# Kibana boom error after install Search Guard

**URL:** <https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650>\
**Category:** Search Guard\
**Created:** [October 23, 2017, 11:30am UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650 "2017-10-23T11:30:23Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sergey\_Emcev](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@Sergey\_Emcev](https://forum.search-guard.com/u/Sergey_Emcev)\
**Post date:** [October 23, 2017, 11:30am UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/1 "2017-10-23T11:30:23Z")

</div>

Hello !  
After install search guard plugin for elasticsearch and Kibana i have trouble with create index pattern in management tab on kibana

In browser:

```
Error: An internal server error occurred

```

at https://------/bundles/kibana.bundle.js?v=15543:227:21357  
at processQueue (https://------/bundles/commons.bundle.js?v=15543:38:23621)  
at https://----------/bundles/commons.bundle.js?v=15543:38:23888  
at Scope.$eval (https://------------/bundles/commons.bundle.js?v=15543:39:4619)  
at Scope.$digest (https://--------------/bundles/commons.bundle.js?v=15543:39:2359)  
at Scope.$apply (https://------------------/bundles/commons.bundle.js?v=15543:39:5037)  
at done (https://----------------------/bundles/commons.bundle.js?v=15543:37:25027)  
at completeRequest (https://---------------/bundles/commons.bundle.js?v=15543:37:28702)  
at XMLHttpRequest.xhr.onload (https://------------/bundles/commons.bundle.js?v=15543:37:29634)

In kibana log:

{“type”:“error”,“@timestamp”:“2017-10-23T11:29:32Z”,“tags”:,“pid”:7526,“level”:“error”,“message”:“Cannot provide statusCode or message with boom error”,“error”:{“message”:“Cannot provide statusCode or message with boom error”,“name”:“Error”,“stack”:“Error: Cannot provide statusCode or message with boom error\n at Object.exports.assert (/usr/share/kibana/node\_modules/hoek/lib/index.js:736:11)\n at Object.exports.wrap (/usr/share/kibana/node\_modules/boom/lib/index.js:96:10)\n at convertEsError (/usr/share/kibana/src/server/index\_patterns/service/lib/errors.js:67:25)\n at /usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:63:40\n at throw (native)\n at step (/usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:74:191)\n at /usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:74:402”},“url”:{“protocol”:null,“slashes”:null,“auth”:null,“host”:null,“port”:null,“hostname”:null,“hash”:null,“search”:“?pattern=logstash-_&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D",“query”:{“pattern”:"logstash-_”,“meta\_fields”:“["\_source","\_id","\_type","\_index","\_score"]”},“pathname”:“/api/index\_patterns/\_fields\_for\_wildcard”,“path”:“/api/index\_patterns/\_fields\_for\_wildcard?pattern=logstash-_&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D",“href”:"/api/index\_patterns/\_fields\_for\_wildcard?pattern=logstash-_&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D”}}

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [October 23, 2017, 11:33am UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/2 "2017-10-23T11:33:48Z")

</div>

Please post:

- which version of ES/KI/SG and the plugin you are using

- which roles does the user you log in with have, and which permissions do these roles have? Just post the Search Guard config files you are using

- do you have any other plugins installed?

- please post the contents of the ES log file when the KI error happens

Your error description is too vague, we need the above infos otherwise we can’t help.

> **···**
>
> On Monday, October 23, 2017 at 1:30:23 PM UTC+2, Sergey Emcev wrote:
> 
> > Hello !  
> > After install search guard plugin for elasticsearch and Kibana i have trouble with create index pattern in management tab on kibana
> 
> > 
> 
> > In browser:
> 
> > ```
> > Error: An internal server error occurred
> > 
> > ```
> > 
> > at https://------/bundles/kibana. bundle.js?v=15543:227:21357  
> > at processQueue (https://------/bundles/commons.bundle.js?v=15543:38: 23621)  
> > at https://----------/bundles/commons.bundle.js?v=15543:38: 23888  
> > at Scope.$eval (https://------------/bundles/commons.bundle.js?v=15543:39: 4619)  
> > at Scope.$digest (https://--------------/bundles/commons.bundle.js?v= 15543:39:2359)  
> > at Scope.$apply (https://------------------/bundles/commons.bundle.js?v= 15543:39:5037)  
> > at done (https://----------------------/bundles/commons.bundle.js?v= 15543:37:25027)  
> > at completeRequest (https://---------------/bundles/commons.bundle.js?v= 15543:37:28702)  
> > at XMLHttpRequest.xhr.onload (https://------------/bundles/commons.bundle.js?v=15543:37:29634)
> 
> > 
> 
> > 
> 
> > In kibana log:
> 
> > {“type”:“error”,“@timestamp”:“2017-10-23T11:29:32Z”,“tags”:,“pid”:7526,“level”:“error”,“message”:“Cannot provide statusCode or message with boom error”,“error”:{“message”:“Cannot provide statusCode or message with boom error”,“name”:“Error”,“stack”:“Error: Cannot provide statusCode or message with boom error\n at Object.exports.assert (/usr/share/kibana/node\_modules/hoek/lib/index.js:736:11)\n at Object.exports.wrap (/usr/share/kibana/node\_modules/boom/lib/index.js:96:10)\n at convertEsError (/usr/share/kibana/src/server/index\_patterns/service/lib/errors.js:67:25)\n at /usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:63:40\n at throw (native)\n at step (/usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:74:191)\n at /usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:74:402”},“url”:{“protocol”:null,“slashes”:null,“auth”:null,“host”:null,“port”:null,“hostname”:null,“hash”:null,“search”:“?pattern=logstash-_&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D",“query”:{“pattern”:"logstash-_”,“meta\_fields”:“["\_source","\_id","\_type","\_index","\_score"]”},“pathname”:“/api/index\_patterns/\_fields\_for\_wildcard”,“path”:“/api/index\_patterns/\_fields\_for\_wildcard?pattern=logstash-_&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D",“href”:"/api/index\_patterns/\_fields\_for\_wildcard?pattern=logstash-_&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D”}}

