# Error in Kibana "xpack =\> unable to get local issuer certificate"

**URL:** https://discuss.elastic.co/t/error-in-kibana-xpack-unable-to-get-local-issuer-certificate/249226
**Category:** Kibana
**Tags:** elastic-stack-security
**Created:** [September 19, 2020, 11:11pm UTC](https://discuss.elastic.co/t/error-in-kibana-xpack-unable-to-get-local-issuer-certificate/249226 "2020-09-19T23:11:07Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Abhishek\_Kumar7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_kumar7/32/45433_2.png) [@Abhishek\_Kumar7](https://discuss.elastic.co/u/Abhishek_Kumar7)
#### Post date: [September 19, 2020, 11:11pm UTC](https://discuss.elastic.co/t/error-in-kibana-xpack-unable-to-get-local-issuer-certificate/249226/1 "2020-09-19T23:11:08Z")

</div>

I have a single node server with ES and Kibana hosted on it. I have put them behind an ELB , under a domain name .  
Assume :- [kibana.xyz.com](http://kibana.xyz.com) and [elasticsearch.xyz.com](http://elasticsearch.xyz.com)  
I have enabled http ssl in elasticsearch and copy pasted the pem to kibana but it's not working.  
While creating http ssl i typed both domain name to check if that is the cause , but no help leaving it blank or passing it makes not difference  
PFB elasticsearch.yml

```auto
cluster.name: my-application
node.name: elk-01
network.host: x.x.x.x
discovery.seed_hosts: ["elk-01"]
cluster.initial_master_nodes: ["elk-01"]
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12
xpack.security.authc:
  anonymous:
    roles: kibana_system
    authz_exception: false
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: "/home/elasticsearch/log_services/elasticsearch-7.9.1/config/new_http.p12"

```

PFB kibana.yml

```auto
server.host: "0.0.0.0"
elasticsearch.hosts: ["https://test-elasticsearch.xyz.com"]
elasticsearch.username: "elastic"
elasticsearch.password: "xxxx"
xpack.security.enabled: true
xpack.reporting.encryptionKey: "5HLw1U6ot9tU490VivE1rR9ymirksJLM"
xpack.encryptedSavedObjects.encryptionKey: "5HLw1U6ot9tU490VivE1rR9ymirksJLM"
elasticsearch.ssl.certificateAuthorities: "/home/elasticsearch/log_services/kibana-7.9.1-linux-x86_64/config/elasticsearch-new-ca.pem"
logging.dest: /home/elasticsearch/log_services/kibana7/logs/kibana.log

```

I have followed below links completely to implement this

```auto
https://techexpert.tips/elasticsearch/elasticsearch-enable-tls-https/
https://www.elastic.co/guide/en/elasticsearch/reference/7.9/configuring-tls.html#node-certificates
https://www.elastic.co/guide/en/kibana/7.9/configuring-tls.html

```

I am sure that transport certificates are fine as without tls implementation it works well in this dev env and prod as well.  
I am using 7.9.1 version of elastic,kibana and agent.

```auto
{"type":"log","@timestamp":"2020-09-19T22:55:00Z","tags":["warning","elasticsearch","data"],"pid":5047,"message":"Unable to revive connection: https://test-elasticsearch.xyz.com/"}
{"type":"log","@timestamp":"2020-09-19T22:55:00Z","tags":["warning","elasticsearch","data"],"pid":5047,"message":"No living connections"}

```

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [September 21, 2020, 12:24am UTC](https://discuss.elastic.co/t/error-in-kibana-xpack-unable-to-get-local-issuer-certificate/249226/2 "2020-09-21T00:24:47Z")

</div>

What sort of ELB did you use?

If it's an Application Load Balancer, then it will terminate the TLS connection and the certificate you need to configure in Kibana is the one that ELB is using, not the one that Elasticsearch is configured to use.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 19, 2020, 12:25am UTC](https://discuss.elastic.co/t/error-in-kibana-xpack-unable-to-get-local-issuer-certificate/249226/3 "2020-10-19T00:25:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
