# FATAL Error: \[config validation of \[xpack.security\].http\]: definition for this key is missing

**URL:** <https://discuss.elastic.co/t/fatal-error-config-validation-of-xpack-security-http-definition-for-this-key-is-missing/275887>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [June 14, 2021, 6:27pm UTC](https://discuss.elastic.co/t/fatal-error-config-validation-of-xpack-security-http-definition-for-this-key-is-missing/275887 "2021-06-14T18:27:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![leprovokateur](https://avatars.discourse-cdn.com/v4/letter/l/8e8cbc/32.png) [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)\
**Post date:** [June 14, 2021, 6:27pm UTC](https://discuss.elastic.co/t/fatal-error-config-validation-of-xpack-security-http-definition-for-this-key-is-missing/275887/1 "2021-06-14T18:27:48Z")

</div>

Hi,

I follow [Set up basic security for the Elastic Stack plus secured HTTPS traffic | Elasticsearch Guide [7.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.13/security-basic-setup-https.html) and am stuck at [Set up basic security for the Elastic Stack plus secured HTTPS traffic | Elasticsearch Guide [7.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.13/security-basic-setup-https.html#encrypt-kibana-elasticsearch)

The kibana.yml consists of:

```auto
server.host: "192.168.58.82"
server.name: "Elastic-Agent Demo"
elasticsearch.hosts: ["https://localhost:9200"]
elasticsearch.username: "kibana_system"
logging.verbose: true
elasticsearch.ssl.certificateAuthorities: ["/etc/kibana/elasticsearch-ca.pem"]

```

After the start of kibana I see:  
`kibana[20546]: FATAL Error: [config validation of [xpack.security].http]: definition for this key is missing`

What am I missing?

Elasticsearch is reachable under [https://localhost:9200](https://localhost:9200)

Kibana and Elasticsearch are in version 7.13.1.

Best regards,  
Robert

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [June 17, 2021, 11:14am UTC](https://discuss.elastic.co/t/fatal-error-config-validation-of-xpack-security-http-definition-for-this-key-is-missing/275887/2 "2021-06-17T11:14:14Z")

</div>

that is all that you have in kibana.yml file? If that's the case, have you added any settings to the kibana keystore? or used any environment variables for configs?

---

<div class="post-metadata">

**Author:** ![leprovokateur](https://avatars.discourse-cdn.com/v4/letter/l/8e8cbc/32.png) [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)\
**Post date:** [June 17, 2021, 3:27pm UTC](https://discuss.elastic.co/t/fatal-error-config-validation-of-xpack-security-http-definition-for-this-key-is-missing/275887/3 "2021-06-17T15:27:44Z")

</div>

Hi Marius,

I executed the following kibana keystore commands:

```auto
/usr/share/kibana/bin/kibana-keystore create
/usr/share/kibana/bin/kibana-keystore add elasticsearch.password
/usr/share/kibana/bin/kibana-keystore add xpack.security.http.ssl.keystore.secure_password

```

Best regards,  
Robert

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [June 17, 2021, 3:52pm UTC](https://discuss.elastic.co/t/fatal-error-config-validation-of-xpack-security-http-definition-for-this-key-is-missing/275887/4 "2021-06-17T15:52:40Z")

</div>

> [@leprovokateur](#):
>
> `/usr/share/kibana/bin/kibana-keystore add xpack.security.http.ssl.keystore.secure_password`

This is the one mentioned in the error message. I've never seen it before as a setting so I don't know why you have it there for.

---

<div class="post-metadata">

**Author:** ![leprovokateur](https://avatars.discourse-cdn.com/v4/letter/l/8e8cbc/32.png) [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)\
**Post date:** [June 17, 2021, 7:37pm UTC](https://discuss.elastic.co/t/fatal-error-config-validation-of-xpack-security-http-definition-for-this-key-is-missing/275887/5 "2021-06-17T19:37:20Z")

</div>

Hi Marius,  
I made a mistake, it should read elasticsearch-keystore. Thanks for the hint.

Best regards,  
Robert

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 15, 2021, 7:37pm UTC](https://discuss.elastic.co/t/fatal-error-config-validation-of-xpack-security-http-definition-for-this-key-is-missing/275887/6 "2021-07-15T19:37:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
