# Kibana server with client certificate auth only

**URL:** <https://forum.search-guard.com/t/kibana-server-with-client-certificate-auth-only/1788>\
**Category:** Search Guard\
**Created:** [April 2, 2020, 3:34pm UTC](https://forum.search-guard.com/t/kibana-server-with-client-certificate-auth-only/1788 "2020-04-02T15:34:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![faxmodem](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/faxmodem/32/22_2.png) [@faxmodem](https://forum.search-guard.com/u/faxmodem)\
**Post date:** [April 2, 2020, 3:34pm UTC](https://forum.search-guard.com/t/kibana-server-with-client-certificate-auth-only/1788/1 "2020-04-02T15:34:15Z")

</div>

Hi,

I’m setting up a fresh new cluster with latest ES/SG.  
I’d like kibana to auth using clientcert.  
I thus set up `kibana.yml` like this:

```auto
#NO elasticsearch.username: kibana
elasticsearch.ssl.certificate: /etc/kibana/ssl/Kibana User.crt
elasticsearch.ssl.key: /etc/kibana/ssl/Kibana User.key

```

The subject of that client cert is `CN=Kibana User`

And I’ve added the following permissions in `sg_roles_mapping.yml`:

```auto
SGS_KIBANA_SERVER:
  users:
    - CN=Kibana User

```

However, this doesn’t need to suffice for kibana to start:

```auto
kibana[2073]: {"type":"log","@timestamp":"2020-04-02T13:36:59Z","tags":["warning","migrations"],"pid":2073,"message":"Unable to connect to Elasticsearch. Error: [security_exception] no permissions for [indices:admin/get] and User [name=CN=Kibana User, backend_roles=[], requestedTenant=null]"}

```

When I add the `SGS_KIBANA_USER` role to the user, kibana is happy.

Did I miss something?

---

<div class="post-metadata">

**Author:** ![srgbnd](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/srgbnd/32/506_2.png) [@srgbnd](https://forum.search-guard.com/u/srgbnd)\
**Post date:** [April 8, 2020, 8:44am UTC](https://forum.search-guard.com/t/kibana-server-with-client-certificate-auth-only/1788/2 "2020-04-08T08:44:09Z")

</div>

You configured the user correctly.

All Kibana users must be mapped to the built-in `SGS_KIBANA_USER` role. This role has the minimum permissions to access Kibana.

**In addition,** the users need to have READ permissions to all indices they should be allowed to use with Kibana. Typically you will want to set up different roles for different users, and give them the `SGS_KIBANA_USER` role in additions.

> **[Installing the Plugin](https://docs.search-guard.com/latest/kibana-plugin-installation#configuring-elasticsearch-adding-kibana-users)**
>
> How to install the Search Guard Kibana plugin which adds authentication, multi-tenancy and the configuration UI.

---

<div class="post-metadata">

**Author:** ![faxmodem](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/faxmodem/32/22_2.png) [@faxmodem](https://forum.search-guard.com/u/faxmodem)\
**Post date:** [April 8, 2020, 1:49pm UTC](https://forum.search-guard.com/t/kibana-server-with-client-certificate-auth-only/1788/3 "2020-04-08T13:49:30Z")

</div>

I’m sorry I didn’t make myself clear.  
I was trying to set up the kibana server user: the one used internally by kibana.  
It seems this is only possible through basic auth, and not like I was trying to do through clientcert.  
Can you confirm that?

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/system/32/1870_2.png) [@system](https://forum.search-guard.com/u/system)\
**Post date:** [April 29, 2020, 1:49pm UTC](https://forum.search-guard.com/t/kibana-server-with-client-certificate-auth-only/1788/4 "2020-04-29T13:49:32Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
