# Username or password is incorrect. Please try again. / HTTP/1.1 401 Unauthorized

**URL:** <https://discuss.elastic.co/t/username-or-password-is-incorrect-please-try-again-http-1-1-401-unauthorized/309145>\
**Category:** Kibana\
**Tags:** elastic-stack-security, docker\
**Created:** [July 7, 2022, 7:10pm UTC](https://discuss.elastic.co/t/username-or-password-is-incorrect-please-try-again-http-1-1-401-unauthorized/309145 "2022-07-07T19:10:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [July 7, 2022, 7:10pm UTC](https://discuss.elastic.co/t/username-or-password-is-incorrect-please-try-again-http-1-1-401-unauthorized/309145/1 "2022-07-07T19:10:08Z")

</div>

Hello World!

I'm trying to follow [Install Kibana with Docker | Kibana Guide [7.17] | Elastic](https://www.elastic.co/guide/en/kibana/7.17/docker.html) and even though it looks like Kibana started fine:

```auto
% docker compose logs --tail 1
kibana | {"type":"log","@timestamp":"2022-07-07T20:12:15+00:00","tags":["info","status"],"pid":7,"message":"Kibana is now available (was degraded)"}
%

```

I'm unable to login to Kibana w/ following banner:

> Username or password is incorrect. Please try again.

I have checked the connectivity from within of the container and to my Elasticsearch cluster (using ca, cert and key) everything works without any issues, yet getting 401 in logs when try to login via Kibana using valid credentials:

```auto
% docker compose logs --tail 2
kibana | {"type":"log","@timestamp":"2022-07-07T19:03:07+00:00","tags":["info","plugins","security","routes"],"pid":7,"message":"Logging in with provider \"basic\" (basic)"}
kibana | {"type":"response","@timestamp":"2022-07-07T19:03:07+00:00","tags":[],"pid":7,"method":"post","statusCode":401,"req":{"url":"/internal/security/login","method":"post","headers":{"host":"X.X.X:5601","connection":"keep-alive","content-length":"175","sec-ch-ua":"\"Chromium\";v=\"104\", \" Not A;Brand\";v=\"99\", \"Google Chrome\";v=\"104\"","dnt":"1","content-type":"application/json","sec-ch-ua-mobile":"?0","user-agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36","kbn-version":"7.17.4","sec-ch-ua-platform":"\"macOS\"","accept":"*/*","origin":"https://X.X.X:5601","sec-fetch-site":"same-origin","sec-fetch-mode":"cors","sec-fetch-dest":"empty","referer":"https://X.X.X:5601/login?next=%2F","accept-encoding":"gzip, deflate, br","accept-language":"en-US,en;q=0.9"},"remoteAddress":"192.168.128.1","userAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36","referer":"https://X.X.X:5601/login?next=%2F"},"res":{"statusCode":401,"responseTime":544,"contentLength":124},"message":"POST /internal/security/login 401 544ms - 124.0B"}

```

same (or similar) request as above, however using `curl` instead:

```auto
kibana@67b3beeb0eec:~$ curl --cacert /usr/share/elasticsearch/config/certificates/ca/ca.crt --cert /usr/share/elasticsearch/config/certificates/elastic7/elastic7.crt --key /usr/share/elasticsearch/config/certificates/elastic7/elastic7.key --user "$ELASTICSEARCH_USERNAME:$ELASTICSEARCH_PASSWORD" https://X.X.X:5601/internal/security/login -I
HTTP/1.1 401 Unauthorized
X-Content-Type-Options: nosniff
Referrer-Policy: no-referrer-when-downgrade
kbn-name: 7-k111
kbn-license-sig: bbac8ed5bf5514a791ee0acce3c70f1b237713fbd26cae45589ec69398171dfe
content-type: application/json; charset=utf-8
cache-control: private, no-cache, no-store, must-revalidate
content-length: 66
Date: Thu, 07 Jul 2022 19:53:40 GMT
Connection: keep-alive
Keep-Alive: timeout=120

kibana@67b3beeb0eec:~$