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [October 23, 2017, 12:08pm UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/3 "2017-10-23T12:08:38Z")

</div>

First, it seems you do not have the Search Guard Kibana plugin installed, this is required for Kibana session management:

> **[Installing the Plugin](http://floragunncom.github.io/search-guard-docs/kibana.html)**
>
> How to install the Search Guard Kibana plugin which adds authentication, multi-tenancy and the configuration UI.

Then it looks like you have configured TLS on REST layer (aka HTTPS), but Kibana is till talking HTTP, see this error message:

2017-10-23T15:01:35,565][WARN][c.f.s.h.SearchGuardHttpServerTransport] [------] Someone (/[127.0.0.1:60938](http://127.0.0.1:60938/)) speaks http plaintext instead of ssl, will close the channel

Please configure HTTPS for your KI - ES connection, described here in the docs:

> **[Installing the Plugin](http://floragunncom.github.io/search-guard-docs/kibana.html)**
>
> How to install the Search Guard Kibana plugin which adds authentication, multi-tenancy and the configuration UI.

> **···**
>
> On Monday, October 23, 2017 at 1:33:48 PM UTC+2, Jochen Kressin wrote:
> 
> > Please post:
> 
> > - which version of ES/KI/SG and the plugin you are using
> 
> > - which roles does the user you log in with have, and which permissions do these roles have? Just post the Search Guard config files you are using
> 
> > - do you have any other plugins installed?
> 
> > - please post the contents of the ES log file when the KI error happens
> > 
> > Your error description is too vague, we need the above infos otherwise we can’t help.
> > 
> > On Monday, October 23, 2017 at 1:30:23 PM UTC+2, Sergey Emcev wrote:
> > 
> > > Hello !  
> > > After install search guard plugin for elasticsearch and Kibana i have trouble with create index pattern in management tab on kibana
> 
> > >
> 
> > > In browser:
> 
> > > ```
> > > Error: An internal server error occurred
> > > 
> > > ```
> > > 
> > > at https://------/bundles/kibana. bundle.js?v=15543:227:21357  
> > > at processQueue (https://------/bundles/commons.bundle.js?v=15543:38: 23621)  
> > > at https://----------/bundles/commons.bundle.js?v=15543:38: 23888  
> > > at Scope.$eval (https://------------/bundles/commons.bundle.js?v=15543:39: 4619)  
> > > at Scope.$digest (https://--------------/bundles/commons.bundle.js?v= 15543:39:2359)  
> > > at Scope.$apply (https://------------------/bundles/commons.bundle.js?v= 15543:39:5037)  
> > > at done (https://----------------------/bundles/commons.bundle.js?v= 15543:37:25027)  
> > > at completeRequest (https://---------------/bundles/commons.bundle.js?v= 15543:37:28702)  
> > > at XMLHttpRequest.xhr.onload (https://------------/bundles/commons.bundle.js?v=15543:37:29634)
> 
> > >
> 
> > >
> 
> > > In kibana log:
> 
> > > {“type”:“error”,“@timestamp”:“2017-10-23T11:29:32Z”,“tags”:,“pid”:7526,“level”:“error”,“message”:“Cannot provide statusCode or message with boom error”,“error”:{“message”:“Cannot provide statusCode or message with boom error”,“name”:“Error”,“stack”:“Error: Cannot provide statusCode or message with boom error\n at Object.exports.assert (/usr/share/kibana/node\_modules/hoek/lib/index.js:736:11)\n at Object.exports.wrap (/usr/share/kibana/node\_modules/boom/lib/index.js:96:10)\n at convertEsError (/usr/share/kibana/src/server/index\_patterns/service/lib/errors.js:67:25)\n at /usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:63:40\n at throw (native)\n at step (/usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:74:191)\n at /usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:74:402”},“url”:{“protocol”:null,“slashes”:null,“auth”:null,“host”:null,“port”:null,“hostname”:null,“hash”:null,“search”:“?pattern=logstash-_&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D",“query”:{“pattern”:"logstash-_”,“meta\_fields”:“["\_source","\_id","\_type","\_index","\_score"]”},“pathname”:“/api/index\_patterns/\_fields\_for\_wildcard”,“path”:“/api/index\_patterns/\_fields\_for\_wildcard?pattern=logstash-_&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D",“href”:"/api/index\_patterns/\_fields\_for\_wildcard?pattern=logstash-_&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D”}}

