# Certificates and keys for Kibana and Logstash with X-Pack

**URL:** <https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 28, 2018, 9:31pm UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390 "2018-09-28T21:31:19Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 1, 2018, 7:11am UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/2 "2018-10-01T07:11:28Z")

</div>

> My question is, how to generate this server certificate for Kibana?

This is slightly different. Users will access Kibana via their browser so the certificate that Kibana will use for https needs to be one that the browsers can trust. This usually means that you generate a CSR ( certificate signing request) and have it signed by a trusted (public or corporate) CA. You can use `elasticsearch-certutil` to create a CSR, see [elasticsearch-certutil | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/certutil.html#certutil-csr)

i.e

```auto
bin/elasticsearch-certutil csr --dns kibana.example.com 

```

Now, under certain circumstances ( i.e. if the number of users accessing Kibana is small, you can control the trust anchors in the users browsers or OSes, testing reasons, etc. ) you might want to use self signed certificates or certificates signed by a CA that the browsers do not trust by default. Keep in mind that this will cause the browser to show a warning.

You can use `elasticsearch-certutil` to create a server certificate for Kibana, but Kibana doesn't yet support the PKCS#12 format so you'd need to create a PEM encoded key and certificate ([by specifying the `--pem` parameter](https://www.elastic.co/guide/en/elasticsearch/reference/current/certutil.html#certutil-cert)). An example invocation would be:

```auto
bin/elasticsearch-certutil cert --pem -ca path/to/your.p12 --dns kibana.example.com

```

> Also, for logstash pipeline output to elasticsearch, what should we put in for "cacert =\>"?

You need to set the CA cert file that you have created with certutil. However, Elasticsearch output Logstash plugin doesn't support PKCS#12 format so you would need to export the CA certificate in PEM format as such :

```auto
openssl pkcs12 -in ca.p12 -clcerts -nokeys -chain -out ca.pem

```

and use that as the value of `cacert`

---

_[View the full topic](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390)._
