# OpenSearch Security Not Initialized Error on OpenSearch Dashboard

**URL:** https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797
**Category:** Security
**Tags:** configure
**Created:** [December 13, 2024, 4:44pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797 "2024-12-13T16:44:18Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![gcavazzana](https://avatars.discourse-cdn.com/v4/letter/g/a87d85/32.png) [@gcavazzana](https://forum.opensearch.org/u/gcavazzana)
#### Post date: [December 13, 2024, 4:44pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797/1 "2024-12-13T16:44:18Z")

</div>

Hello,

I’m experiencing an issue when trying to access the OpenSearch Dashboard in Chrome. I get the following error:  
**“OpenSearch Security not initialized.”**

To troubleshoot, I tried running `securityadmin.sh` and passing the demo certificates, but it failed. I believe this might be because I am not using SSL, and it’s currently disabled in my `opensearch.yml`.

The problem started after I attempted to change the password for the `admin` and `kibanaserver` users using the following command:

```auto
cd /usr/share/opensearch/plugins/opensearch-security/tools
OPENSEARCH_JAVA_HOME=/usr/share/opensearch/jdk ./securityadmin.sh -h <my-ip> -p 9200 -cd /etc/opensearch/opensearch-security/ -cacert /etc/opensearch/certs/root-ca.pem -cert /
etc/opensearch/certs/admin.pem -key /etc/opensearch/certs/admin-key.pem -icl -nhnv

```

How can I resolve this issue and make the dashboard work again?

Here are the details of my setup:

- OpenSearch version: 2.11.1
- 1 coordinator node
- 1 manager node
- 2 database nodes
- Content of my `opensearch.yml` file on coordinator node:

```auto
# ======================== OpenSearch Configuration =========================
#
# NOTE: OpenSearch comes with reasonable defaults for most settings.
# Before you set out to tweak and tune the configuration, make sure you
# understand what are you trying to accomplish and the consequences.
#
# The primary way of configuring a node is via this file. This template lists
# the most important settings you may want to configure for a production cluster.
#
# Please consult the documentation for further information on configuration options:
# https://www.opensearch.org
#
# ---------------------------------- Cluster -----------------------------------
#
# Use a descriptive name for your cluster:
#
cluster.name: hmsc-opensearch
#
# ------------------------------------ Node ------------------------------------
#
# Use a descriptive name for the node:
#
node.name: coordinator-node
#
# Add custom attributes to the node:
#
#node.attr.rack: r1
node.roles: []

#
# ----------------------------------- Paths ------------------------------------
#
# Path to directory where to store the data (separate multiple locations by comma):
#
path.data: /var/lib/opensearch
#
# Path to log files:
#
path.logs: /var/log/opensearch
#
# ----------------------------------- Memory -----------------------------------
#
# Lock the memory on startup:
#
#bootstrap.memory_lock: true
#
# Make sure that the heap size is set to about half the memory available
# on the system and that the owner of the process is allowed to use this
# limit.
#
# OpenSearch performs poorly when the system is swapping the memory.
#
# ---------------------------------- Network -----------------------------------
#
# Set the bind address to a specific IP (IPv4 or IPv6):
#
network.host: <my-ip>
#
# Set a custom port for HTTP:
#
http.port: 9200
#
# For more information, consult the network module documentation.
#network.publish_host:
network.publish_host: srvmusad01
#
# --------------------------------- Discovery ----------------------------------
#
# Pass an initial list of hosts to perform discovery when this node is started:
# The default list of hosts is ["127.0.0.1", "[::1]"]
discovery.seed_hosts: ["srvmusad02", "srvmusad03", "srvmussad04"]
#
#discovery.seed_hosts: []
#
# Bootstrap the cluster using an initial set of cluster-manager-eligible nodes:
#
cluster.initial_cluster_manager_nodes: ["<my-ip-manager>"]
