# Issue with SSL

**URL:** https://discuss.elastic.co/t/issue-with-ssl/374657
**Category:** Kibana
**Created:** [February 17, 2025, 7:09pm UTC](https://discuss.elastic.co/t/issue-with-ssl/374657 "2025-02-17T19:09:42Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![arcsons](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@arcsons](https://discuss.elastic.co/u/arcsons)
#### Post date: [February 17, 2025, 7:09pm UTC](https://discuss.elastic.co/t/issue-with-ssl/374657/1 "2025-02-17T19:09:42Z")

</div>

Hello,

I'm encountering problems while configuring SSL certificates for HTTPS. I've attempted the setup, but I've run into some issues.

I have configuration files, status reports, and logs available that I believe are relevant to the problem. I would appreciate assistance in resolving these issues.

kibana.yml:  
server.ssl.enabled: true  
server.ssl.certificate: /etc/kibana/certs/elastic\_client\_cert.pem  
server.ssl.key: /etc/kibana/certs/elastic\_client\_cert.key  
server.ssl.certificateAuthorities: ["/etc/kibana/certs/elastic\_ca\_cert.pem"]

sudo chmod 600 /etc/kibana/certs/elastic\_client\_cert.key  
sudo chmod 600 /etc/kibana/certs/elastic\_client\_cert.pem  
sudo chmod 644 /etc/kibana/certs/elasticsearch-ca.pem

sudo chown kibana:kibana /etc/kibana/certs/elasticsearch-ca.pem  
sudo chown kibana:kibana /etc/kibana/certs/elastic\_client\_cert.key  
sudo chown kibana:kibana /etc/kibana/certs/elastic\_client\_cert.pem

sudo systemctl status kibana

Feb 17 19:49:15 test.local systemd[1]: kibana.service: Scheduled restart job, restart counter is at 2.  
Feb 17 19:49:15 test.local systemd[1]: Started kibana.service - Kibana.  
Feb 17 19:49:15 test.local kibana[2359845]: Kibana is currently running with legacy OpenSSL providers enabled! For details and instructions on how to disable see [Use Kibana in a production environment | Kibana Guide [8.15] | Elastic](https://www.elastic.co/guide/en/kibana/8.15/production.html#o)\>  
Feb 17 19:49:15 test.local kibana[2359845]: {"log.level":"info","@timestamp":"2025-02-17T18:49:15.874Z","log.logger":"elastic-apm-node","ecs.version":"8.10.0","agentVersion":"4.7.0","env":{"pid":2359845,"proctitle":"/usr/sh\>  
Feb 17 19:49:15 test.local kibana[2359845]: Native global console methods have been overridden in production environment.

$ sudo systemctl status kibana  
× kibana.service - Kibana  
Loaded: loaded (/usr/lib/systemd/system/kibana.service; enabled; preset: enabled)  
Active: failed (Result: exit-code) since Mon 2025-02-17 19:49:24 CET; 1min 35s ago  
Duration: 5.804s  
Docs: [https://www.elastic.co](https://www.elastic.co)  
Process: 2359845 ExecStart=/usr/share/kibana/bin/kibana (code=exited, status=1/FAILURE)  
Main PID: 2359845 (code=exited, status=1/FAILURE)  
CPU: 7.032s

Feb 17 19:49:24 test.local systemd[1]: kibana.service: Scheduled restart job, restart counter is at 3.  
Feb 17 19:49:24 test.local systemd[1]: kibana.service: Start request repeated too quickly.  
Feb 17 19:49:24 test.local systemd[1]: kibana.service: Failed with result 'exit-code'.  
Feb 17 19:49:24 test.local systemd[1]: Failed to start kibana.service - Kibana.  
Feb 17 19:49:24 test.local systemd[1]: kibana.service: Consumed 7.032s CPU time, 253.7M memory peak, 0B memory swap peak.

kibana.log:

