# Enterprise Search - Configure Kibana to trust your SSL CA

**URL:** <https://discuss.elastic.co/t/enterprise-search-configure-kibana-to-trust-your-ssl-ca/308139>\
**Category:** Elastic Search\
**Created:** [June 24, 2022, 7:10pm UTC](https://discuss.elastic.co/t/enterprise-search-configure-kibana-to-trust-your-ssl-ca/308139 "2022-06-24T19:10:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rajkeshav](https://avatars.discourse-cdn.com/v4/letter/r/ecd19e/32.png) [@rajkeshav](https://discuss.elastic.co/u/rajkeshav)\
**Post date:** [June 24, 2022, 7:10pm UTC](https://discuss.elastic.co/t/enterprise-search-configure-kibana-to-trust-your-ssl-ca/308139/1 "2022-06-24T19:10:46Z")

</div>

**Kibana cannot find or does not trust the SSL certificates for Enterprise Search**

Kibana [logs](https://www.elastic.co/guide/en/enterprise-search/current/troubleshoot-setup.html#troubleshoot-setup-logs) the following:

{"type":"log","@timestamp":"2021-09-28T17:42:11+00:00","tags":["error","plugins","enterpriseSearch"],"pid":1220,"message":"Could not perform access check to Enterprise Search: FetchError: request to [https://enterprise-search:3002/api/ent/v2/internal/client\_config](https://enterprise-search:3002/api/ent/v2/internal/client_config) failed, reason: unable to verify the first certificate"}

I tried to modify kibana.yml to include enterpriseSearch.ssl.VerificationMode: none as a last resort, but kibana fails to start with FATAL Error: [config validation of [enterpriseSearch].ssl]: definition for this key is missing) .  
I see the same error when I try to pass a ca certificate (elasticsearch.ssl.certificateAuthorities: and elasticsearch.ssl.verificationMode: certificate)

ElasticSearch and Kibana version: 7.12  
EnterpriseSearch version: 7.12

---

<div class="post-metadata">

**Author:** ![Sean\_Story](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean_story/32/69987_2.png) [@Sean\_Story](https://discuss.elastic.co/u/Sean_Story)\
**Post date:** [June 24, 2022, 7:47pm UTC](https://discuss.elastic.co/t/enterprise-search-configure-kibana-to-trust-your-ssl-ca/308139/2 "2022-06-24T19:47:23Z")

</div>

Hi @rajkeshav,

It looks like you may be reading documentation for a more recent version of Enterprise Search than you are using. In the latest version ([Configure SSL/TLS | Elastic Enterprise Search Documentation [8.2] | Elastic](https://www.elastic.co/guide/en/enterprise-search/8.2/configure-ssl-tls.html#configure-ssl-tls-in-kibana)) the fields for `enterpriseSearch.ssl.*` are available, but in 7.12, you should be using:

> **[Configure SSL/TLS | Elastic Enterprise Search Documentation \[7.12\] | Elastic](https://www.elastic.co/guide/en/enterprise-search/7.12/configure-ssl-tls.html)**

You may want to just upgrade to 7.17 or 8.2, especially if you're wanting to use Enterprise Search through Kibana.

---

<div class="post-metadata">

**Author:** ![rajkeshav](https://avatars.discourse-cdn.com/v4/letter/r/ecd19e/32.png) [@rajkeshav](https://discuss.elastic.co/u/rajkeshav)\
**Post date:** [July 6, 2022, 12:51am UTC](https://discuss.elastic.co/t/enterprise-search-configure-kibana-to-trust-your-ssl-ca/308139/3 "2022-07-06T00:51:12Z")

</div>

Hi Sean. I was able to resolve this by using version 8. Thank you for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2022, 12:51am UTC](https://discuss.elastic.co/t/enterprise-search-configure-kibana-to-trust-your-ssl-ca/308139/4 "2022-08-03T00:51:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