#
# For more information, consult the discovery and cluster formation module documentation.
#
# ---------------------------------- Gateway -----------------------------------
#
# Block initial recovery after a full cluster restart until N nodes are started:
#
#gateway.recover_after_nodes: 3
#
# For more information, consult the gateway module documentation.
#
# ---------------------------------- Various -----------------------------------
#
# Require explicit names when deleting indices:
#
action.destructive_requires_name: true
#
# ---------------------------------- Remote Store -----------------------------------
# Controls whether cluster imposes index creation only with remote store enabled
# cluster.remote_store.enabled: true
#
# Repository to use for segment upload while enforcing remote store for an index
# node.attr.remote_store.segment.repository: my-repo-1
#
# Repository to use for translog upload while enforcing remote store for an index
# node.attr.remote_store.translog.repository: my-repo-1
#
# ---------------------------------- Experimental Features -----------------------------------
# Gates the visibility of the experimental segment replication features until they are production ready.
#
#opensearch.experimental.feature.segment_replication_experimental.enabled: false
#
# Gates the functionality of a new parameter to the snapshot restore API
# that allows for creation of a new index type that searches a snapshot
# directly in a remote repository without restoring all index data to disk
# ahead of time.
#
#opensearch.experimental.feature.searchable_snapshot.enabled: false
#
#
# Gates the functionality of enabling extensions to work with OpenSearch.
# This feature enables applications to extend features of OpenSearch outside of
# the core.
#
#opensearch.experimental.feature.extensions.enabled: false
#
#
# Gates the concurrent segment search feature. This feature enables concurrent segment search in a separate
# index searcher threadpool.
#
#opensearch.experimental.feature.concurrent_segment_search.enabled: false

######## Start OpenSearch Security Demo Configuration ########
# WARNING: revise all the lines below before you go into production
plugins.security.ssl.transport.pemcert_filepath: esnode.pem
plugins.security.ssl.transport.pemkey_filepath: esnode-key.pem
plugins.security.ssl.transport.pemtrustedcas_filepath: root-ca.pem
plugins.security.ssl.transport.enforce_hostname_verification: false
plugins.security.ssl.http.enabled: false
plugins.security.ssl.http.pemcert_filepath: esnode.pem
plugins.security.ssl.http.pemkey_filepath: esnode-key.pem
plugins.security.ssl.http.pemtrustedcas_filepath: root-ca.pem
plugins.security.allow_unsafe_democertificates: true
plugins.security.allow_default_init_securityindex: true
plugins.security.authcz.admin_dn:
  - CN=kirk,OU=client,O=client,L=test, C=de

plugins.security.audit.type: internal_opensearch
plugins.security.enable_snapshot_restore_privilege: true
plugins.security.check_snapshot_restore_write_privileges: true
plugins.security.restapi.roles_enabled: ["all_access", "security_rest_api_access"]
plugins.security.system_indices.enabled: true
plugins.security.system_indices.indices: [".plugins-ml-config", ".plugins-ml-connector", ".plugins-ml-model-group", ".plugins-ml-model", ".plugins-ml-task", ".plugins-ml-conversation-meta", ".plugins-ml-conversation-interactions", ".opendistro-alerting-config", ".opendistro-alerting-alert*", ".opendistro-anomaly-results*", ".opendistro-anomaly-detector*", ".opendistro-anomaly-checkpoints", ".opendistro-anomaly-detection-state", ".opendistro-reports-*", ".opensearch-notifications-*", ".opensearch-notebooks", ".opensearch-observability", ".ql-datasources", ".opendistro-asynchronous-search-response*", ".replication-metadata-store", ".opensearch-knn-models", ".geospatial-ip2geo-data*"]
node.max_local_storage_nodes: 3

#plugins.security.disabled: true

######## End OpenSearch Security Demo Configuration ########

