# Kibana 6.2 fails to start, ValidationError, child xpack, child security fails because “http” is not allowed

**URL:** <https://discuss.elastic.co/t/kibana-6-2-fails-to-start-validationerror-child-xpack-child-security-fails-because-http-is-not-allowed/121899>\
**Category:** Kibana\
**Created:** [February 28, 2018, 4:52pm UTC](https://discuss.elastic.co/t/kibana-6-2-fails-to-start-validationerror-child-xpack-child-security-fails-because-http-is-not-allowed/121899 "2018-02-28T16:52:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [February 28, 2018, 4:52pm UTC](https://discuss.elastic.co/t/kibana-6-2-fails-to-start-validationerror-child-xpack-child-security-fails-because-http-is-not-allowed/121899/1 "2018-02-28T16:52:21Z")

</div>

Have little to no Linux nor ELK knowledge and am moving into the position of owning ELK. The previous owner is helping me, and I'm trying to figure this out on my own. This one has me stumped?

I believe that I have setup xpack to use TLS in the elasticsearch & kibana YMLs, but obviously it's not working. Since I am so new to this, wondering if I'm just missing something here?

**Kibana Log Error:**

```
{
	"type": "error",
	"@timestamp": "2018-02-18T08:39:38-05:00",
	"tags": ["fatal"],
	"pid": 7566,
	"level": "fatal",
	"error": {
		"message": "child \"xpack\" fails because [child \"security\" fails because [\"http\" is not allowed]]",
		"name": "ValidationError",
		"stack": "ValidationError: child \"xpack\" fails because [child \"security\" fails because [\"http\" is not allowed]]\n at Object.exports.process (/usr/share/kibana/node_modules/joi/lib/errors.js:181:19)\n at _validateWithOptions (/usr/share/kibana/node_modules/joi/lib/any.js:651:31)\n at root.validate (/usr/share/kibana/node_modules/joi/lib/index.js:121:23)\n at Config._commit (/usr/share/kibana/src/server/config/config.js:119:35)\n at Config.set (/usr/share/kibana/src/server/config/config.js:89:10)\n at Config.extendSchema (/usr/share/kibana/src/server/config/config.js:62:10)\n at /usr/share/kibana/src/plugin_discovery/plugin_config/extend_config_service.js:22:12\n at next (native)\n at step (/usr/share/kibana/src/plugin_discovery/plugin_config/extend_config_service.js:45:191)\n at /usr/share/kibana/src/plugin_discovery/plugin_config/extend_config_service.js:45:361"
	},
	"message": "child \"xpack\" fails because [child \"security\" fails because [\"http\" is not allowed]]"
}

```

RHEL 7, ELK 30 day trial, Kibana 6.2 with Xpack 6.2, ElasctSearch 6.2 with Xpack 6.2

The ElasticSearch nodes are up and green.

YML entries are "sanitized", but are in the order they appear in the "live" files.

**kibana.yml**

```
server.port: 5601

server.host: 2.2.2.2

elasticsearch.url: "https://2.2.2.2:9200"

elasticsearch.username: "kibana"
elasticsearch.password: "kibana"

elasticsearch.ssl.certificateAuthorities: /etc/kibana/elastic-stack-ca.p12
elasticsearch.ssl.enabled: true
elasticsearch.ssl.verificationMode: certificate
elasticsearch.ssl.certificate: elastic-stack-ca..p12
elasticsearch.ssl.key: elastic-stack-ca..p12

xpack.security.enabled: false

xpack.security.encryptionKey: "SomethingOver36Charachters0123456789012345"

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: /etc/kibana/elastic-stack-ca..p12
xpack.security.http.ssl.truststore.path: /etc/kibana/elastic-stack-ca..p12
xpack.ssl.verification_mode: certificate

elasticsearch.requestTimeout: 60000

```

**elasticsearch.yml**

```
node.name: ${HOSTNAME}
node.master: true
node.data: true
node.ingest: true
cluster.name: uatelk
discovery.zen.ping.unicast.hosts: ["2.2.2.2", "2.2.2.12", "2.2.2.13", "2.2.2.14"]

xpack.security.transport.ssl.keystore.path: elastic-stack-ca.p12
xpack.security.transport.ssl.truststore.path: elastic-stack-ca.p12

xpack.security.transport.ssl.enabled: true 
xpack.security.transport.ssl.verification_mode: certificate 

xpack.security.enabled: false 
xpack.security.http.ssl.enabled: true 
xpack.security.http.ssl.keystore.path: elastic-stack-ca.p12 
xpack.security.http.ssl.truststore.path: elastic-stack-ca.p12 

network.host: 2.2.2.2 

http.port: 9200
```

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 28, 2018, 6:43pm UTC](https://discuss.elastic.co/t/kibana-6-2-fails-to-start-validationerror-child-xpack-child-security-fails-because-http-is-not-allowed/121899/2 "2018-02-28T18:43:36Z")

</div>

> [@JimP](#):
>
> xpack.security.http.ssl.enabled: true  
> xpack.security.http.ssl.keystore.path: /etc/kibana/elastic-stack-ca..p12  
> xpack.security.http.ssl.truststore.path: /etc/kibana/elastic-stack-ca..p12  
> xpack.ssl.verification\_mode: certificate

I don't believe these should be in your kibana configuration file. Where did they come from?

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [March 7, 2018, 11:22am UTC](https://discuss.elastic.co/t/kibana-6-2-fails-to-start-validationerror-child-xpack-child-security-fails-because-http-is-not-allowed/121899/3 "2018-03-07T11:22:38Z")

</div>

Thank you. That was the last version I had tried. I'm going to uninstall kibana-xpack. Get kibana working, then install xpack, again. Making sure not to put in those entries.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2018, 11:22am UTC](https://discuss.elastic.co/t/kibana-6-2-fails-to-start-validationerror-child-xpack-child-security-fails-because-http-is-not-allowed/121899/4 "2018-04-04T11:22:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
