# Encrypting communications in Kibana

**URL:** https://discuss.elastic.co/t/encrypting-communications-in-kibana/186369
**Category:** Kibana
**Tags:** elastic-stack-security
**Created:** [June 19, 2019, 5:04am UTC](https://discuss.elastic.co/t/encrypting-communications-in-kibana/186369 "2019-06-19T05:04:10Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![philshikkim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philshikkim/32/48341_2.png) [@philshikkim](https://discuss.elastic.co/u/philshikkim)
#### Post date: [June 19, 2019, 5:04am UTC](https://discuss.elastic.co/t/encrypting-communications-in-kibana/186369/1 "2019-06-19T05:04:11Z")

</div>

Hello,

English is not my native language. I hope you get my drift.

I want to make a Kibana secure communication using https. So I made this following:

$ openssl genrsa -out server.key 2048

$ openssl req -new -key server.key -out server.csr

$ openssl x509 -req -days 365 -in server.csr -signkey server.key -out server.crt

$ vi kibana.yml

server.ssl.enabled: true  
server.ssl.certificate: /home/phil/elasticsearch-7.1.1/config/server.crt  
server.ssl.key: /home/phil/elasticsearch-7.1.1/config/server.key

$ bin/kibana

This is working well. I can connect the Kibana using https protocol. but Kibana shows me following error logs whenever clients connect to Kibana.

\</\> error [04:49:21.864] [error][client][connection] Error: 140531484981120:error:14094416:SSL routines:ssl3\_read\_bytes:sslv3 alert certificate unknown:../deps/openssl/openssl/ssl/record/rec\_layer\_s3.c:1407:SSL alert number 46\</\>

Is this a real error log or normal?

or Can I remove this error logs from Kibana?

I tried to use elasticsearch-certutil for making a ssl key and cert file, but it's failed. can't make a key and cert file using elasticsearch-certutil command. So I used openssl command.

Thanks in advance.

---

<div class="post-metadata">

### Author: ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)
#### Post date: [June 19, 2019, 3:12pm UTC](https://discuss.elastic.co/t/encrypting-communications-in-kibana/186369/2 "2019-06-19T15:12:09Z")

</div>

Are you able to connect to Elasticsearch through Kibana using this setup?

---

<div class="post-metadata">

### Author: ![philshikkim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philshikkim/32/48341_2.png) [@philshikkim](https://discuss.elastic.co/u/philshikkim)
#### Post date: [June 21, 2019, 12:46am UTC](https://discuss.elastic.co/t/encrypting-communications-in-kibana/186369/3 "2019-06-21T00:46:41Z")

</div>

Yes. I found that Kibana is able to connect to Elasticsearch with this setup.

GET /\_cat/health?v

epoch timestamp cluster status node.total node.data shards pri relo init unassign pending\_tasks max\_task\_wait\_time active\_shards\_percent  
1561077975 00:46:15 elasticsearch yellow 1 1 3 3 0 0 1 0 - 75.0%

Could you give me an example of ealsticsearch-certutil for making a key and a cert file? I tried to do several times. can't make it.

I tried to do like this

$ ./elasticsearch-certutil ca  
Please enter the desired output file [elastic-stack-ca.p12]: elastic-stack-ca.p12  
Enter password for elastic-stack-ca.p12 :

$ ls /home/phil/elasticsearch-7.1.1/elastic-stack-ca.p12  
/home/phil/elasticsearch-7.1.1/elastic-stack-ca.p12

$ ./elasticsearch-certutil cert --ca /home/phil/elasticsearch-7.1.1/elastic-stack-ca.p12  
Enter password for CA (/home/phil/elasticsearch-7.1.1/elastic-stack-ca.p12) :  
Please enter the desired output file [elastic-certificates.p12]:  
Enter password for elastic-certificates.p12 :

$ vi kibana.yml

server.ssl.enabled: true  
server.ssl.certificate: /home/phil/elasticsearch-7.1.1/elastic-certificates.p12  
server.ssl.key: /home/phil/elasticsearch-7.1.1/elastic-certificates.p12