```

now using _same_ credentials, however connecting to Elasticsearch cluster _directly_ (w/out Kibana):

```auto
kibana@519e28384ee2:~$ curl --cacert /usr/share/elasticsearch/config/certificates/ca/ca.crt --cert /usr/share/elasticsearch/config/certificates/elastic7/elastic7.crt --key /usr/share/elasticsearch/config/certificates/elastic7/elastic7.key --user "$ELASTICSEARCH_USERNAME:$ELASTICSEARCH_PASSWORD" https://X.X.X:9200 -I
HTTP/2 200 
x-elastic-product: Elasticsearch
content-type: application/json; charset=UTF-8
content-length: 544
x-envoy-upstream-service-time: 9
strict-transport-security: max-age=31536000; includeSubDomains
date: Thu, 07 Jul 2022 19:40:34 GMT
server: istio-envoy

kibana@519e28384ee2:~$ 

```

my `kibana.yml`:

```auto
% cat ./config/kibana.yml | cut -d\: -f1
elasticsearch
  hosts
  - https
  password
  ssl
    certificateAuthorities
    verificationMode
  username
monitoring
  ui
    container
      elasticsearch
        enabled
server
  host
  name
xpack
  encryptedSavedObjects
    encryptionKey
  license_management
    ui
      enabled
  reporting
    encryptionKey
  security
    authc
      providers
        basic
          basic1
            order
        oidc
          Google
            order
            realm
    encryptionKey
%

```

Please advise.

---

<div class="post-metadata">

**Author:** ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Post date:** [July 8, 2022, 1:09am UTC](https://discuss.elastic.co/t/username-or-password-is-incorrect-please-try-again-http-1-1-401-unauthorized/309145/2 "2022-07-08T01:09:23Z")

</div>

I wasn't expecting the `--key` in the request. To avoid any certificate wonkiness, what happens if you use this:

```auto
curl --insecure --user "$ELASTICSEARCH_USERNAME:$ELASTICSEARCH_PASSWORD" https://X.X.X:5601/internal/security/login

```

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [July 8, 2022, 4:27am UTC](https://discuss.elastic.co/t/username-or-password-is-incorrect-please-try-again-http-1-1-401-unauthorized/309145/3 "2022-07-08T04:27:37Z")

</div>

@xeraa - thank you so much for looking into my topic, i appreciate your time!

per your request the command output:

```auto
kibana@e2dd07f3bc22:~$ curl --insecure --user "$ELASTICSEARCH_USERNAME:$ELASTICSEARCH_PASSWORD" https://X.X.X:5601/internal/security/login --head
HTTP/1.1 401 Unauthorized
X-Content-Type-Options: nosniff
Referrer-Policy: no-referrer-when-downgrade
kbn-name: kibana
kbn-license-sig: bbac8ed5bf5514a791ee0acce3c70f1b237713fbd26cae45589ec69398171dfe
content-type: application/json; charset=utf-8
cache-control: private, no-cache, no-store, must-revalidate
content-length: 66
Date: Fri, 08 Jul 2022 04:27:11 GMT
Connection: keep-alive
Keep-Alive: timeout=120

kibana@e2dd07f3bc22:~$

```

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [July 9, 2022, 4:41am UTC](https://discuss.elastic.co/t/username-or-password-is-incorrect-please-try-again-http-1-1-401-unauthorized/309145/4 "2022-07-09T04:41:33Z")

</div>

and it's turned out to be Mutual TLS authentication between Kibana and Elasticsearch related..

> **[Mutual TLS authentication between Kibana and Elasticsearch | Kibana Guide...](https://www.elastic.co/guide/en/kibana/7.17/elasticsearch-mutual-tls.html)**
>
> A list of the supported authentication mechanisms in Kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2022, 4:42am UTC](https://discuss.elastic.co/t/username-or-password-is-incorrect-please-try-again-http-1-1-401-unauthorized/309145/5 "2022-08-06T04:42:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
