# Unable to authenticate user \[\*\*\*\*\*\] for REST request \[/\]

**URL:** <https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/197461>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 30, 2019, 7:49am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/197461 "2019-08-30T07:49:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![akhil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhil/32/116231_2.png) [@akhil](https://discuss.elastic.co/u/akhil)\
**Post date:** [August 30, 2019, 7:49am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/197461/1 "2019-08-30T07:49:38Z")

</div>

Hi Team,

\*I have created one user from kibana UI and also from elastic server using the REST API.  
Now when I'm trying to hit the API using my new user id and password I'm getting the error message -

\*API that I'm using -

**curl -v -u akhil:akhil12345 -X GET "https://\*\*\*\*\*\*\*.** \*\*\*.com:7878/\_xpack/security/\_authenticate"

below is the error message -

- Connection #0 to host _ **.** _\*\*\*.com left intact

{"error":{"root\_cause":[{"type":"security\_exception","reason":"unable to authenticate user [akhil] for REST request [/\_xpack/security/\_authenticate]","header":{"WWW-Authenticate":["Bearer realm="security"","Basic realm="security" charset="UTF-8""]}}],"type":"security\_exception","reason":"unable to authenticate user [akhil] for REST request [/\_xpack/security/\_authenticate]","header":{"WWW-Authenticate":["Bearer realm="security"","Basic realm="security" charset="UTF-8""]}},"status":401}

Also, unable to login kibana with this new uid and password.

\*it's working fine for elastic

curl -v -u elastic:akhil12345 -X GET "https://\*\*\*\*\*\*\*.\*\*\*\*\*.com:7878/\_xpack/security/\_authenticate"

{"username":"elastic","roles":["superuser"],"full\_name":null,"email":null,"metadata":{"\_reserved":true},"enabled":true}

\*API used for creating user -

**curl -v -u elastic:akhil12345 -X POST "https://** _ **.** _**.com:7878/\_xpack/security/user/akhil?pretty" -H 'Content-Type: application/json' -d'  
{  
"password" : "akhil12345",  
"roles" : ["superuser", "other\_role1"],  
"full\_name" : "Akhil Patwal",  
"email" : "akhil@ ****.**",  
"metadata" : {  
"intelligence" : 7  
}  
}

I can see this user when hitting the below API -

**curl -v -u elastic:akhil12345 -X GET "https://** _ **.** _\*\*.com:7878/\_xpack/security/user"

#0 to host **.** \*\*.com left intact

":{},"enabled":true},"akhil":{"username":"akhil","roles":["superuser"],"full\_name":null,"email":null,"metadata":{},"enabled":

Tried to create the user from kibana also, but my bad luck it's not working, getting the same error.

Below are some more details regarding this ELK setup :

1. Using nginx reverse proxy method- port 7878 has been used

2. We have valid ssl certificates that we are using currently.

3. Also having a gold licence. It's also in used.

Please let us know, how it can be resolved. If you want more details kindly let us know.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 30, 2019, 8:00am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/197461/2 "2019-08-30T08:00:20Z")

</div>

A number of things can be happening:

- Your password is wrong or misstyped. You can use the [change password API](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-change-password.html) authenticating as the `elastic` user to change the password of your akhil user just to be sure.

- You have defined an extra authentication realm in your `elasticsearch.yml`. Doing so, stops the native realm from being implicitly enabled, so you need to explicitly enable it yourself. See [https://www.elastic.co/guide/en/elasticsearch/reference/7.3/configuring-native-realm.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/configuring-native-realm.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2019, 8:00am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/197461/3 "2019-09-27T08:00:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