{"service":{"node":{"roles":["background\_tasks","ui"]}},"ecs":{"version":"8.11.0"},"@timestamp":"2025-02-17T20:02:30.848+01:00","message":"Reason: error:1C800064:Provider routines::bad decrypt\nError: error:1C800064:Provider routines::bad decrypt\n at setKey (node:internal/tls/secure-context:93:11)\n at configSecureContext (node:internal/tls/secure-context:204:7)\n at Object.createSecureContext (node:\_tls\_common:116:3)\n at Server.setSecureContext (node:\_tls\_wrap:1486:27)\n at Server (node:\_tls\_wrap:1350:8)\n at new Server (node:https:75:3)\n at Object.createServer (node:https:133:10)\n at configureHttp1Listener (/usr/share/kibana/node\_modules/@kbn/server-http-tools/src/get\_listener.js:29:44)\n at getServerListener (/usr/share/kibana/node\_modules/@kbn/server-http-tools/src/get\_listener.js:22:63)\n at getServerOptions (/usr/share/kibana/node\_modules/@kbn/server-http-tools/src/get\_server\_options.js:35:51)\n at HttpServer.setup (/usr/share/kibana/node\_modules/@kbn/core-http-server-internal/src/http\_server.js:142:65)\n at HttpService.preboot (/usr/share/kibana/node\_modules/@kbn/core-http-server-internal/src/http\_service.js:62:26)\n at Server.preboot (/usr/share/kibana/node\_modules/@kbn/core-root-server-internal/src/server.js:194:27)\n at Root.preboot (/usr/share/kibana/node\_modules/@kbn/core-root-server-internal/src/root/index.js:47:14)\n at bootstrap (/usr/share/kibana/node\_modules/@kbn/core-root-server-internal/src/bootstrap.js:95:29)\n at Command. (/usr/share/kibana/src/cli/serve/serve.js:233:5)","log":{"level":"FATAL","logger":"root"},"process":{"pid":2360395,"uptime":5.873129091},"trace":{"id":"5fa606ca0c272c04ce1e70803f6d230c"},"transaction":{"id":"3c299e6de33a4596"}}  
{"service":{"node":{"roles":["background\_tasks","ui"]}},"ecs":{"version":"8.11.0"},"@timestamp":"2025-02-17T20:02:39.933+01:00","message":"Reason: error:1C800064:Provider routines::bad decrypt\nError: error:1C800064:Provider routines::bad decrypt\n at setKey (node:internal/tls/secure-context:93:11)\n at configSecureContext (node:internal/tls/secure-context:204:7)\n at Object.createSecureContext (node:\_tls\_common:116:3)\n at Server.setSecureContext (node:\_tls\_wrap:1486:27)\n at Server (node:\_tls\_wrap:1350:8)\n at new Server (node:https:75:3)\n at Object.createServer (node:https:133:10)\n at configureHttp1Listener (/usr/share/kibana/node\_modules/@kbn/server-http-tools/src/get\_listener.js:29:44)\n at getServerListener (/usr/share/kibana/node\_modules/@kbn/server-http-tools/src/get\_listener.js:22:63)\n at getServerOptions (/usr/share/kibana/node\_modules/@kbn/server-http-tools/src/get\_server\_options.js:35:51)\n at HttpServer.setup (/usr/share/kibana/node\_modules/@kbn/core-http-server-internal/src/http\_server.js:142:65)\n at HttpService.preboot (/usr/share/kibana/node\_modules/@kbn/core-http-server-internal/src/http\_service.js:62:26)\n at Server.preboot (/usr/share/kibana/node\_modules/@kbn/core-root-server-internal/src/server.js:194:27)\n at Root.preboot (/usr/share/kibana/node\_modules/@kbn/core-root-server-internal/src/root/index.js:47:14)\n at bootstrap (/usr/share/kibana/node\_modules/@kbn/core-root-server-internal/src/bootstrap.js:95:29)\n at Command. (/usr/share/kibana/src/cli/serve/serve.js:233:5)","log":{"level":"FATAL","logger":"root"},"process":{"pid":2360417,"uptime":5.786669326},"trace":{"id":"12ad339c5584eb6904d082725a51a745"},"transaction":{"id":"95b59fc2ad298d2c"}}  
{"service":{"node":{"roles":["background\_tasks","ui"]}},"ecs":{"version":"8.11.0"},"@timestamp":"2025-02-17T20:02:48.941+01:00","message":"Reason: error:1C800064:Provider routines::bad decrypt\nError: error:1C800064:Provider routines::bad decrypt\n at setKey (node:internal/tls/secure-context:93:11)\n at configSecureContext (node:internal/tls/secure-context:204:7)\n at Object.createSecureContext (node:\_tls\_common:116:3)\n at Server.setSecureContext (node:\_tls\_wrap:1486:27)\n at Server (node:\_tls\_wrap:1350:8)\n at new Server (node:https:75:3)\n at Object.createServer (node:https:133:10)\n at configureHttp1Listener (/usr/share/kibana/node\_modules/@kbn/server-http-tools/src/get\_listener.js:29:44)\n at getServerListener (/usr/share/kibana/node\_modules/@kbn/server-http-tools/src/get\_listener.js:22:63)\n at getServerOptions (/usr/share/kibana/node\_modules/@kbn/server-http-tools/src/get\_server\_options.js:35:51)\n at HttpServer.setup (/usr/share/kibana/node\_modules/@kbn/core-http-server-internal/src/http\_server.js:142:65)\n at HttpService.preboot (/usr/share/kibana/node\_modules/@kbn/core-http-server-internal/src/http\_service.js:62:26)\n at Server.preboot (/usr/share/kibana/node\_modules/@kbn/core-root-server-internal/src/server.js:194:27)\n at Root.preboot (/usr/share/kibana/node\_modules/@kbn/core-root-server-internal/src/root/index.js:47:14)\n at bootstrap (/usr/share/kibana/node\_modules/@kbn/core-root-server-internal/src/bootstrap.js:95:29)\n at Command. (/usr/share/kibana/src/cli/serve/serve.js:233:5)","log":{"level":"FATAL","logger":"root"},"process":{"pid":2360446,"uptime":5.790623256},"trace":{"id":"5b3c095f9face624907490180bdbcb29"},"transaction":{"id":"610ac96cc8507014"}}

