# Basic authentication only for OpenSearch Dashboards

**URL:** <https://forum.opensearch.org/t/basic-authentication-only-for-opensearch-dashboards/12612>\
**Category:** Security\
**Tags:** configure, install, security-issue\
**Created:** [February 23, 2023, 9:25am UTC](https://forum.opensearch.org/t/basic-authentication-only-for-opensearch-dashboards/12612 "2023-02-23T09:25:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![opensearchgenius](https://avatars.discourse-cdn.com/v4/letter/o/2bfe46/32.png) [@opensearchgenius](https://forum.opensearch.org/u/opensearchgenius)\
**Post date:** [February 23, 2023, 9:25am UTC](https://forum.opensearch.org/t/basic-authentication-only-for-opensearch-dashboards/12612/1 "2023-02-23T09:25:31Z")

</div>

Hi Opensearch enjoyers,

Would be possible to configure authentication with login/password only for Dashboards GUI and not for Opensearch itself ?

We trying to avoid a lot of reconfiguring ( meaning add login, password and trusted cert) all apps which are sending logs, metrics and traces to our Opensearch cluster, but it seems like it’s not possible because internal users are under control of security\_admin.sh and/or security plugin which requires https and auth enabled on Opensearch. Is there some way how to do it ?

Our OpenSearch stack is behind corporate proxy and is not accessible from outside.  
We are using OpenSearch and Dashboards both in version 2.1.0.

Thank you for all meaningful comments.

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)\
**Post date:** [February 24, 2023, 2:02pm UTC](https://forum.opensearch.org/t/basic-authentication-only-for-opensearch-dashboards/12612/2 "2023-02-24T14:02:11Z")

</div>

Hi @opensearchgenius

What exactly do you want to achieve? How do you want to connect external apps to the OpenSearch cluster?

---

<div class="post-metadata">

**Author:** ![opensearchgenius](https://avatars.discourse-cdn.com/v4/letter/o/2bfe46/32.png) [@opensearchgenius](https://forum.opensearch.org/u/opensearchgenius)\
**Post date:** [February 24, 2023, 2:21pm UTC](https://forum.opensearch.org/t/basic-authentication-only-for-opensearch-dashboards/12612/3 "2023-02-24T14:21:12Z")

</div>

Hey,

Well, simply , we want to achieve that not all user or people in company can see all data/dashboards/logs in Opensearch.

All external apps are already connected to OpenSearch cluster on port 9200. We use different external apps such as: Otell collector + Data Prepepr, Logstash, Fluentbit and Fluentd because there are lot of things in our environment which need to store logs.

Thats why we want to avoid configure all of them to and avoid to set authentication to Opensearch on port 9200.

Hope I explain our problem

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)\
**Post date:** [February 24, 2023, 7:37pm UTC](https://forum.opensearch.org/t/basic-authentication-only-for-opensearch-dashboards/12612/4 "2023-02-24T19:37:11Z")

</div>

@opensearchgenius Have you tried anonymous authentication? If not, please use the below procedure to enable it.

1. Set “anonymous\_auth\_enabled” to true in **config.yml**  
 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/5/5c49a55764dad3b019089bbe0ae66548b55cb90c.png)

2. Add the below line to **opensearch\_dashboards.yml**

```auto
opensearch_security.auth.anonymous_auth_enabled: true

```

1. In **roles.yml** set the following role. (The permissions are just an example.)

```auto
opendistro_security_anonymous:
  cluster_permissions:
  - "unlimited"
  index_permissions:
  - index_patterns:
    - "*"
    allowed_actions:
    - "unlimited"
  tenant_permissions:
  - tenant_patterns:
    - "global_tenant"
    allowed_actions:
    - "kibana_all_write"

```

1. In **roles\_mapping.yml** configure the mapping of the anonymous backend role

```auto
opendistro_security_anonymous:
  backend_roles:
  - "opendistro_security_anonymous_backendrole"

```

Please remember to apply security plugin configuration changes with securityadmin.sh script.

You can also disable SSL on port 9200. To do so, add the following configuration to **opensearch.yml** file:

```auto
plugins.security.ssl.http.enabled: false

```

---

<div class="post-metadata">

**Author:** ![opensearchgenius](https://avatars.discourse-cdn.com/v4/letter/o/2bfe46/32.png) [@opensearchgenius](https://forum.opensearch.org/u/opensearchgenius)\
**Post date:** [February 27, 2023, 9:43am UTC](https://forum.opensearch.org/t/basic-authentication-only-for-opensearch-dashboards/12612/5 "2023-02-27T09:43:08Z")

</div>

Hey @Eugene7

Yes, we already tried it, here is screenshot of error we got after i run securityadmin.sh:

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/6/63d2b779f7c148d79447ac05447cd6334be62542.png)

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)\
**Post date:** [March 1, 2023, 11:11am UTC](https://forum.opensearch.org/t/basic-authentication-only-for-opensearch-dashboards/12612/6 "2023-03-01T11:11:06Z")

</div>

The error is caused by disabling SSL in HTTP 9200. Starting from version 2.0, the securityadmin.sh connects to OpenSearch through port 9200 (it was 9300 in versions 1.x). securityadmin.sh requires certificate authentication, which forces SSL on the API endpoint 9200.