```

---

<div class="post-metadata">

### Author: ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)
#### Post date: [December 13, 2024, 6:01pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797/2 "2024-12-13T18:01:58Z")

</div>

Hi @gcavazzana,

Could you please share the `opensearch_dashboards.yml` file? Also, have you updated the `kibanaserver` user’s password in the `opensearch_dashboards.yml` file after changing the `kibanaserver` user’s password?

---

<div class="post-metadata">

### Author: ![gcavazzana](https://avatars.discourse-cdn.com/v4/letter/g/a87d85/32.png) [@gcavazzana](https://forum.opensearch.org/u/gcavazzana)
#### Post date: [December 13, 2024, 6:07pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797/3 "2024-12-13T18:07:17Z")

</div>

Hi @Eugene7

Thanks for your attention

This is my `opensearch_dashboards.yml` file:

```auto

---
# Copyright OpenSearch Contributors
# SPDX-License-Identifier: Apache-2.0

# Description:
# Default configuration for OpenSearch Dashboards

# OpenSearch Dashboards is served by a back end server. This setting specifies the port to use.
server.port: 5601

# Specifies the address to which the OpenSearch Dashboards server will bind. IP addresses and host names are both valid values.
# The default is 'localhost', which usually means remote machines will not be able to connect.
# To allow connections from remote users, set this parameter to a non-loopback address.
server.host: "<my-ip>"

# Enables you to specify a path to mount OpenSearch Dashboards at if you are running behind a proxy.
# Use the `server.rewriteBasePath` setting to tell OpenSearch Dashboards if it should remove the basePath
# from requests it receives, and to prevent a deprecation warning at startup.
# This setting cannot end in a slash.
# server.basePath: ""

# Specifies whether OpenSearch Dashboards should rewrite requests that are prefixed with
# `server.basePath` or require that they are rewritten by your reverse proxy.
# server.rewriteBasePath: false

# The maximum payload size in bytes for incoming server requests.
# server.maxPayloadBytes: 1048576

# The OpenSearch Dashboards server's name. This is used for display purposes.
server.name: "srvmusad01"

# The URLs of the OpenSearch instances to use for all your queries.
opensearch.hosts: ["http://srvmusad01:9200"]

# OpenSearch Dashboards uses an index in OpenSearch to store saved searches, visualizations and
# dashboards. OpenSearch Dashboards creates a new index if the index doesn't already exist.
# opensearchDashboards.index: ".opensearch_dashboards"

# The default application to load.
# opensearchDashboards.defaultAppId: "home"

# Setting for an optimized healthcheck that only uses the local OpenSearch node to do Dashboards healthcheck.
# This settings should be used for large clusters or for clusters with ingest heavy nodes.
# It allows Dashboards to only healthcheck using the local OpenSearch node rather than fan out requests across all nodes.
#
# It requires the user to create an OpenSearch node attribute with the same name as the value used in the setting
# This node attribute should assign all nodes of the same cluster an integer value that increments with each new cluster that is spun up
# e.g. in opensearch.yml file you would set the value to a setting using node.attr.cluster_id:
# Should only be enabled if there is a corresponding node attribute created in your OpenSearch config that matches the value here
# opensearch.optimizedHealthcheckId: "cluster_id"

# If your OpenSearch is protected with basic authentication, these settings provide
# the username and password that the OpenSearch Dashboards server uses to perform maintenance on the OpenSearch Dashboards
# index at startup. Your OpenSearch Dashboards users still need to authenticate with OpenSearch, which
# is proxied through the OpenSearch Dashboards server.
#opensearch.username: "kibanaserver"
#opensearch.password: "kibanaserver"

# Enables SSL and paths to the PEM-format SSL certificate and SSL key files, respectively.
# These settings enable SSL for outgoing requests from the OpenSearch Dashboards server to the browser.
# server.ssl.enabled: false
# server.ssl.certificate: /path/to/your/server.crt
# server.ssl.key: /path/to/your/server.key

# Optional settings that provide the paths to the PEM-format SSL certificate and key files.
# These files are used to verify the identity of OpenSearch Dashboards to OpenSearch and are required when
# xpack.security.http.ssl.client_authentication in OpenSearch is set to required.
# opensearch.ssl.certificate: /path/to/your/client.crt
# opensearch.ssl.key: /path/to/your/client.key

# Optional setting that enables you to specify a path to the PEM file for the certificate
# authority for your OpenSearch instance.
# opensearch.ssl.certificateAuthorities: ["/path/to/your/CA.pem"]

# To disregard the validity of SSL certificates, change this setting's value to 'none'.
# opensearch.ssl.verificationMode: full

# Time in milliseconds to wait for OpenSearch to respond to pings. Defaults to the value of
# the opensearch.requestTimeout setting.
# opensearch.pingTimeout: 1500

# Time in milliseconds to wait for responses from the back end or OpenSearch. This value
# must be a positive integer.
