# How to enable SSL (https) for Kibana?

**URL:** https://discuss.elastic.co/t/how-to-enable-ssl-https-for-kibana/224161
**Category:** Kibana
**Created:** [March 18, 2020, 5:16pm UTC](https://discuss.elastic.co/t/how-to-enable-ssl-https-for-kibana/224161 "2020-03-18T17:16:28Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![TheVintik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thevintik/32/60494_2.png) [@TheVintik](https://discuss.elastic.co/u/TheVintik)
#### Post date: [March 18, 2020, 5:16pm UTC](https://discuss.elastic.co/t/how-to-enable-ssl-https-for-kibana/224161/1 "2020-03-18T17:16:29Z")

</div>

Hello,

I just installed ES node and Kibana (latest, 7.6 version) and trying to enable SSL for Kibana.

Could anybody advise me on how I can do it?

I used this command to generate certificates:

> bin/elasticsearch-certutil http

After unpacking zip file I got `elasticsearch` and `kibana` dirs. And I have these files in `elasticsearch` dir:

```
README.txt  
my-domain.csr  
my-domain.key  
sample-elasticsearch.yml

```

How I can get `crt` file instead of `csr`?

---

<div class="post-metadata">

### Author: ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)
#### Post date: [March 18, 2020, 5:48pm UTC](https://discuss.elastic.co/t/how-to-enable-ssl-https-for-kibana/224161/2 "2020-03-18T17:48:51Z")

</div>

Hi @TheVintik,

Here is our documentation to for Kibana TLS:  
[https://www.elastic.co/guide/en/kibana/current/configuring-tls.html](https://www.elastic.co/guide/en/kibana/current/configuring-tls.html)

To generate crt file you can do the following:

./bin/elasticsearch-certutil ca --pem

Thanks!  
Liza

---

<div class="post-metadata">

### Author: ![TheVintik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thevintik/32/60494_2.png) [@TheVintik](https://discuss.elastic.co/u/TheVintik)
#### Post date: [March 18, 2020, 6:27pm UTC](https://discuss.elastic.co/t/how-to-enable-ssl-https-for-kibana/224161/3 "2020-03-18T18:27:51Z")

</div>

Thank you for response, @Liza\_Dayoub ! I generated keys with `./bin/elasticsearch-certutil ca --pem` and update my kibana.yml config file with:

```
server.ssl.enabled: true
server.ssl.certificate: /etc/kibana/certs/ca.crt
server.ssl.key: /etc/kibana/certs/ca.key

```

After Kibana restart I got these logs:

> {"type":"log","@timestamp":"2020-03-18T18:24:09Z","tags":["listening","info"],"pid":29080,"message":"Server running at [https://MY-IP:5601](https://MY-IP:5601)"}

> {"type":"log","@timestamp":"2020-03-18T18:24:09Z","tags":["info","http","server","Kibana"],"pid":29080,"message":"http server running at [https://MY-IP:5601](https://MY-IP:5601)"}

But when I try to open Kibana in browser [https://MY-IP:5601](https://MY-IP:5601) I got a lot of these errors:

> {"type":"error","@timestamp":"2020-03-18T18:25:30Z","tags":["connection","client","error"],"pid":29080,"level":"error","error":{"message":"140293902256000:error:14094418:SSL routines:ssl3\_read\_bytes:tlsv1 alert unknown ca:../deps/openssl/openssl/ssl/record/rec\_layer\_s3.c:1544:SSL alert number 48\n","name":"Error","stack":"Error: 140293902256000:error:14094418:SSL routines:ssl3\_read\_bytes:tlsv1 alert unknown ca:../deps/openssl/openssl/ssl/record/rec\_layer\_s3.c:1544:SSL alert number 48\n"},"message":"140293902256000:error:14094418:SSL routines:ssl3\_read\_bytes:tlsv1 alert unknown ca:../deps/openssl/openssl/ssl/record/rec\_layer\_s3.c:1544:SSL alert number 48\n"}

---

<div class="post-metadata">

### Author: ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)
#### Post date: [March 18, 2020, 6:38pm UTC](https://discuss.elastic.co/t/how-to-enable-ssl-https-for-kibana/224161/4 "2020-03-18T18:38:17Z")

</div>

Hi @TheVintik,

I believe these messages are expected if it is a self signed certificate, due to the client not trusting the certificate and Kibana ignore the certificate errors.

