# How to set SSL certificate and key in kibana.yml?

**URL:** https://discuss.elastic.co/t/how-to-set-ssl-certificate-and-key-in-kibana-yml/168213
**Category:** Kibana
**Created:** [February 13, 2019, 12:46pm UTC](https://discuss.elastic.co/t/how-to-set-ssl-certificate-and-key-in-kibana-yml/168213 "2019-02-13T12:46:33Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![li\_jessen2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/li_jessen2016/32/38817_2.png) [@li\_jessen2016](https://discuss.elastic.co/u/li_jessen2016)
#### Post date: [February 13, 2019, 12:46pm UTC](https://discuss.elastic.co/t/how-to-set-ssl-certificate-and-key-in-kibana-yml/168213/1 "2019-02-13T12:46:33Z")

</div>

in Kibana.yml, there are:  
#Optional settings that provide the paths to the PEM-format SSL certificate and key files.  
#These files validate that your Elasticsearch backend uses the same key files.  
elasticsearch.ssl.certificate:  
elasticsearch.ssl.key:

1. What does " validate that your Elasticsearch backend uses the same key files." mean? Does it mean the certificate and key to be set there are the same as the ones used for elasticsearch node?

2. It said that "Optional settings". Then when must we set it?

---

<div class="post-metadata">

### Author: ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)
#### Post date: [February 14, 2019, 6:46pm UTC](https://discuss.elastic.co/t/how-to-set-ssl-certificate-and-key-in-kibana-yml/168213/2 "2019-02-14T18:46:05Z")

</div>

Are you looking to serve kibana over https or pass a certificate and key to elasticsearch? The comment is referring to passing certificates along with each request to elasticsearch, and elasticsearch is configured to only accept requests that have these certificates. It's not a common workflow until we support full PKI - [https://github.com/elastic/kibana/issues/7341](https://github.com/elastic/kibana/issues/7341).

Is it possible we want server.ssl.certificate/server.ssl.key?

---

<div class="post-metadata">

### Author: ![li\_jessen2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/li_jessen2016/32/38817_2.png) [@li\_jessen2016](https://discuss.elastic.co/u/li_jessen2016)
#### Post date: [February 15, 2019, 7:40am UTC](https://discuss.elastic.co/t/how-to-set-ssl-certificate-and-key-in-kibana-yml/168213/3 "2019-02-15T07:40:59Z")

</div>

So you mean that normally we don't need to do this?

---

<div class="post-metadata">

### Author: ![li\_jessen2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/li_jessen2016/32/38817_2.png) [@li\_jessen2016](https://discuss.elastic.co/u/li_jessen2016)
#### Post date: [February 16, 2019, 7:14am UTC](https://discuss.elastic.co/t/how-to-set-ssl-certificate-and-key-in-kibana-yml/168213/4 "2019-02-16T07:14:26Z")

</div>

Yes, I tried, it is not necessary.

---

<div class="post-metadata">

### Author: ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)
#### Post date: [February 20, 2019, 12:52am UTC](https://discuss.elastic.co/t/how-to-set-ssl-certificate-and-key-in-kibana-yml/168213/5 "2019-02-20T00:52:48Z")

</div>

Correct, typically not necessary.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 20, 2019, 12:52am UTC](https://discuss.elastic.co/t/how-to-set-ssl-certificate-and-key-in-kibana-yml/168213/6 "2019-03-20T00:52:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