---

<div class="post-metadata">

**Author:** ![Sergey\_Emcev](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@Sergey\_Emcev](https://forum.search-guard.com/u/Sergey_Emcev)\
**Post date:** [October 23, 2017, 12:17pm UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/4 "2017-10-23T12:17:31Z")

</div>

> > > No, No - i installed plugin Search guard for Kibana

And https also configured

See attached

 ![](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/1X/4941bd6fdccb57747f450d693759a8e8b9246eb6.jpeg)

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [October 23, 2017, 12:25pm UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/5 "2017-10-23T12:25:30Z")

</div>

Ok, let’s analyze step by step. This error message from your ES logfile:

2017-10-23T15:01:35,565][WARN][c.f.s.h.SearchGuardHttpServerTransport] [------] Someone (/[127.0.0.1:60938](http://127.0.0.1:60938/)) speaks http plaintext instead of ssl, will close the channel

Means that someone (a plugin, a tool etc.) is trying to connect to your ES cluster with HTTP, and not HTTPS. If you have other tools or plugins enabled, please disable them first, so we can have a clearer picture.

Please also post your kibana.yml, maybe it’s about the HTTP header.

Also, set your ES cluster to debug level, restart, and reproduce the error. We need to see the ES log in the moment when the error occurs.

How to enable debug level for SG plugin:

> **[TLS troubleshooting](http://floragunncom.github.io/search-guard-docs/tls_troubleshooting.html)**
>
> Step-by-step instructions to troubleshoot Search Guard TLS and certificates issues

Section “Setting the log level to debug”

> **···**
>
> On Monday, October 23, 2017 at 2:17:32 PM UTC+2, Sergey Emcev wrote:
> 
> > > > > No, No - i installed plugin Search guard for Kibana
> 
> > And https also configured
> 
> > See attached
> 
> >

---

<div class="post-metadata">

**Author:** ![Sergey\_Emcev](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@Sergey\_Emcev](https://forum.search-guard.com/u/Sergey_Emcev)\
**Post date:** [October 23, 2017, 1:38pm UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/6 "2017-10-23T13:38:29Z")

</div>

Ok. Found who send http - logstash. Disable

Here is parameters in my kibana.yml

server.port: 5601

server.host: “0.0.0.0”

elasticsearch.url: “https://---------------:9200”

elasticsearch.username: “kibanaserver”

elasticsearch.password: “kibanaserver”

searchguard.basicauth.enabled: false

searchguard.multitenancy.enabled: false

elasticsearch.ssl.verificationMode: none

ES log in error moment attached

[es.log](https://forum.search-guard.com/uploads/short-url/j4sCniXdtBTJbyViVa0THYw9WIe.log) (137 KB)

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [October 23, 2017, 1:59pm UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/7 "2017-10-23T13:59:23Z")

</div>

You have set basic authentication to false in kibana.yml:

searchguard.basicauth.enabled: false

Which means the login dialogue is not displayed and no user credentials are passed from Kibana to Elasticsearch. If you want to use HTTP Basic Authentication, then you need this parameter set to true. From the logfiles, I can see that you have an HTTP Basic Authenticator enabled in sg\_config, so I’m assuming that’s what you want to use. If you intend to use some SSO auth, like JWT or Proxy, let me know.

> **···**
>
> On Monday, October 23, 2017 at 3:38:30 PM UTC+2, Sergey Emcev wrote:
> 
> > Ok. Found who send http - logstash. Disable
> 
> > 
> 
> > Here is parameters in my kibana.yml
> 
> > 
> 
> > server.port: 5601
> 
> > server.host: “0.0.0.0”
> 
> > elasticsearch.url: “https://---------------:9200”
> 
> > elasticsearch.username: “kibanaserver”
> 
> > elasticsearch.password: “kibanaserver”
> 
> > searchguard.basicauth.enabled: false
> 
> > searchguard.multitenancy.enabled: false
> 
> > elasticsearch.ssl.verificationMode: none
> 
> > 
> 
> > 
> 
> > ES log in error moment attached
> 
> >

---

<div class="post-metadata">

**Author:** ![Sergey\_Emcev](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@Sergey\_Emcev](https://forum.search-guard.com/u/Sergey_Emcev)\
**Post date:** [October 23, 2017, 2:11pm UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/8 "2017-10-23T14:11:00Z")

</div>

We use kerberos and no need basic authentication.