# opensearch.requestTimeout: 30000

# List of OpenSearch Dashboards client-side headers to send to OpenSearch. To send *no* client-side
# headers, set this value to [] (an empty list).
# opensearch.requestHeadersWhitelist: [authorization]

# Header names and values that are sent to OpenSearch. Any custom headers cannot be overwritten
# by client-side headers, regardless of the opensearch.requestHeadersWhitelist configuration.
# opensearch.customHeaders: {}

# Time in milliseconds for OpenSearch to wait for responses from shards. Set to 0 to disable.
# opensearch.shardTimeout: 30000

# Logs queries sent to OpenSearch. Requires logging.verbose set to true.
# opensearch.logQueries: false

# Specifies the path where OpenSearch Dashboards creates the process ID file.
# pid.file: /var/run/opensearchDashboards.pid

# Enables you to specify a file where OpenSearch Dashboards stores log output.
# logging.dest: stdout

# 2.15 Ignore 'ENOSPC' error for logging stream.
# When set to true, the 'ENOSPC' error message will not cause the OpenSearch Dashboards process to crash. Otherwise,
# the original behavior will be maintained. It is disabled by default.
# logging.ignoreEnospcError: false

# Set the value of this setting to true to suppress all logging output.
# logging.silent: false

# Set the value of this setting to true to suppress all logging output other than error messages.
# logging.quiet: false

# Set the value of this setting to true to log all events, including system usage information
# and all requests.
# logging.verbose: false

# Set the interval in milliseconds to sample system and process performance
# metrics. Minimum is 100ms. Defaults to 5000.
# ops.interval: 5000

# Specifies locale to be used for all localizable strings, dates and number formats.
# Supported languages are the following: English - en , by default , Chinese - zh-CN .
# i18n.locale: "en"

# Set the allowlist to check input graphite Url. Allowlist is the default check list.
# vis_type_timeline.graphiteAllowedUrls: ['https://www.hostedgraphite.com/UID/ACCESS_KEY/graphite']

# Set the blocklist to check input graphite Url. Blocklist is an IP list.
# Below is an example for reference
# vis_type_timeline.graphiteBlockedIPs: [
# //Loopback
# '127.0.0.0/8',
# '::1/128',
# //Link-local Address for IPv6
# 'fe80::/10',
# //Private IP address for IPv4
# '10.0.0.0/8',
# '172.16.0.0/12',
# '192.168.0.0/16',
# //Unique local address (ULA)
# 'fc00::/7',
# //Reserved IP address
# '0.0.0.0/8',
# '100.64.0.0/10',
# '192.0.0.0/24',
# '192.0.2.0/24',
# '198.18.0.0/15',
# '192.88.99.0/24',
# '198.51.100.0/24',
# '203.0.113.0/24',
# '224.0.0.0/4',
# '240.0.0.0/4',
# '255.255.255.255/32',
# '::/128',
# '2001:db8::/32',
# 'ff00::/8',
# ]
# vis_type_timeline.graphiteBlockedIPs: []

# opensearchDashboards.branding:
# logo:
# defaultUrl: ""
# darkModeUrl: ""
# mark:
# defaultUrl: ""
# darkModeUrl: ""
# loadingLogo:
# defaultUrl: ""
# darkModeUrl: ""
# faviconUrl: ""
# applicationTitle: ""

# Set the value of this setting to true to capture region blocked warnings and errors
# for your map rendering services.
# map.showRegionBlockedWarning: false%

# Set the value of this setting to false to suppress search usage telemetry
# for reducing the load of OpenSearch cluster.
# data.search.usageTelemetry.enabled: false

# 2.4 renames 'wizard.enabled: false' to 'vis_builder.enabled: false'
# Set the value of this setting to false to disable VisBuilder
# functionality in Visualization.
# vis_builder.enabled: false

# 2.4 New Experimental Feature
# Set the value of this setting to true to enable the experimental multiple data source
# support feature. Use with caution.
# data_source.enabled: false
# Set the value of these settings to customize crypto materials to encryption saved credentials
# in data sources.
# data_source.encryption.wrappingKeyName: 'changeme'
# data_source.encryption.wrappingKeyNamespace: 'changeme'
# data_source.encryption.wrappingKey: [0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]

# 2.6 New ML Commons Dashboards Feature
# Set the value of this setting to true to enable the ml commons dashboards
# ml_commons_dashboards.enabled: false

# 2.12 New experimental Assistant Dashboards Feature
# Set the value of this setting to true to enable the assistant dashboards
# assistant.chat.enabled: false

# 2.13 New Query Assistant Feature
# Set the value of this setting to false to disable the query assistant
# observability.query_assist.enabled: false

# 2.14 Enable Ui Metric Collectors in Usage Collector
# Set the value of this setting to true to enable UI Metric collections
# usageCollection.uiMetric.enabled: false

#opensearch.hosts: [https://srvmusad01:9200]
opensearch.ssl.verificationMode: none
opensearch.username: kibanaserver
opensearch.password: kibanaserver
opensearch.requestHeadersWhitelist: [authorization, securitytenant]

opensearch_security.multitenancy.enabled: true
opensearch_security.multitenancy.tenants.preferred: [Private, Global]
opensearch_security.readonly_mode.roles: [kibana_read_only]
# Use this setting if you are running opensearch-dashboards without https
opensearch_security.cookie.secure: false

