# Allow SSL/TLS with self-generated ca certs and keys in localhost

**URL:** https://discuss.elastic.co/t/allow-ssl-tls-with-self-generated-ca-certs-and-keys-in-localhost/212502
**Category:** Kibana
**Tags:** elastic-stack-security
**Created:** [December 19, 2019, 1:51pm UTC](https://discuss.elastic.co/t/allow-ssl-tls-with-self-generated-ca-certs-and-keys-in-localhost/212502 "2019-12-19T13:51:22Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![LuigiDelavega](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@LuigiDelavega](https://discuss.elastic.co/u/LuigiDelavega)
#### Post date: [December 19, 2019, 1:51pm UTC](https://discuss.elastic.co/t/allow-ssl-tls-with-self-generated-ca-certs-and-keys-in-localhost/212502/1 "2019-12-19T13:51:22Z")

</div>

Hello ELK workers,

I'm working on the ELK stack and i manage to install it and make it work on my computer with local data etc... I'm now trying to make the stack use SSL/TLS for transport and http layer. I took the trial for 30 days to use security.

I did the Elasticsearch configuration to connect to localhost with https, here is my elasticsearch.yml file :

`node.name: node-1`  
`http.cors.enabled: true`  
`http.cors.allow-origin: "*"`  
`http.max_header_size: 16kb`  
`discovery.seed_hosts: ["127.0.0.1"]`  
`cluster.initial_master_nodes: ["node-1"]`  
`xpack.security.enabled: true`  
`xpack.security.transport.ssl.enabled: true`  
`xpack.security.transport.ssl.verification_mode: none`  
`xpack.security.transport.ssl.key: certs/instance.key`  
`xpack.security.transport.ssl.certificate: certs/instance.crt`  
`xpack.security.transport.ssl.certificate_authorities: ["certs/ca.crt"]`  
`xpack.security.http.ssl.enabled: true`  
`xpack.security.http.ssl.key: certs/instance.key`  
`xpack.security.http.ssl.certificate: certs/instance.crt`  
`xpack.security.http.ssl.certificate_authorities: ["certs/ca.crt"]`

I used elasticsearch-certutil tool with ca mode to construct the CA and cert mode to construct the instance key and certificate. All those files are stored in Config/certs folder that i created for each instance of the elk stack. Then i was able to connect to [https://localohost:9200](https://localohost:9200)

Then i generated with the same tool one key and certificate for kibana (stored in config/certs in kibana folder) and my kibana.yml looks like :

`server.host: "localhost"`  
`server.name: "kibana"`  
`elasticsearch.hosts: ["https://localhost:9200"]`  
`elasticsearch.username: "kibana"`  
`elasticsearch.password: "?????????"`  
`server.ssl.enabled: true`  
`server.ssl.key: C:\Users\T6SH\Desktop\Kibana\config\certs\instance.key`  
`server.ssl.certificate: C:\Users\T6SH\Desktop\Kibana\config\certs\instance.crt`  
`elasticsearch.ssl.certificateAuthorities: C:\Users\T6SH\Desktop\Elasticsearch\config\certs\ca.crt`

My problem is that i can launch the elasticsearch node, but when i launch my kibana, i got errors saying :

`GET https://localhost:9200/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip => unable to verify the first certificate`

How do i make the kibana trust my cert ? In the future my company will use a real CA, non-autosigned cert etc... but i kinda need it now to make my test.

Thanks for your help, merry christmas and happy new year !

(sorry for my awful english)

---

<div class="post-metadata">

### Author: ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)
#### Post date: [December 19, 2019, 2:30pm UTC](https://discuss.elastic.co/t/allow-ssl-tls-with-self-generated-ca-certs-and-keys-in-localhost/212502/2 "2019-12-19T14:30:00Z")

</div>

Hi @LuigiDelavega,

Which version of Kibana/Elasticsearch are you working with?

At a glance, your configuration _appears_ correct, so I want to try to reproduce this on my side with the same version you're using. I don't have a windows machine to test on though, so hopefully it's not an OS-specific issue.

Unrelated, you likely won't want to set `xpack.security.transport.ssl.verification_mode: none` when you deploy to production.

---

<div class="post-metadata">

### Author: ![LuigiDelavega](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@LuigiDelavega](https://discuss.elastic.co/u/LuigiDelavega)
#### Post date: [December 19, 2019, 2:34pm UTC](https://discuss.elastic.co/t/allow-ssl-tls-with-self-generated-ca-certs-and-keys-in-localhost/212502/3 "2019-12-19T14:34:32Z")

</div>

Hey @Larry_Gregory,

I'm working with 7.4.2 stack. I tried to put none to see if it changes something, i put it back at certificate\*. Thanks for your time i really appreciate it !

---

<div class="post-metadata">

### Author: ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)
#### Post date: [December 19, 2019, 5:50pm UTC](https://discuss.elastic.co/t/allow-ssl-tls-with-self-generated-ca-certs-and-keys-in-localhost/212502/4 "2019-12-19T17:50:20Z")

</div>

Thanks!

Can you try setting `server.ssl.certificateAuthorities` as well in your `kibana.yml`, and point that to the CA used to generate `C:\Users\T6SH\Desktop\Kibana\config\certs\instance.crt`?

---

<div class="post-metadata">

### Author: ![LuigiDelavega](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@LuigiDelavega](https://discuss.elastic.co/u/LuigiDelavega)
#### Post date: [December 20, 2019, 8:49am UTC](https://discuss.elastic.co/t/allow-ssl-tls-with-self-generated-ca-certs-and-keys-in-localhost/212502/5 "2019-12-20T08:49:53Z")

</div>

I tried to add it, but i still get the same errors...  
`GET https://localhost:9200/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip => unable to verify the first certificate`  
`HEAD https://localhost:9200/.apm-agent-configuration => unable to verify the first certificate`

I gonna put ` elasticsearch.ssl.verificationMode: none` to work on other axis of the ELK stack, and when i will install the stack on a dedicated server, with the company CA i won't get those errors i think. I spent a lot of time on this already, i did it from scratch twice to be sure i wasn't doing something wrong.

Have a great day and thanks again for the help !

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 17, 2020, 8:58am UTC](https://discuss.elastic.co/t/allow-ssl-tls-with-self-generated-ca-certs-and-keys-in-localhost/212502/6 "2020-01-17T08:58:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