> **···**
>
> понедельник, 23 октября 2017 г., 16:59:23 UTC+3 пользователь Jochen Kressin написал:
> 
> > You have set basic authentication to false in kibana.yml:
> 
> > searchguard.basicauth.enabled: false
> 
> > Which means the login dialogue is not displayed and no user credentials are passed from Kibana to Elasticsearch. If you want to use HTTP Basic Authentication, then you need this parameter set to true. From the logfiles, I can see that you have an HTTP Basic Authenticator enabled in sg\_config, so I’m assuming that’s what you want to use. If you intend to use some SSO auth, like JWT or Proxy, let me know.
> 
> > 
> 
> > 
> 
> > >

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [October 23, 2017, 2:15pm UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/9 "2017-10-23T14:15:01Z")

</div>

So please check first if you can access ES directly with Kerberos, not via Kibana. I want to first make sure basic Kerberos auth is working. Please also post the Search Guard configuraton files.

> **···**
>
> On Monday, October 23, 2017 at 4:11:01 PM UTC+2, Sergey Emcev wrote:
> 
> > We use kerberos and no need basic authentication.
> > 
> > понедельник, 23 октября 2017 г., 16:59:23 UTC+3 пользователь Jochen Kressin написал:
> > 
> > > You have set basic authentication to false in kibana.yml:
> 
> > > searchguard.basicauth.enabled: false
> 
> > > Which means the login dialogue is not displayed and no user credentials are passed from Kibana to Elasticsearch. If you want to use HTTP Basic Authentication, then you need this parameter set to true. From the logfiles, I can see that you have an HTTP Basic Authenticator enabled in sg\_config, so I’m assuming that’s what you want to use. If you intend to use some SSO auth, like JWT or Proxy, let me know.
> 
> > >
> 
> > >
> 
> > > >

---

<div class="post-metadata">

**Author:** ![Sergey\_Emcev](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@Sergey\_Emcev](https://forum.search-guard.com/u/Sergey_Emcev)\
**Post date:** [October 23, 2017, 2:29pm UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/10 "2017-10-23T14:29:37Z")

</div>

Attached screenshot directly connect to es via kerberos and sg\_config  
In sg\_roles\_mapping i add my account to group sg\_all\_access

 ![](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/1X/97593985f13c3ce5eaa98e28af2546e3418abfc7.jpeg)

[sg\_config.txt](https://forum.search-guard.com/uploads/short-url/i0p0gYfovF6XJrD8RADS9Wh9NgM.txt) (5.62 KB)

> **···**
>
> понедельник, 23 октября 2017 г., 17:15:01 UTC+3 пользователь Jochen Kressin написал:
> 
> > So please check first if you can access ES directly with Kerberos, not via Kibana. I want to first make sure basic Kerberos auth is working. Please also post the Search Guard configuraton files.
> 
> > On Monday, October 23, 2017 at 4:11:01 PM UTC+2, Sergey Emcev wrote:
> > 
> > > We use kerberos and no need basic authentication.
> > > 
> > > понедельник, 23 октября 2017 г., 16:59:23 UTC+3 пользователь Jochen Kressin написал:
> > > 
> > > > You have set basic authentication to false in kibana.yml:
> 
> > > > searchguard.basicauth.enabled: false
> 
> > > > Which means the login dialogue is not displayed and no user credentials are passed from Kibana to Elasticsearch. If you want to use HTTP Basic Authentication, then you need this parameter set to true. From the logfiles, I can see that you have an HTTP Basic Authenticator enabled in sg\_config, so I’m assuming that’s what you want to use. If you intend to use some SSO auth, like JWT or Proxy, let me know.
> 
> > > >
> 
> > > >
> 
> > > > >

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [October 23, 2017, 5:21pm UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/11 "2017-10-23T17:21:57Z")

</div>

Ok, the configs seem valid, we’ll need to investigate this. Just a last check - please verify that this error also occurs when Sentinl is not installed (means, please remove it from plugins folder, don’t just disable it in kibana.yml)

> **···**
>
> On Monday, October 23, 2017 at 4:29:37 PM UTC+2, Sergey Emcev wrote:
> 
> > Attached screenshot directly connect to es via kerberos and sg\_config  
> > In sg\_roles\_mapping i add my account to group sg\_all\_access
> 
> > 
> 
> > 
> 
> > понедельник, 23 октября 2017 г., 17:15:01 UTC+3 пользователь Jochen Kressin написал:
> > 
> > > So please check first if you can access ES directly with Kerberos, not via Kibana. I want to first make sure basic Kerberos auth is working. Please also post the Search Guard configuraton files.
> 
> > > On Monday, October 23, 2017 at 4:11:01 PM UTC+2, Sergey Emcev wrote:
> > > 
> > > > We use kerberos and no need basic authentication.
> > > > 
> > > > понедельник, 23 октября 2017 г., 16:59:23 UTC+3 пользователь Jochen Kressin написал:
> > > > 
> > > > > You have set basic authentication to false in kibana.yml:
> 
> > > > > searchguard.basicauth.enabled: false
> 
> > > > > Which means the login dialogue is not displayed and no user credentials are passed from Kibana to Elasticsearch. If you want to use HTTP Basic Authentication, then you need this parameter set to true. From the logfiles, I can see that you have an HTTP Basic Authenticator enabled in sg\_config, so I’m assuming that’s what you want to use. If you intend to use some SSO auth, like JWT or Proxy, let me know.
> 
> > > > >
> 
> > > > >
> 
> > > > > >

---

<div class="post-metadata">

**Author:** ![Sergey\_Emcev](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@Sergey\_Emcev](https://forum.search-guard.com/u/Sergey_Emcev)\
**Post date:** [October 24, 2017, 9:32am UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/12 "2017-10-24T09:32:43Z")

</div>

Ok, remove sentinl.

