi @nkf_123,

Do you have a proxy in front of Kibana at all? I assume you're using the latest versions of Chrome, Edge and Firefox?

---

<div class="post-metadata">

**Author:** ![nkf\_123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nkf_123/32/125692_2.png) [@nkf\_123](https://discuss.elastic.co/u/nkf_123)\
**Post date:** [March 14, 2024, 3:21pm UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/355298/3 "2024-03-14T15:21:49Z")

</div>

I am not 100% but I do think there is a proxy @carly.richmond

And yes, I am using the latest chrome version.

But how do I fix this? csp.strict : false will hamper with the security

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [March 18, 2024, 10:33am UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/355298/4 "2024-03-18T10:33:18Z")

</div>

Can you share your Kibana config @nkf_123, including any proxy-specific configuration that you've added? Are you using nginx or an alternative?

---

<div class="post-metadata">

**Author:** ![nkf\_123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nkf_123/32/125692_2.png) [@nkf\_123](https://discuss.elastic.co/u/nkf_123)\
**Post date:** [March 18, 2024, 10:57am UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/355298/5 "2024-03-18T10:57:30Z")

</div>

@carly.richmond  
Sorry, I cannot share it.

But could you advise whether setting it to the following will cause an issue?

csp.strict: false  
csp.warnLegacyBrowsers: true

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [March 19, 2024, 9:22am UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/355298/6 "2024-03-19T09:22:32Z")

</div>

As you said in your original message @nkf_123 disabling Kibana's strict CSP mode does open you up to unsafe scripting practices. You can enable these options if you're comfortable with the risk.

Alternatively I would look at your proxy settings to see if they need to be tweaked. There is an example in [this thread](https://discuss.elastic.co/t/nginx-reverse-proxy-setup-for-kibana/167327/5).

I also assume you're not embedding the Kibana dashboard in a web application, which can also give you CSP issues if misconfigured?

Hope that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 16, 2024, 9:22am UTC](https://discuss.elastic.co/t/this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/355298/7 "2024-04-16T09:22:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
