Kibana redirects back to login after successful auth on AWS Elasticsearch Service when accessing remotely via an NGINX reverse proxy

Viewed 1265

I have Elasticsearch (AWS Elasticsearch Service 7.7) running in my AWS VPC.

I'm trying to access Kibana, from a web browser, on my laptop at home.

I followed these instructions, to setup an nginx reverse proxy: https://medium.com/@k.ashu403/aws-elasticsearch-nginx-reverse-proxy-for-accessing-kibana-86292edc6f14

My config file based on this one (authored by the blog post author): https://github.com/kin-kins/AWS-services/blob/34c94abeaac5e8e7f5371f5d0df3f49c0417ec56/nginx_reverse_proxy.conf

Everywhere that file shows 3.226.189.187, I have replaced it with the external IP of my reverse proxy.

Everywhere that file shows vpc-ngelasti-qmazoh6hzvpxiludpnzasoi2nu.us-east-1.es.amazonaws.com, I have replaced it with the fqdn of the Kibana instance running in my VPC.

(And nginx has been restarted).

If I then access, my equivalent of: http://3.226.189.187/_plugin/kibana/, I get properly requested for my username & password, and I pass basic auth.

It then redirects to the equivalent of http://3.226.189.187/_plugin/kibana/login?nextUrl=%2F_plugin%2Fkibana%2F#/

If I put in an incorrect username or password, it tells me that it's wrong.

If I put in the correct username & password, it sends me right back to http://3.226.189.187/_plugin/kibana/login?nextUrl=%2F_plugin%2Fkibana%2F#/

In short, I keep getting prompted for the username/password (i.e. redirected to the login page). I assume something is wrong in the nginx conf, but I'm not sure, and have spend a lot of time w/ trial and error, and haven't made much progress. (AWS Elasticsearch Service is configured for username/password auth, which works within the VPC, for Elasticsearch)

1 Answers

What worked for me:

  • add https (443) on the inbound security group with your ip/office ip range/all traffic

  • generate a certificate (be aware chrome doesn't like self signed, might have to use firefox)

  • change your nginx config to use https (port 443) instead of http (port 80) and add the path to the certificate in the config as well.

Example config, namely the listen 443 line as well all the lines starting with ssl

Explanation:

When logging in a security cookie is supposed to be set with a token but it won’t be set when using http for security reasons, changing to https will allow this cookie to be set.

This can be seen by looking at the network request to _plugin/kibana/api/ui_metric/report and looking at the headers and response. It shows the redirect back to log in as well the session expired message.

Related