# Http client did not trust this server's certificate from the browser

**URL:** https://discuss.elastic.co/t/http-client-did-not-trust-this-servers-certificate-from-the-browser/200254
**Category:** Elasticsearch
**Tags:** elastic-stack-security
**Created:** [September 19, 2019, 3:30pm UTC](https://discuss.elastic.co/t/http-client-did-not-trust-this-servers-certificate-from-the-browser/200254 "2019-09-19T15:30:55Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![NNN](https://avatars.discourse-cdn.com/v4/letter/n/58f4c7/32.png) [@NNN](https://discuss.elastic.co/u/NNN)
#### Post date: [September 19, 2019, 3:30pm UTC](https://discuss.elastic.co/t/http-client-did-not-trust-this-servers-certificate-from-the-browser/200254/1 "2019-09-19T15:30:55Z")

</div>

Hello,

SSL does not work when I try to access [https://localhost:9200](https://localhost:9200) from the browser  
I get  
: http client did not trust this server's certificate, closing connection

my elasticsearch.yml

xpack.security.enabled : true  
xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.key: instance.key  
xpack.security.transport.ssl.certificate: instance.crt  
xpack.security.transport.ssl.certificate\_authorities: ["ca.crt"]  
xpack.security.http.ssl.enabled: true  
xpack.security.http.ssl.key: instance.key  
xpack.security.http.ssl.certificate: instance.crt  
xpack.security.http.ssl.certificate\_authorities: ["ca.crt"]

I generated the certificates with .elasticsearch-certutil (pem format)

---

<div class="post-metadata">

### Author: ![MiTschMR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mitschmr/32/48254_2.png) [@MiTschMR](https://discuss.elastic.co/u/MiTschMR)
#### Post date: [September 23, 2019, 7:19am UTC](https://discuss.elastic.co/t/http-client-did-not-trust-this-servers-certificate-from-the-browser/200254/2 "2019-09-23T07:19:34Z")

</div>

Hi @NNN

First of all, what version of Elasticsearch are you using? Then, did you include "localhost" as a SAN (Subject Alternative Name) when you created the certificate?

MiTschMR

---

<div class="post-metadata">

### Author: ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)
#### Post date: [September 23, 2019, 10:27am UTC](https://discuss.elastic.co/t/http-client-did-not-trust-this-servers-certificate-from-the-browser/200254/3 "2019-09-23T10:27:20Z")

</div>

> [@NNN](#):
>
> SSL does not work when I try to access [https://localhost:9200](https://localhost:9200) from the browser  
> I get  
> : http client did not trust this server's certificate, closing connection

This is expected. You are using an SSL certificate that was generated with `elasticsearch-certutil` and singed by a custom local CA which, as expected, is not trusted by your browser. Most browsers will allow you to add an exception for this certificate so that you can bypass this warning and access your Elasticsearch node on localhost over https.

This is fine for a dev environment on localhost.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 21, 2019, 10:27am UTC](https://discuss.elastic.co/t/http-client-did-not-trust-this-servers-certificate-from-the-browser/200254/4 "2019-10-21T10:27:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