The problem not solve.

> **···**
>
> понедельник, 23 октября 2017 г., 20:21:58 UTC+3 пользователь Jochen Kressin написал:
> 
> > Ok, the configs seem valid, we’ll need to investigate this. Just a last check - please verify that this error also occurs when Sentinl is not installed (means, please remove it from plugins folder, don’t just disable it in kibana.yml)
> > 
> > On Monday, October 23, 2017 at 4:29:37 PM UTC+2, Sergey Emcev wrote:
> > 
> > > Attached screenshot directly connect to es via kerberos and sg\_config  
> > > In sg\_roles\_mapping i add my account to group sg\_all\_access
> 
> > >
> 
> > >
> 
> > > понедельник, 23 октября 2017 г., 17:15:01 UTC+3 пользователь Jochen Kressin написал:
> > > 
> > > > So please check first if you can access ES directly with Kerberos, not via Kibana. I want to first make sure basic Kerberos auth is working. Please also post the Search Guard configuraton files.
> 
> > > > On Monday, October 23, 2017 at 4:11:01 PM UTC+2, Sergey Emcev wrote:
> > > > 
> > > > > We use kerberos and no need basic authentication.
> > > > > 
> > > > > понедельник, 23 октября 2017 г., 16:59:23 UTC+3 пользователь Jochen Kressin написал:
> > > > > 
> > > > > > You have set basic authentication to false in kibana.yml:
> 
> > > > > > searchguard.basicauth.enabled: false
> 
> > > > > > Which means the login dialogue is not displayed and no user credentials are passed from Kibana to Elasticsearch. If you want to use HTTP Basic Authentication, then you need this parameter set to true. From the logfiles, I can see that you have an HTTP Basic Authenticator enabled in sg\_config, so I’m assuming that’s what you want to use. If you intend to use some SSO auth, like JWT or Proxy, let me know.
> 
> > > > > >
> 
> > > > > >
> 
> > > > > > >

---

<div class="post-metadata">

**Author:** ![Sergey\_Emcev](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@Sergey\_Emcev](https://forum.search-guard.com/u/Sergey_Emcev)\
**Post date:** [October 25, 2017, 2:08pm UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/13 "2017-10-25T14:08:29Z")

</div>

Well, after update elasticsearch, kibana, logstah and search-guard plugin for elasticsearch and kibana … it works !  
I did not do anything else

Magic …

> **···**
>
> вторник, 24 октября 2017 г., 12:32:43 UTC+3 пользователь Sergey Emcev написал:
> 
> > Ok, remove sentinl.
> 
> > The problem not solve.
> > 
> > понедельник, 23 октября 2017 г., 20:21:58 UTC+3 пользователь Jochen Kressin написал:
> > 
> > > Ok, the configs seem valid, we’ll need to investigate this. Just a last check - please verify that this error also occurs when Sentinl is not installed (means, please remove it from plugins folder, don’t just disable it in kibana.yml)
> > > 
> > > On Monday, October 23, 2017 at 4:29:37 PM UTC+2, Sergey Emcev wrote:
> > > 
> > > > Attached screenshot directly connect to es via kerberos and sg\_config  
> > > > In sg\_roles\_mapping i add my account to group sg\_all\_access
> 
> > > >
> 
> > > >
> 
> > > > понедельник, 23 октября 2017 г., 17:15:01 UTC+3 пользователь Jochen Kressin написал:
> > > > 
> > > > > So please check first if you can access ES directly with Kerberos, not via Kibana. I want to first make sure basic Kerberos auth is working. Please also post the Search Guard configuraton files.
> 
> > > > > On Monday, October 23, 2017 at 4:11:01 PM UTC+2, Sergey Emcev wrote:
> > > > > 
> > > > > > We use kerberos and no need basic authentication.
> > > > > > 
> > > > > > понедельник, 23 октября 2017 г., 16:59:23 UTC+3 пользователь Jochen Kressin написал:
> > > > > > 
> > > > > > > You have set basic authentication to false in kibana.yml:
> 
> > > > > > > searchguard.basicauth.enabled: false
> 
> > > > > > > Which means the login dialogue is not displayed and no user credentials are passed from Kibana to Elasticsearch. If you want to use HTTP Basic Authentication, then you need this parameter set to true. From the logfiles, I can see that you have an HTTP Basic Authenticator enabled in sg\_config, so I’m assuming that’s what you want to use. If you intend to use some SSO auth, like JWT or Proxy, let me know.
> 
> > > > > > >
> 
> > > > > > >
> 
> > > > > > > >

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [October 26, 2017, 9:06am UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/14 "2017-10-26T09:06:35Z")

</div>

I’d really like to understand the magic here 😉 because clearly, something was going on with your setup. We’ve tried to replicate the issue yesterday with the versions and configs you provided, but were not able to.

