# Elasticsearch security PKI

**URL:** <https://discuss.elastic.co/t/elasticsearch-security-pki/195838>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 20, 2019, 4:02am UTC](https://discuss.elastic.co/t/elasticsearch-security-pki/195838 "2019-08-20T04:02:45Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [August 20, 2019, 10:31pm UTC](https://discuss.elastic.co/t/elasticsearch-security-pki/195838/7 "2019-08-20T22:31:25Z")

</div>

Thanks for your help once more

I've finished setting up elasticsearch part but stuck on encrypting communications in Kibana

> **[Encrypt TLS communications in Kibana | Kibana Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/kibana/current/configuring-tls.html)**

I don't see any clear examples but trying to understand what you have written here

> [@Certificates and keys for Kibana and Logstash with X-Pack](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390):
>
> Hello there, I'm setting up the ELK security using X-Pack, I generated the CA and Certs as suggested by the docs: bin/elasticsearch-certutil ca bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12 Shipped them to all the elasticseach nodes and worked fine. On Kibana, per the document: [https://www.elastic.co/guide/en/kibana/6.3/configuring-tls.html](https://www.elastic.co/guide/en/kibana/6.3/configuring-tls.html) It says: " Generate a server certificate for Kibana. You must either set the certificate’s subjectAltName to the hostname, fully-quali…

I'm still only using localhost and nginx to proxy 5601

---

_[View the full topic](https://discuss.elastic.co/t/elasticsearch-security-pki/195838)._
