# Mapping new user to kibana\_server

**URL:** <https://forum.opensearch.org/t/mapping-new-user-to-kibana-server/6694>\
**Category:** Security\
**Created:** [August 4, 2021, 10:45am UTC](https://forum.opensearch.org/t/mapping-new-user-to-kibana-server/6694 "2021-08-04T10:45:01Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![silver\_searcher](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@silver\_searcher](https://forum.opensearch.org/u/silver_searcher)\
**Post date:** [August 4, 2021, 10:45am UTC](https://forum.opensearch.org/t/mapping-new-user-to-kibana-server/6694/1 "2021-08-04T10:45:01Z")

</div>

Hi,

I’m trying to map new user to built-in `kibana_server` role (instead of using `kibanaserver` user). But the permissions don’t seem to be mapping. Is this not allowed? Can you please help check if I’m missing something?

internal\_users.yml

```auto
dashboardserver:
  reserved: true
  hash: "xxx"
  description: "Login for Opensearch-Dashboards"

```

roles\_mapping.yml

```auto
kibana_server:
  reserved: true
  users:
  - "dashboardserver"

```

Error in opensearch.log

> [2021-08-04T03:42:39,669][INFO][audit] [my.internal.url] {“audit\_cluster\_name”:“my-internal-url”,“audit\_node\_name”:“my.internal.url”,“audit\_trace\_task\_id”:“yQO73t8nR6eCkXMXteibbA:267357”,“audit\_transport\_request\_type”:“GetIndexRequest”,“audit\_category”:“MISSING\_PRIVILEGES”,“audit\_request\_origin”:“REST”,“audit\_node\_id”:“yQO73t8nR6eCkXMXteibbA”,“audit\_request\_layer”:“TRANSPORT”,“@timestamp”:“2021-08-04T10:42:39.668+00:00”,“audit\_format\_version”:4,“audit\_request\_remote\_address”:“1.2.3.4”,“audit\_request\_privilege”:“indices:admin/get”,“audit\_node\_host\_address”:“1.2.3.4”,“audit\_request\_effective\_user”:“dashboardserver”,“audit\_trace\_indices”:[“.kibana”],“audit\_trace\_resolved\_indices”:[“.kibana\_1”],“audit\_node\_host\_name”:“1.2.3.4”}

Appreciate your help.

---

<div class="post-metadata">

**Author:** ![spapadop](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/spapadop/32/950_2.png) [@spapadop](https://forum.opensearch.org/u/spapadop)\
**Post date:** [August 4, 2021, 11:16am UTC](https://forum.opensearch.org/t/mapping-new-user-to-kibana-server/6694/2 "2021-08-04T11:16:10Z")

</div>

Hello,

Can you please double-check if `dashboardserver` is indeed mapped to the `kibana_server` role?

```auto
GET _opendistro/_security/api/rolesmapping/kibana_server

```

---

<div class="post-metadata">

**Author:** ![silver\_searcher](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@silver\_searcher](https://forum.opensearch.org/u/silver_searcher)\
**Post date:** [August 4, 2021, 11:43am UTC](https://forum.opensearch.org/t/mapping-new-user-to-kibana-server/6694/3 "2021-08-04T11:43:42Z")

</div>

@spapadop  
Here’s the output. I think it looks ok?

> `{"kibana_server":{"hosts":[],"users":["dashboardserver"],"reserved":true,"hidden":false,"backend_roles":[],"and_backend_roles":[]}}`

I’m using OpenSearch and Dashboards 1.0.0, btw. with the corresponding plugins in security.

---

<div class="post-metadata">

**Author:** ![silver\_searcher](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@silver\_searcher](https://forum.opensearch.org/u/silver_searcher)\
**Post date:** [August 7, 2021, 12:55am UTC](https://forum.opensearch.org/t/mapping-new-user-to-kibana-server/6694/4 "2021-08-07T00:55:28Z")

</div>

@spapadop just kindly following up, would you have some idea on what might be wrong or missing?

---

<div class="post-metadata">

**Author:** ![spapadop](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/spapadop/32/950_2.png) [@spapadop](https://forum.opensearch.org/u/spapadop)\
**Post date:** [August 9, 2021, 10:33am UTC](https://forum.opensearch.org/t/mapping-new-user-to-kibana-server/6694/5 "2021-08-09T10:33:57Z")

</div>

Apologies I can’t think of anything else. Maybe you still need to give permissions to all tenants for user `dashboardserver`.  
@pablo or @Anthony may have some better ideas.

---

<div class="post-metadata">

**Author:** ![Anthony](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/anthony/32/9939_2.png) [@Anthony](https://forum.opensearch.org/u/Anthony)\
**Post date:** [December 9, 2021, 5:05pm UTC](https://forum.opensearch.org/t/mapping-new-user-to-kibana-server/6694/7 "2021-12-09T17:05:21Z")

</div>

For anyone looking at this ticket, ensure the username that is set up in elasticsearch.yml file under: `elasticsearch.username: username` matches the entry in config.yml under:

```auto
kibana:
    # Kibana multitenancy
      multitenancy_enabled: true
      server_username: username
      index: '.kibana'

```

---

<div class="post-metadata">

**Author:** ![Wasabi](https://avatars.discourse-cdn.com/v4/letter/w/c5a1d2/32.png) [@Wasabi](https://forum.opensearch.org/u/Wasabi)\
**Post date:** [October 6, 2024, 7:26pm UTC](https://forum.opensearch.org/t/mapping-new-user-to-kibana-server/6694/8 "2024-10-06T19:26:28Z")

</div>

Just to make this even more clear, it took me a while and various forum threads including this one and [also this one](https://forum.opensearch.org/t/opensearch-dashboards-cannot-connect-to-opensearch/13343/5) to figure out what’s going on.

**This is only needed if you want to change the open search dashboards username from `kibanaserver` to something else**.

Assuming you’ve setup authentication (method doesn’t matter, can be basic auth or client cert) correctly, and the user itself works, there are two things that need to be done:

1. Assign proper permissions
2. Change the Dashboards Username in Opensearch (!) settings

For 1, it is usually sufficient to use the built-in `kibana_server` role. In my case, a role\_mapping such as the following is sufficient:

```auto
kibana_server:
      reserved: true
      users:
        - 'CN=xyz,OU=xxx,O=xxx'

```

The second one, and that’s probably what most people forget, and what @Anthony mentioned above - you need to change the single username that is used for Kibana / Opensearch Dashboards in **opensearch-security config.yml** :

```auto
config:
  dynamic:
    kibana:
      server_username: 'CN=xyz,OU=xxx,O=xxx'
    authc:
      ... your settings

```