So, can you please share what exactly you did / upgraded / to which version? Because so far all our Kerberos integration tests are working fine ootb and we want to make sure there’s no real issue in SG itself.

Thanks!

> **···**
>
> On Wednesday, October 25, 2017 at 4:08:29 PM UTC+2, Sergey Emcev wrote:
> 
> > Well, after update elasticsearch, kibana, logstah and search-guard plugin for elasticsearch and kibana … it works !  
> > I did not do anything else
> 
> > Magic …
> > 
> > вторник, 24 октября 2017 г., 12:32:43 UTC+3 пользователь Sergey Emcev написал:
> > 
> > > Ok, remove sentinl.
> 
> > > The problem not solve.
> > > 
> > > понедельник, 23 октября 2017 г., 20:21:58 UTC+3 пользователь Jochen Kressin написал:
> > > 
> > > > Ok, the configs seem valid, we’ll need to investigate this. Just a last check - please verify that this error also occurs when Sentinl is not installed (means, please remove it from plugins folder, don’t just disable it in kibana.yml)
> > > > 
> > > > On Monday, October 23, 2017 at 4:29:37 PM UTC+2, Sergey Emcev wrote:
> > > > 
> > > > > Attached screenshot directly connect to es via kerberos and sg\_config  
> > > > > In sg\_roles\_mapping i add my account to group sg\_all\_access
> 
> > > > >
> 
> > > > >
> 
> > > > > понедельник, 23 октября 2017 г., 17:15:01 UTC+3 пользователь Jochen Kressin написал:
> > > > > 
> > > > > > So please check first if you can access ES directly with Kerberos, not via Kibana. I want to first make sure basic Kerberos auth is working. Please also post the Search Guard configuraton files.
> 
> > > > > > On Monday, October 23, 2017 at 4:11:01 PM UTC+2, Sergey Emcev wrote:
> > > > > > 
> > > > > > > We use kerberos and no need basic authentication.
> > > > > > > 
> > > > > > > понедельник, 23 октября 2017 г., 16:59:23 UTC+3 пользователь Jochen Kressin написал:
> > > > > > > 
> > > > > > > > You have set basic authentication to false in kibana.yml:
> 
> > > > > > > > searchguard.basicauth.enabled: false
> 
> > > > > > > > Which means the login dialogue is not displayed and no user credentials are passed from Kibana to Elasticsearch. If you want to use HTTP Basic Authentication, then you need this parameter set to true. From the logfiles, I can see that you have an HTTP Basic Authenticator enabled in sg\_config, so I’m assuming that’s what you want to use. If you intend to use some SSO auth, like JWT or Proxy, let me know.
> 
> > > > > > > >
> 
> > > > > > > >
> 
> > > > > > > > >

---

<div class="post-metadata">

**Author:** ![Sergey\_Emcev](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@Sergey\_Emcev](https://forum.search-guard.com/u/Sergey_Emcev)\
**Post date:** [October 26, 2017, 12:23pm UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/15 "2017-10-26T12:23:33Z")

</div>

All components upgraded from 5.6.2 to 5.6.3

> **···**
>
> четверг, 26 октября 2017 г., 12:06:35 UTC+3 пользователь Jochen Kressin написал:
> 
> > I’d really like to understand the magic here 😉 because clearly, something was going on with your setup. We’ve tried to replicate the issue yesterday with the versions and configs you provided, but were not able to.
> 
> > So, can you please share what exactly you did / upgraded / to which version? Because so far all our Kerberos integration tests are working fine ootb and we want to make sure there’s no real issue in SG itself.
> 
> > Thanks!
> > 
> > On Wednesday, October 25, 2017 at 4:08:29 PM UTC+2, Sergey Emcev wrote:
> > 
> > > Well, after update elasticsearch, kibana, logstah and search-guard plugin for elasticsearch and kibana … it works !  
> > > I did not do anything else
> 
> > > Magic …
> > > 
> > > вторник, 24 октября 2017 г., 12:32:43 UTC+3 пользователь Sergey Emcev написал:
> > > 
> > > > Ok, remove sentinl.
> 
> > > > The problem not solve.
> > > > 
> > > > понедельник, 23 октября 2017 г., 20:21:58 UTC+3 пользователь Jochen Kressin написал:
> > > > 
> > > > > Ok, the configs seem valid, we’ll need to investigate this. Just a last check - please verify that this error also occurs when Sentinl is not installed (means, please remove it from plugins folder, don’t just disable it in kibana.yml)
> > > > > 
> > > > > On Monday, October 23, 2017 at 4:29:37 PM UTC+2, Sergey Emcev wrote:
> > > > > 
> > > > > > Attached screenshot directly connect to es via kerberos and sg\_config  
> > > > > > In sg\_roles\_mapping i add my account to group sg\_all\_access
> 
> > > > > >
> 
> > > > > >
> 
> > > > > > понедельник, 23 октября 2017 г., 17:15:01 UTC+3 пользователь Jochen Kressin написал:
> > > > > > 
> > > > > > > So please check first if you can access ES directly with Kerberos, not via Kibana. I want to first make sure basic Kerberos auth is working. Please also post the Search Guard configuraton files.
> 
> > > > > > > On Monday, October 23, 2017 at 4:11:01 PM UTC+2, Sergey Emcev wrote:
> > > > > > > 
> > > > > > > > We use kerberos and no need basic authentication.
> > > > > > > > 
> > > > > > > > понедельник, 23 октября 2017 г., 16:59:23 UTC+3 пользователь Jochen Kressin написал:
> > > > > > > > 
> > > > > > > > > You have set basic authentication to false in kibana.yml:
> 
> > > > > > > > > searchguard.basicauth.enabled: false
> 
> > > > > > > > > Which means the login dialogue is not displayed and no user credentials are passed from Kibana to Elasticsearch. If you want to use HTTP Basic Authentication, then you need this parameter set to true. From the logfiles, I can see that you have an HTTP Basic Authenticator enabled in sg\_config, so I’m assuming that’s what you want to use. If you intend to use some SSO auth, like JWT or Proxy, let me know.
> 
> > > > > > > > >
> 
> > > > > > > > >
> 
> > > > > > > > > >