$ bin/kibana  
log [01:13:06.046] [fatal][root] Error: error:0906D06C:PEM routines:PEM\_read\_bio:no start line  
at Object.createSecureContext (\_tls\_common.js:113:17)  
at Server (\_tls\_wrap.js:870:27)  
at new Server (https.js:62:14)  
at Object.createServer (https.js:85:10)  
at module.exports.internals.Core.\_createListener (/home/phil/kibana-7.1.1-linux-x86\_64/node\_modules/hapi/lib/core.js:491:79)  
at new module.exports.internals.Core (/home/phil/kibana-7.1.1-linux-x86\_64/node\_modules/hapi/lib/core.js:112:30)  
at new module.exports (/home/phil/kibana-7.1.1-linux-x86\_64/node\_modules/hapi/lib/server.js:25:18)  
at Object.createServer (/home/phil/kibana-7.1.1-linux-x86\_64/src/core/server/http/http\_tools.js:75:20)  
at HttpServer.start (/home/phil/kibana-7.1.1-linux-x86\_64/src/core/server/http/http\_server.js:40:36)  
at HttpService.start (/home/phil/kibana-7.1.1-linux-x86\_64/src/core/server/http/http\_service.js:46:38)

FATAL Error: error:0906D06C:PEM routines:PEM\_read\_bio:no start line

$

Thanks in advance.

---

<div class="post-metadata">

### Author: ![philshikkim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philshikkim/32/48341_2.png) [@philshikkim](https://discuss.elastic.co/u/philshikkim)
#### Post date: [June 21, 2019, 1:47am UTC](https://discuss.elastic.co/t/encrypting-communications-in-kibana/186369/4 "2019-06-21T01:47:35Z")

</div>

Thanks a lot.

I solved my problem via the following link got from Elastic news e-mail.

> **[Configuring SSL, TLS, and HTTPS to secure Elasticsearch, Kibana, Beats, and...](https://www.elastic.co/blog/configuring-ssl-tls-and-https-to-secure-elasticsearch-kibana-beats-and-logstash?ultron=june-2019&blade=newsletter&hulk=email&mkt_tok=eyJpIjoiTlRBM1pqWTJPV0ppWldaaiIsInQiOiJiXC96b2JuZ0pUWEpCUDNzWDNlcmZualRmejM0blBVTk5tWFRsbTVubk9FXC9PNVIzTkIweWRGdXBzdXdmTjhPV0dyOFNPSzRuT3NZVXcwMDd6SFdnUFUxVnhoa29iWHZnRUJRbzd2Y1wveXE1MXUrVzlkdG96dnFcL1dabjNTczlUaXoifQ%253D%253D)**
>
> Feeling insecure about your Elastic Stack security? Run through these step-by-step instructions for setting up TLS encryption and https on Elasticsearch, Kibana, Logstash, and Beats to shore up your stack's defenses. Highly recommended for end-to-end...

---

<div class="post-metadata">

### Author: ![philshikkim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philshikkim/32/48341_2.png) [@philshikkim](https://discuss.elastic.co/u/philshikkim)
#### Post date: [June 21, 2019, 7:18am UTC](https://discuss.elastic.co/t/encrypting-communications-in-kibana/186369/5 "2019-06-21T07:18:55Z")

</div>

I found useful information at the Elasticsearch blog page above.

Publicly trusted authorities have very strict standards and auditing practices to ensure that a certificate is not created without validating proper identity ownership. For the purpose of this blog post, we will create a self-signed certificate for Kibana (meaning the generated certificate was signed by using its own private key). **Due to clients(Web Browsers) not trusting self-signed Kibana certificates, you will see a message similar to the following in your Kibana logs, until proper trust is established by using certificates generated by an enterprise or public CA** (here's the [link to the issue in the Kibana repo](https://github.com/elastic/kibana/issues/35004)). This issue does not affect your ability to work in Kibana:

[18:22:31.675] [error][client][connection] Error: 4443837888:error:14094416:SSL routines:ssl3\_read\_bytes:sslv3 alert certificate unknown:../deps/openssl/openssl/ssl/s3\_pkt.c:1498:SSL alert number 46

As a result, Kibana's error logs is normal.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 19, 2019, 7:18am UTC](https://discuss.elastic.co/t/encrypting-communications-in-kibana/186369/6 "2019-07-19T07:18:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
