# Kibana 7.1.0 -- Secure Communication Between Kibana and Browser -- Bad Decrypt Error

**URL:** https://discuss.elastic.co/t/kibana-7-1-0-secure-communication-between-kibana-and-browser-bad-decrypt-error/183406
**Category:** Kibana
**Tags:** elastic-stack-security
**Created:** [May 29, 2019, 7:07pm UTC](https://discuss.elastic.co/t/kibana-7-1-0-secure-communication-between-kibana-and-browser-bad-decrypt-error/183406 "2019-05-29T19:07:07Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![ShaqFanClub](https://avatars.discourse-cdn.com/v4/letter/s/b19c9b/32.png) [@ShaqFanClub](https://discuss.elastic.co/u/ShaqFanClub)
#### Post date: [May 29, 2019, 7:07pm UTC](https://discuss.elastic.co/t/kibana-7-1-0-secure-communication-between-kibana-and-browser-bad-decrypt-error/183406/1 "2019-05-29T19:07:07Z")

</div>

Hello,

I am attempting to set up TLS on my cluster. So far, I have secure communication between Logstash / Elasticsearch, the Elasticsearch nodes, and Elasticsearch / Kibana working without errors.

The last step is to secure the communication between Kibana and the browser, which is where I am running into errors. Specifically, verbose logging shows:

```auto
{"type":"log","@timestamp":"2019-05-29T17:51:03Z","tags":["debug","config"],"pid":23636,"message":"Marking config path as handled: server"}
{"type":"log","@timestamp":"2019-05-29T17:51:03Z","tags":["debug","http"],"pid":23636,"message":"registering route handler for [/core]"}
{"type":"log","@timestamp":"2019-05-29T17:51:03Z","tags":["debug","root"],"pid":23636,"message":"starting root"}
{"type":"log","@timestamp":"2019-05-29T17:51:03Z","tags":["debug","config"],"pid":23636,"message":"Marking config path as handled: logging"}
{"type":"log","@timestamp":"2019-05-29T17:51:03Z","tags":["debug","server"],"pid":23636,"message":"starting server"}
{"type":"log","@timestamp":"2019-05-29T17:51:03Z","tags":["debug","http","server"],"pid":23636,"message":"starting http server"}
{"type":"log","@timestamp":"2019-05-29T17:51:03Z","tags":["debug","root"],"pid":23636,"message":"shutting root down"}
{"type":"log","@timestamp":"2019-05-29T17:51:03Z","tags":["fatal","root"],"pid":23636,"message":"{ Error: error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt\n at Object.createSecureContext (_tls_common.js:134:17)\n at Server (_tls_wrap.js:870:27)\n at new Server (https.js:62:14)\n at Object.createServer (https.js:85:10)\n at module.exports.internals.Core._createListener (/usr/share/kibana/node_modules/hapi/lib/core.js:491:79)\n at new module.exports.internals.Core (/usr/share/kibana/node_modules/hapi/lib/core.js:112:30)\n at new module.exports (/usr/share/kibana/node_modules/hapi/lib/server.js:25:18)\n at Object.createServer (/usr/share/kibana/src/core/server/http/http_tools.js:75:20)\n at HttpServer.start (/usr/share/kibana/src/core/server/http/http_server.js:40:36)\n at HttpService.start (/usr/share/kibana/src/core/server/http/http_service.js:46:38)\n opensslErrorStack: ['error:0906A065:PEM routines:PEM_do_header:bad decrypt'] }"}

```

To create the CA and certs, I ran the following:

```auto
#CA
/usr/share/elasticsearch/bin/elasticsearch-certutil ca --pass foo --pem --out /etc/elasticsearch/certs/ca.zip
#CRT + KEY
/usr/share/elasticsearch/bin/elasticsearch-certutil cert --ca-cert /etc/elasticsearch/certs/ca/ca.crt --ca-key /etc/elasticsearch/certs/ca/ca.key --name serverName --dns serverName,serverName.domain.com --ip serverIPAddress --pass foo --pem --out /etc/elasticsearch/certs/cert.zip

```

My kibana.yml looks like this:

```auto
server.port: 5601
server.host: serverName

#Secure communication between Kibana and Elasticsearch
elasticsearch.hosts: ["https://serverName:9200"]
elasticsearch.ssl.certificateAuthorities: /etc/kibana/certs/ca/ca.crt
elasticsearch.ssl.verificationMode: certificate

#Secure communication between Kibana and Browser
server.ssl.enabled: true
server.ssl.certificate: /etc/kibana/certs/serverName/serverName.crt
server.ssl.key: /etc/kibana/certs/serverName/serverName.key

#Settings
elasticsearch.requestTimeout: 120000

#Test
#xpack.security.enabled: true
#xpack.security.audit.enabled: true
#xpack.security.sessionTimeout: 600000
#xpack.security.encryptionKey: "32_character_string"

logging.verbose: true

```

I have tried working through [this](https://www.elastic.co/guide/en/kibana/7.1/using-kibana-with-security.html) and [this](https://discuss.elastic.co/t/trouble-enabling-ssl-on-kibana/179383) while troubleshooting with no luck. I have a feeling it has to do with the certs, but I'm not sure.

Any ideas?

Thanks,  
Joe

---

<div class="post-metadata">

### Author: ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)
#### Post date: [May 29, 2019, 7:13pm UTC](https://discuss.elastic.co/t/kibana-7-1-0-secure-communication-between-kibana-and-browser-bad-decrypt-error/183406/2 "2019-05-29T19:13:46Z")

</div>

Hey @ShaqFanClub, you'll need to set `server.ssl.keyPassphrase: foo` in your `kibana.yml` as you're specifying the `--pass` option when generating the certificate and key.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 26, 2019, 7:13pm UTC](https://discuss.elastic.co/t/kibana-7-1-0-secure-communication-between-kibana-and-browser-bad-decrypt-error/183406/3 "2019-06-26T19:13:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