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [October 31, 2017, 4:18pm UTC](https://forum.search-guard.com/t/kibana-boom-error-after-install-search-guard/650/16 "2017-10-31T16:18:39Z")

</div>

This seems to be an Elastic/Kibana issue, not a Search Guard issue:

> <https://github.com/elastic/kibana/issues/14021>
>
> \<!--
> GitHub is reserved for bug reports and feature requests. The best place
> t…o ask a general question is at the Elastic Discourse forums at
> https://discuss.elastic.co. If you are in fact posting a bug report or
> a feature request, please include one and only one of the below blocks
> in your new issue.
> \--\>
> 
> \<!--
> If you are filing a bug report, please remove the below feature
> request block and provide responses for all of the below items.
> \--\>
> 
> \*\*Kibana version\*\*:
> 5.6.0
> 
> \*\*Elasticsearch version\*\*:
> 5.6.0
> 
> \*\*Server OS version\*\*:
> fedora 25
> 
> \*\*Browser version\*\*:
> chrome 60
> 
> \*\*Browser OS version\*\*:
> 
> \*\*Original install method (e.g. download page, yum, from source, etc.)\*\*:
> dnf/yum
> 
> \*\*Description of the problem including expected versus actual behavior\*\*:
> Since I moved to 5.6.0, I can not create indices in kibana setting page nor refresh them.
> 
> When I try, I get this error:
> {"type":"error","@timestamp":"2017-09-17T08:40:06Z","tags":\[\],"pid":27860,"level":"error","message":"Cannot provide statusCode or message with boom error","error":{"message":"Cannot provide statusCode or message with boom error","name":"Error","stack":"Error: Cannot provide statusCode or message with boom error\\n at Object.exports.assert (/usr/share/kibana/node\_modules/hoek/lib/index.js:736:11)\\n at Object.exports.wrap (/usr/share/kibana/node\_modules/boom/lib/index.js:96:10)\\n at convertEsError (/usr/share/kibana/src/server/index\_patterns/service/lib/errors.js:67:25)\\n at /usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:63:40\\n at throw (native)\\n at step (/usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:74:191)\\n at /usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:74:402"},"url":{"protocol":null,"slashes":null,"auth":null,"host":null,"port":null,"hostname":null,"hash":null,"search":"?pattern=myindex-\*&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D","query":{"pattern":"myindex-\*","meta\_fields":"\[\\"\_source\\",\\"\_id\\",\\"\_type\\",\\"\_index\\",\\"\_score\\"\]"},"pathname":"/api/index\_patterns/\_fields\_for\_wildcard","path":"/api/index\_patterns/\_fields\_for\_wildcard?pattern=myindex-\*&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D","href":"/api/index\_patterns/\_fields\_for\_wildcard?pattern=myindex-\*&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D"}}
> 
> I tried to see debug logs, but it does not get anything special.
> 
> Another thing I did is:
> https://discuss.elastic.co/t/upgrade-issue-with-elastic-stack-5-6-0-workaround-option-until-fix-is-available/100595
> 
> to make kibana work in 5.6.0
> 
> \*\*Steps to reproduce\*\*:
> 1. Create kibana and elastic 5.5.0
> 2. Upgrade to 5.6.0
> 3. Use the script to fix the kibana indices
> 4. Try to add new index or refresh an index.
> 
> \*\*Errors in browser console (if relevant)\*\*:
> non
> 
> \*\*Provide logs and/or server output (if relevant)\*\*:
> {"type":"error","@timestamp":"2017-09-17T08:40:06Z","tags":\[\],"pid":27860,"level":"error","message":"Cannot provide statusCode or message with boom error","error":{"message":"Cannot provide statusCode or message with boom error","name":"Error","stack":"Error: Cannot provide statusCode or message with boom error\\n at Object.exports.assert (/usr/share/kibana/node\_modules/hoek/lib/index.js:736:11)\\n at Object.exports.wrap (/usr/share/kibana/node\_modules/boom/lib/index.js:96:10)\\n at convertEsError (/usr/share/kibana/src/server/index\_patterns/service/lib/errors.js:67:25)\\n at /usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:63:40\\n at throw (native)\\n at step (/usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:74:191)\\n at /usr/share/kibana/src/server/index\_patterns/service/lib/es\_api.js:74:402"},"url":{"protocol":null,"slashes":null,"auth":null,"host":null,"port":null,"hostname":null,"hash":null,"search":"?pattern=myindex-\*&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D","query":{"pattern":"myindex-\*","meta\_fields":"\[\\"\_source\\",\\"\_id\\",\\"\_type\\",\\"\_index\\",\\"\_score\\"\]"},"pathname":"/api/index\_patterns/\_fields\_for\_wildcard","path":"/api/index\_patterns/\_fields\_for\_wildcard?pattern=myindex-\*&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D","href":"/api/index\_patterns/\_fields\_for\_wildcard?pattern=myindex-\*&meta\_fields=%5B%22\_source%22%2C%22\_id%22%2C%22\_type%22%2C%22\_index%22%2C%22\_score%22%5D"}}
> 
> 
> Thanks!