---

<div class="post-metadata">

### Author: ![arcsons](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@arcsons](https://discuss.elastic.co/u/arcsons)
#### Post date: [February 20, 2025, 8:08am UTC](https://discuss.elastic.co/t/issue-with-ssl/374657/2 "2025-02-20T08:08:22Z")

</div>

Now after I added this line  
server.ssl.keyPassphrase: "password"  
So can Kibana starts.

But when I surf to [https://ip:5601](https://ip:5601) I can see the certificate but it still says the connection is not "Connection not secure".

Any idea what could be missing or how to troubleshoot further?

---

<div class="post-metadata">

### Author: ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)
#### Post date: [February 20, 2025, 10:05am UTC](https://discuss.elastic.co/t/issue-with-ssl/374657/3 "2025-02-20T10:05:37Z")

</div>

Hi @arcsons,

Which version of Elasticsearch and Kibana are you using? For 8.x you should be able to follow the enrollment steps [here](https://www.elastic.co/guide/en/elasticsearch/reference/8.17/configuring-stack-security.html) without needing to generate the configuration yourself. Did you generate the certs yourself using [elasticsearch-certutil](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup-https.html)?

Let us know!

---

<div class="post-metadata">

### Author: ![arcsons](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@arcsons](https://discuss.elastic.co/u/arcsons)
#### Post date: [February 20, 2025, 10:37am UTC](https://discuss.elastic.co/t/issue-with-ssl/374657/4 "2025-02-20T10:37:50Z")

</div>

Hi Charly,  
I just did tested with the FQDN and it worked. I got the certificates from the Windows team which handle the CA.  
How but now I need to figure out how to protect the password in the kibana.yml. But can I do with the keystore thing I guess?

---

<div class="post-metadata">

### Author: ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)
#### Post date: [February 20, 2025, 12:00pm UTC](https://discuss.elastic.co/t/issue-with-ssl/374657/5 "2025-02-20T12:00:53Z")

</div>

Yes using the keystore is the right way to go:

> **[Secure settings | Kibana Guide \[8.17\] | Elastic](https://www.elastic.co/guide/en/kibana/current/secure-settings.html)**

---

<div class="post-metadata">

### Author: ![arcsons](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@arcsons](https://discuss.elastic.co/u/arcsons)
#### Post date: [February 21, 2025, 7:10am UTC](https://discuss.elastic.co/t/issue-with-ssl/374657/6 "2025-02-21T07:10:46Z")

</div>

Perfect, working. Case closed. Thanks
