# Elastic stack issues Certificates and Kibana is not ready yet

**URL:** <https://discuss.elastic.co/t/elastic-stack-issues-certificates-and-kibana-is-not-ready-yet/264728>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 18, 2021, 3:20pm UTC](https://discuss.elastic.co/t/elastic-stack-issues-certificates-and-kibana-is-not-ready-yet/264728 "2021-02-18T15:20:56Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 19, 2021, 5:29am UTC](https://discuss.elastic.co/t/elastic-stack-issues-certificates-and-kibana-is-not-ready-yet/264728/3 "2021-02-19T05:29:27Z")

</div>

Certificate and Key formats are fairly confusing.

PKCS#8 is a private key _encoding_. It's a way of describing a private key as a stream of bytes. It it technically not a file type, because it doesn't describe how to store that key in a file - just how to store it as bytes.

PEM is a _file format_. It's a way of writing a cryptographic object in particular encoding, into a file on disk.

It is possible (and common) to have a private key that is _encoded_ as PKCS#8 and then written to a PEM _file_.

> [@](#):
>
> Why there are .crt and .pem certificates ?

The PEM file format can store a variety of different cryptographic objects. Among other object types, it can store both certificates and keys.  
So, when you have `elasticsearch.pem + elasticsearch.key`, _technically_ those are both PEM files. You can assume that `elasticsearch.pem` is a _certificate_ written in PEM format and `elasticsearch.key` is a _key_ (using some encoding), also written in PEM format.

Sometimes people use the `.pem` extension because they are PEM files, which is fair enough.  
Other people use `.cer` or `.crt` because they are certificates, written as PEM files, which is also a fair choice.  
The Elasticsearch team prefers to use the `.crt` and `.key` style of naming (because that emphasizes the main difference between the 2 files) but it doesn't matter.

It is highly likely that your `.cer`,`.crt` and `.pem` files all use the same encoding and format.  
If you want to be consistent you can just rename the files.

> [@](#):
>
> For logstash, it asked me a password, I think because it's PKCS8 format.

PKCS#8 files _can_ have password, but don't always. In this case, it's really just that there is a password on that key (which is a good idea) and there isn't one on the Elasticsearch & Kibana keys.

> [@](#):
>
> I didn't have the password so I generated a new private key

Logstash has a copy of the password, so it's possible you could get it from there, but generating a new one is fine.

> [@](#):
>
> `java.lang.IllegalArgumentException: File does not contain valid private key: /etc/logstash/certs/logstash.pkcs8.key`

This error message is a little bit misleading.  
It simply means that Logstash failed to read the key from the file. It can be triggered by a number of reasons that don't necessarily mean that the file is invalid.

In this case:

```auto
InvalidKeyException: IOException : DER input, Integer tag error`

```

The most likely cause is that your private key has a password (that is, it is encrypted) and you didn't provide that password to Logstash. In that case the code that reads the private key in Logstash will assume it is not encrypted, and then fail because it's not encoded correctly.

> [@](#):
>
> **FROM ELASTICSEARCH /var/log/syslog :**
> 
> ```auto
> Feb 17 16:19:51 elasticsearch python3[32232]: INFO:elastalert:Queried rule hid from 2021-02-17 16:19 CET to 2021-02-17 16:19 CET: 0 / 0 hits
> 
> ```

This is not elasticsearch. This is coming from `elastalert`, and I really don't know enough to be able to help you with that.

> [@](#):
>
> **FROM KIBANA /var/log/syslog :**
> 
> ```auto
> Feb 17 16:27:27 kibana kibana[5792]: {"type":"log","@timestamp":"2021-02-17T15:27:27Z","tags":["warning","elasticsearch","admin"],"pid":5792,"message":"No living connections"}
> 
> ```

Are there more messages above that? The most useful information appears to be missing.

---

_[View the full topic](https://discuss.elastic.co/t/elastic-stack-issues-certificates-and-kibana-is-not-ready-yet/264728)._