> **···**
>
> On Thursday, October 26, 2017 at 2:23:33 PM UTC+2, Sergey Emcev wrote:
> 
> > All components upgraded from 5.6.2 to 5.6.3
> > 
> > четверг, 26 октября 2017 г., 12:06:35 UTC+3 пользователь Jochen Kressin написал:
> > 
> > > I’d really like to understand the magic here 😉 because clearly, something was going on with your setup. We’ve tried to replicate the issue yesterday with the versions and configs you provided, but were not able to.
> 
> > > So, can you please share what exactly you did / upgraded / to which version? Because so far all our Kerberos integration tests are working fine ootb and we want to make sure there’s no real issue in SG itself.
> 
> > > Thanks!
> > > 
> > > On Wednesday, October 25, 2017 at 4:08:29 PM UTC+2, Sergey Emcev wrote:
> > > 
> > > > Well, after update elasticsearch, kibana, logstah and search-guard plugin for elasticsearch and kibana … it works !  
> > > > I did not do anything else
> 
> > > > Magic …
> > > > 
> > > > вторник, 24 октября 2017 г., 12:32:43 UTC+3 пользователь Sergey Emcev написал:
> > > > 
> > > > > Ok, remove sentinl.
> 
> > > > > The problem not solve.
> > > > > 
> > > > > понедельник, 23 октября 2017 г., 20:21:58 UTC+3 пользователь Jochen Kressin написал:
> > > > > 
> > > > > > Ok, the configs seem valid, we’ll need to investigate this. Just a last check - please verify that this error also occurs when Sentinl is not installed (means, please remove it from plugins folder, don’t just disable it in kibana.yml)
> > > > > > 
> > > > > > On Monday, October 23, 2017 at 4:29:37 PM UTC+2, Sergey Emcev wrote:
> > > > > > 
> > > > > > > Attached screenshot directly connect to es via kerberos and sg\_config  
> > > > > > > In sg\_roles\_mapping i add my account to group sg\_all\_access
> 
> > > > > > >
> 
> > > > > > >
> 
> > > > > > > понедельник, 23 октября 2017 г., 17:15:01 UTC+3 пользователь Jochen Kressin написал:
> > > > > > > 
> > > > > > > > So please check first if you can access ES directly with Kerberos, not via Kibana. I want to first make sure basic Kerberos auth is working. Please also post the Search Guard configuraton files.
> 
> > > > > > > > On Monday, October 23, 2017 at 4:11:01 PM UTC+2, Sergey Emcev wrote:
> > > > > > > > 
> > > > > > > > > We use kerberos and no need basic authentication.
> > > > > > > > > 
> > > > > > > > > понедельник, 23 октября 2017 г., 16:59:23 UTC+3 пользователь Jochen Kressin написал:
> > > > > > > > > 
> > > > > > > > > > You have set basic authentication to false in kibana.yml:
> 
> > > > > > > > > > searchguard.basicauth.enabled: false
> 
> > > > > > > > > > Which means the login dialogue is not displayed and no user credentials are passed from Kibana to Elasticsearch. If you want to use HTTP Basic Authentication, then you need this parameter set to true. From the logfiles, I can see that you have an HTTP Basic Authenticator enabled in sg\_config, so I’m assuming that’s what you want to use. If you intend to use some SSO auth, like JWT or Proxy, let me know.
> 
> > > > > > > > > >
> 
> > > > > > > > > >
> 
> > > > > > > > > > >
