# KIbana 7.6.2 with SSL

**URL:** https://discuss.elastic.co/t/kibana-7-6-2-with-ssl/232471
**Category:** Kibana
**Created:** [May 13, 2020, 3:27pm UTC](https://discuss.elastic.co/t/kibana-7-6-2-with-ssl/232471 "2020-05-13T15:27:55Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![jgarbora](https://avatars.discourse-cdn.com/v4/letter/j/9fc29f/32.png) [@jgarbora](https://discuss.elastic.co/u/jgarbora)
#### Post date: [May 13, 2020, 3:27pm UTC](https://discuss.elastic.co/t/kibana-7-6-2-with-ssl/232471/1 "2020-05-13T15:27:55Z")

</div>

I am trying to enable SSL in Kibana ... and I am getting:

`Error: 139959624402752:error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca:../deps/openssl/openssl/ssl/record/rec_layer_s3.c:1544:SSL alert number 48`

I created private key and CSR with:

`bin/elasticsearch-certutil csr -name kibana-server -dns kibana-dev.xxx.com`

My cert is hosted in Cloudflare ... so I am signing the CSR there.

this is my kibana config:

`server.ssl.enabled: true`  
`server.ssl.certificate: /opt/kibana-7.6.2-linux-x86_64/config/gen-with-es/kibana-server.crt`  
`server.ssl.key: /opt/kibana-7.6.2-linux-x86_64/config/gen-with-es/kibana-server.key`

I tried also add CA root as cloud flare suggest [here](https://support.cloudflare.com/hc/en-us/articles/115000479507)

`elasticsearch.ssl.certificateAuthorities: "/opt/kibana-7.6.2-linux-x86_64/config/origin_ca_rsa_root.pem"`

any thoughts ?

---

<div class="post-metadata">

### Author: ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)
#### Post date: [May 13, 2020, 7:42pm UTC](https://discuss.elastic.co/t/kibana-7-6-2-with-ssl/232471/2 "2020-05-13T19:42:52Z")

</div>

The ssl error should not be a problem. What is the error when trying to access from the browser or via curl?

Also, the `elasticsearch.ssl*` settings are related to the connection of Kibana to Elasticsearch.  
The `elasticsearch.ssl.certificateAuthorities` is required to trust the connections to Elasticsearch from the Kibana server.

The settings `server.ssl.*` are to enable SSL on the Kibana server when connecting from the browser.

Can you try:

```auto
curl -vvvv https://kibanahost:kibanaport -u elastic:yourpassword --cacert theCaCertUsedForKibanaCerts.crt

```

Then the same command with the parameter `-k` and post the output (hide sensible data).

---

<div class="post-metadata">

### Author: ![jgarbora](https://avatars.discourse-cdn.com/v4/letter/j/9fc29f/32.png) [@jgarbora](https://discuss.elastic.co/u/jgarbora)
#### Post date: [May 13, 2020, 8:34pm UTC](https://discuss.elastic.co/t/kibana-7-6-2-with-ssl/232471/3 "2020-05-13T20:34:00Z")

</div>

just found it !

Cloudfare Orgin Certificates only works with proxied connections ! And proxy was disabled ...

thank you for you response @Luca_Belluccini

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 10, 2020, 8:34pm UTC](https://discuss.elastic.co/t/kibana-7-6-2-with-ssl/232471/4 "2020-06-10T20:34:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
