# How to setup https for kibana?

**URL:** https://discuss.elastic.co/t/how-to-setup-https-for-kibana/287383
**Category:** Kibana
**Tags:** elastic-stack-security
**Created:** [October 22, 2021, 4:11am UTC](https://discuss.elastic.co/t/how-to-setup-https-for-kibana/287383 "2021-10-22T04:11:46Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![nhattanmai](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nhattanmai/32/82550_2.png) [@nhattanmai](https://discuss.elastic.co/u/nhattanmai)
#### Post date: [October 22, 2021, 4:11am UTC](https://discuss.elastic.co/t/how-to-setup-https-for-kibana/287383/1 "2021-10-22T04:11:46Z")

</div>

Hi all,  
Sorry about my bad English. I'm config https following the guide:

> **[Set up basic security for the Elastic Stack plus secured HTTPS traffic |...](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup-https.html)**

I generated a server certificate and private key for Kibana:

```auto
./bin/elasticsearch-certutil csr -name kibana-server MY_IP_SERVER

```

Kibana setting is:

```auto
server.host: "0.0.0.0"
server.ssl.enabled: true
server.ssl.certificate: /etc/kibana/kibana-server.csr
server.ssl.key: /etc/kibana/kibana-server.key

```

I got the error:

```auto
 kibana.service - Kibana
   Loaded: loaded (/etc/systemd/system/kibana.service; enabled; vendor preset: disabled)
   Active: failed (Result: start-limit) since Fri 2021-10-22 10:31:39 +07; 1min 5s ago
     Docs: https://www.elastic.co
  Process: 6171 ExecStart=/usr/share/kibana/bin/kibana --logging.dest="/var/log/kibana/kibana.log" --pid.file="/run/kibana/kibana.pid" (code=exited, status=1/FAILURE)
 Main PID: 6171 (code=exited, status=1/FAILURE)

Oct 22 10:31:36 centos-elk systemd[1]: kibana.service: main process exited, code=exited, status=1/FAILURE
Oct 22 10:31:36 centos-elk systemd[1]: Unit kibana.service entered failed state.
Oct 22 10:31:36 centos-elk systemd[1]: kibana.service failed.
Oct 22 10:31:39 centos-elk systemd[1]: kibana.service holdoff time over, scheduling restart.
Oct 22 10:31:39 centos-elk systemd[1]: Stopped Kibana.
Oct 22 10:31:39 centos-elk systemd[1]: start request repeated too quickly for kibana.service
Oct 22 10:31:39 centos-elk systemd[1]: Failed to start Kibana.
Oct 22 10:31:39 centos-elk systemd[1]: Unit kibana.service entered failed state.
Oct 22 10:31:39 centos-elk systemd[1]: kibana.service failed.

```

Please help me, thank you!

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [October 25, 2021, 3:55am UTC](https://discuss.elastic.co/t/how-to-setup-https-for-kibana/287383/2 "2021-10-25T03:55:17Z")

</div>

Welcome to our community! 😃

Can you please check the Kibana logs under `/var/log/kibana/kibana.log` as it will contain more information on what is happening.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [October 25, 2021, 5:47am UTC](https://discuss.elastic.co/t/how-to-setup-https-for-kibana/287383/3 "2021-10-25T05:47:22Z")

</div>

> [@nhattanmai](#):
>
> I generated a server certificate and private key for Kibana:
> 
> ```auto
> ./bin/elasticsearch-certutil csr -name kibana-server MY_IP_SERVER
> 
> ```

That does not create a cert that creates a CSR a certificate signing request which you send to a certificate authority like Let's Encrypt create and actual certificate.

> The following instructions create a Certificate Signing Request (CSR) for Kibana. A CSR contains information that a CA uses to generate and sign a security certificate

> 1. Send the `kibana-server.csr` certificate signing request to your internal CA or trusted CA for signing to obtain a signed certificate. The signed file can be in different formats, such as a `.crt` file like `kibana-server.crt` .

So that's not going to work.

You need to create a cert with the cert util you need to use the `cert` mode not `csr` mode see [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/certutil.html#certutil-cert)

I have an example here If you are putting both elasticsearch and Kibana on the same host.

[https://github.com/bvader/howtos/blob/master/basic-security-elasticsearch/README.md](https://github.com/bvader/howtos/blob/master/basic-security-elasticsearch/README.md)

---

<div class="post-metadata">

### Author: ![nhattanmai](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nhattanmai/32/82550_2.png) [@nhattanmai](https://discuss.elastic.co/u/nhattanmai)
#### Post date: [October 26, 2021, 6:48am UTC](https://discuss.elastic.co/t/how-to-setup-https-for-kibana/287383/4 "2021-10-26T06:48:49Z")

</div>

Thank you @stephenb, it worked. I generated certificates:

```auto
cd /etc/elasticsearch/
openssl pkcs12 -in elastic-certificates.p12 -out newfile.crt.pem -clcerts -nokeys
openssl pkcs12 -in elastic-certificates.p12 -out newfile.key.pem -nocerts -nodes

```

And config in kibana.yml:

```auto
server.ssl.enabled: true
server.ssl.certificate: /etc/kibana/newfile.crt.pem
server.ssl.key: /etc/kibana/newfile.key.pem
elasticsearch.ssl.verificationMode: none

```

Everything is okie. Thank you again!

---

<div class="post-metadata">

### Author: ![nhattanmai](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nhattanmai/32/82550_2.png) [@nhattanmai](https://discuss.elastic.co/u/nhattanmai)
#### Post date: [November 1, 2021, 8:36am UTC](https://discuss.elastic.co/t/how-to-setup-https-for-kibana/287383/5 "2021-11-01T08:36:08Z")

</div>

Hello @stephenb,  
I have a problem with email connector. I read the guide

> **[Email connector and action | Kibana Guide \[7.15\] | Elastic](https://www.elastic.co/guide/en/kibana/7.15/email-action-type.html)**

But I am not clear with the guide. I don't where to config email connector (maybe kibana.yml). How can I create Gmail connector to send mail when have a alert?  
Thank you!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 29, 2021, 8:36am UTC](https://discuss.elastic.co/t/how-to-setup-https-for-kibana/287383/6 "2021-11-29T08:36:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
