# Elastic stack issues Certificates and Kibana is not ready yet

**URL:** <https://discuss.elastic.co/t/elastic-stack-issues-certificates-and-kibana-is-not-ready-yet/264728>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 18, 2021, 3:20pm UTC](https://discuss.elastic.co/t/elastic-stack-issues-certificates-and-kibana-is-not-ready-yet/264728 "2021-02-18T15:20:56Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![baddack](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/baddack/32/100535_2.png) [@baddack](https://discuss.elastic.co/u/baddack)\
**Post date:** [February 19, 2021, 3:03pm UTC](https://discuss.elastic.co/t/elastic-stack-issues-certificates-and-kibana-is-not-ready-yet/264728/4 "2021-02-19T15:03:42Z")

</div>

First, thank you very much for your explanations about certificates. I was confused about PKCS8 format and the ecryption of the private key, but now it's OK.

> The most likely cause is that your private key has a password (that is, it is encrypted) and you didn't provide that password to Logstash. In that case the code that reads the private key in Logstash will assume it is not encrypted, and then fail because it's not encoded correctly.

Thanks to you I realized that I used the following command :

`openssl pkcs8 -in logstash.key -topk8 -out logstash.pkcs8.key`

Like you said it, I didn't specify the password to Logstash and in addition I encrypted the private key so the server couldn't read the file.

In the next command I specify **-nocrypt** option and it generated a new file with the private key in the PKCS8 format without encryption.

`openssl pkcs8 -in logstash.key -topk8 -nocrypt -out logstash.pkcs8.key`

Note: Thanks to this message too [Settings SSL/TLS setup with PKCS8 keys - #2 by ikakavas](https://discuss.elastic.co/t/settings-ssl-tls-setup-with-pkcs8-keys/127496/2) 🙂

Now the error about certificate disappeared but there is a new one :

```
Feb 19 14:37:23 logstash logstash[25980]: [2021-02-19T14:37:23,317][INFO][org.logstash.beats.BeatsHandler] [local: 0.0.0.0:5044, remote: 10.56.244.177:45616] Handling exception: javax.net.ssl.SSLHandshakeException: error:10000412:SSL routines:OPENSSL_internal:SSLV3_ALERT_BAD_CERTIFICATE

```

For this one I found a topic with a response from you --\> [Logstash 7.5 with SSL giving SSLV3\_ALERT\_BAD\_CERTIFICATE - #3 by TimV](https://discuss.elastic.co/t/logstash-7-5-with-ssl-giving-sslv3-alert-bad-certificate/212512/3)

And I saw that 10.56.244.177 is my suricata IDS server, the certificate was expirated too. So, Logstash says "I don't trust your certificate" to suricata. So, I changed it and there are no more SSL errors on Logstash.

About Elasticsearch and Kibana :

The few logs which are in the topics are repeated thousand of times. There are no others logs which can helps. I will continue to investigate maybe I will find something more explicit about "Kibana is not ready yet" error !

Anyway, thank you a lot for the help with logstash and certificates.

---

_[View the full topic](https://discuss.elastic.co/t/elastic-stack-issues-certificates-and-kibana-is-not-ready-yet/264728)._