However let me ping our security expert @Larry_Gregory to comment further.

Thanks!  
Liza

---

<div class="post-metadata">

### Author: ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)
#### Post date: [March 18, 2020, 7:40pm UTC](https://discuss.elastic.co/t/how-to-enable-ssl-https-for-kibana/224161/5 "2020-03-18T19:40:43Z")

</div>

@TheVintik if you run the command with the `cert` option, it will generate a certificate as opposed to a CSR:

`bin/elasticsearch-certutil http cert`

It looks like you're trying to specify the certificate authority ("CA") as the kibana server certificate, which is not something you'd want to do.

---

<div class="post-metadata">

### Author: ![TheVintik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thevintik/32/60494_2.png) [@TheVintik](https://discuss.elastic.co/u/TheVintik)
#### Post date: [March 18, 2020, 8:24pm UTC](https://discuss.elastic.co/t/how-to-enable-ssl-https-for-kibana/224161/6 "2020-03-18T20:24:36Z")

</div>

Thank you for response @Larry_Gregory

Could you please advice me - how I should generate `crt` and `key` for Kibana?  
Should I run `bin/elasticsearch-certutil http` (without `cert` option)?

By the way, I got these files after running `bin/elasticsearch-certutil http`:

> Generate a CSR? [y/N]  
> Use an existing CA? [y/N]  
> ...

```
Archive: /usr/share/elasticsearch/elasticsearch-ssl-http.zip
creating: elasticsearch/
inflating: elasticsearch/README.txt  
inflating: elasticsearch/http.p12  
inflating: elasticsearch/sample-elasticsearch.yml  
creating: ca/
inflating: ca/README.txt           
inflating: ca/ca.p12               
creating: kibana/
inflating: kibana/README.txt       
inflating: kibana/elasticsearch-ca.pem  
inflating: kibana/sample-kibana.yml

```

But looks like there are no `key` and `cert` files for Kibana`s config.

I would appreciate you with an example of how to generate `crt` and `key`.

---

<div class="post-metadata">

### Author: ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)
#### Post date: [March 19, 2020, 7:31pm UTC](https://discuss.elastic.co/t/how-to-enable-ssl-https-for-kibana/224161/7 "2020-03-19T19:31:24Z")

</div>

Hi @TheVintik,

For production you will need to follow below guide and have the certificates signed by a CA:

```auto
https://www.elastic.co/guide/en/kibana/current/configuring-tls.html

```

For local non-production setup, you can do the following:

```auto
./bin/elasticsearch-certutil cert -name <name> -dns <dns> 

```

Then kibana.yml you can add the following:

```auto
server.ssl.keystore.path: <name>.p12
server.ssl.keystore.password: ""

```

Then follow instructions to add the certificate as trusted for your browser and those errors will go away.

Let me know if this helps.

Adding another one of security experts @jportner for more info.

Thanks Joe for helping me understand it better.

@TheVintik hope this helps! Let us know.

---

<div class="post-metadata">

### Author: ![TheVintik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thevintik/32/60494_2.png) [@TheVintik](https://discuss.elastic.co/u/TheVintik)
#### Post date: [March 23, 2020, 11:46am UTC](https://discuss.elastic.co/t/how-to-enable-ssl-https-for-kibana/224161/8 "2020-03-23T11:46:07Z")

</div>

I found an error from my side.

When I worked on Kibana configuration, I was not sure about two things"

- does Kibana configured property?
- does my firewall configured property?

For except firewall issue I decided to use linux console web browser to check - does Kibana web page open or not. It worked well for HTTP protocol, but there were errors, described above when I tried to use HTTPS.

But, then I checked firewall rules again and fix it, my web browser opened Kibana fine.

So, it was linux console web browser issue. And, looks like all described above methods for SSL keys generate are good.

Thank you all for your help and time!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 20, 2020, 11:46am UTC](https://discuss.elastic.co/t/how-to-enable-ssl-https-for-kibana/224161/9 "2020-04-20T11:46:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