```

PS: I didn’t change the `kibanaserver` password

---

<div class="post-metadata">

### Author: ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)
#### Post date: [December 13, 2024, 6:20pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797/4 "2024-12-13T18:20:49Z")

</div>

It is strongly recommended to enable SSL. Otherwise, passwords will be sent in plain text through the network. Please enable SSL and try to run the following command:

`curl -k -u "kibanaserver": "kibanaserver" -XGET https://<your-opensearch-cluster-ip>:9200`

---

<div class="post-metadata">

### Author: ![gcavazzana](https://avatars.discourse-cdn.com/v4/letter/g/a87d85/32.png) [@gcavazzana](https://forum.opensearch.org/u/gcavazzana)
#### Post date: [December 13, 2024, 6:25pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797/5 "2024-12-13T18:25:27Z")

</div>

An error occured

```auto
[root@srvmusad01 ~]# curl -k -u "kibanaserver": "kibanaserver" -XGET https://<my-ip>:9200
curl: (6) Could not resolve host: kibanaserver
curl: (35) error:0A0000C6:SSL routines::packet length too long

```

---

<div class="post-metadata">

### Author: ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)
#### Post date: [December 13, 2024, 6:26pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797/6 "2024-12-13T18:26:22Z")

</div>

Sorry, please run this command:

`curl -k -u "kibanaserver":"kibanaserver" -XGET https://<your-opensearch-cluster-ip>:9200`

---

<div class="post-metadata">

### Author: ![gcavazzana](https://avatars.discourse-cdn.com/v4/letter/g/a87d85/32.png) [@gcavazzana](https://forum.opensearch.org/u/gcavazzana)
#### Post date: [December 13, 2024, 6:26pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797/7 "2024-12-13T18:26:42Z")

</div>

I just changed this option in `opensearch.yml` file:

`plugins.security.ssl.http.enabled: true`

And I restarted the service.

---

<div class="post-metadata">

### Author: ![gcavazzana](https://avatars.discourse-cdn.com/v4/letter/g/a87d85/32.png) [@gcavazzana](https://forum.opensearch.org/u/gcavazzana)
#### Post date: [December 13, 2024, 6:27pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797/8 "2024-12-13T18:27:25Z")

</div>

[root@srvmusad01 ~]# curl -k -u “kibanaserver”:“kibanaserver” -XGET https://:9200  
curl: (35) error:0A0000C6:SSL routines::packet length too long

Another error

---

<div class="post-metadata">

### Author: ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)
#### Post date: [December 13, 2024, 6:38pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797/9 "2024-12-13T18:38:11Z")

</div>

Do you have any error messages in the OpenSearch logs after rebooting your cluster?

---

<div class="post-metadata">

### Author: ![gcavazzana](https://avatars.discourse-cdn.com/v4/letter/g/a87d85/32.png) [@gcavazzana](https://forum.opensearch.org/u/gcavazzana)
#### Post date: [December 13, 2024, 6:49pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797/10 "2024-12-13T18:49:47Z")

</div>

No

`[root@srvmusad01 ~]# sudo systemctl restart opensearch`  
`[root@srvmusad01 ~]#`

---

<div class="post-metadata">

### Author: ![gcavazzana](https://avatars.discourse-cdn.com/v4/letter/g/a87d85/32.png) [@gcavazzana](https://forum.opensearch.org/u/gcavazzana)
#### Post date: [December 13, 2024, 6:53pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797/11 "2024-12-13T18:53:28Z")

</div>

I just runned this command and shows that’s all good.

`curl -k -u "kibanaserver":"kibanaserver" -X GET "http://<my-ip>:9200/_cluster/health?pretty"` - I used http

```auto
{
  "cluster_name" : "hmsc-opensearch",
  "status" : "green",
  "timed_out" : false,
  "number_of_nodes" : 4,
  "number_of_data_nodes" : 2,
  "discovered_master" : true,
  "discovered_cluster_manager" : true,
  "active_primary_shards" : 6,
  "active_shards" : 12,
  "relocating_shards" : 0,
  "initializing_shards" : 0,
  "unassigned_shards" : 0,
  "delayed_unassigned_shards" : 0,
  "number_of_pending_tasks" : 0,
  "number_of_in_flight_fetch" : 0,
  "task_max_waiting_in_queue_millis" : 0,
  "active_shards_percent_as_number" : 100.0
}

```

Anyway I still have the same initial issue on port 5601 on Chrome

**OpenSearch Dashboards server is not ready yet**

---

<div class="post-metadata">

### Author: ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)
#### Post date: [December 16, 2024, 12:27pm UTC](https://forum.opensearch.org/t/opensearch-security-not-initialized-error-on-opensearch-dashboard/22797/12 "2024-12-16T12:27:36Z")

</div>

Could you please check OpenSearch logs on the srvmusad01 node?  
Also, please run the following curl command against the srvmusad01 node:

`curl -k -u "kibanaserver":"kibanaserver" -X GET "http:// srvmusad01:9200/_cluster/health?pretty`
