# Kibana cannot connect to Elasticsearch after enabling SSL/TLS

**URL:** <https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201>\
**Category:** Kibana\
**Tags:** elastic-stack-security, docker\
**Created:** [August 7, 2019, 9:53am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201 "2019-08-07T09:53:26Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![saifat29](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@saifat29](https://discuss.elastic.co/u/saifat29)\
**Post date:** [August 7, 2019, 9:53am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/1 "2019-08-07T09:53:26Z")

</div>

I am running a two node ES cluster and a single Kibana instance using Docker Swarm,  
everything worked fine before enabling SSL/TLS on the ES nodes.

I am using same certificate without hostname verification for all the ES nodes and everything works perfect for the ES nodes. The only problem is that Kibana is not able to connect to ES cluster.  
I am using the same certificate for all the ES instances and for Kibana too.

Following is my **docker-compose.yml** -

```
version: "3.2"
services:
  elasticsearch:
    image: docker.elastic.co/elasticsearch/elasticsearch:7.2.0
    restart: always
    environment:
      - node.name={{.Node.Hostname}}
      - discovery.seed_hosts=elasticsearch
      - cluster.name=docker-cluster
      - cluster.initial_master_nodes=node1,node2
      - network.host=0.0.0.0
      - bootstrap.memory_lock=true
      - "ES_JAVA_OPTS=-Xms3g -Xmx3g"
      - "ELASTIC_PASSWORD=myespassword"
      - xpack.license.self_generated.type=basic
      - xpack.security.enabled=true
      - xpack.security.http.ssl.enabled=true
      - xpack.security.http.ssl.key=$CERTS_DIR/elasticsearch/elasticsearch.key
      - xpack.security.http.ssl.certificate_authorities=$CERTS_DIR/ca/ca.crt
      - xpack.security.http.ssl.certificate=$CERTS_DIR/elasticsearch/elasticsearch.crt
      - xpack.security.transport.ssl.enabled=true
      - xpack.security.transport.ssl.verification_mode=certificate
      - xpack.security.transport.ssl.certificate_authorities=$CERTS_DIR/ca/ca.crt
      - xpack.security.transport.ssl.certificate=$CERTS_DIR/elasticsearch/elasticsearch.crt
      - xpack.security.transport.ssl.key=$CERTS_DIR/elasticsearch/elasticsearch.key
    secrets:
      - source: es_ssl_key
        target: $CERTS_DIR/elasticsearch/elasticsearch.key
      - source: es_ssl_ca
        target: $CERTS_DIR/ca/ca.crt
      - source: es_ssl_crt
        target: $CERTS_DIR/elasticsearch/elasticsearch.crt
    ulimits:
      memlock:
        soft: -1
        hard: -1
    deploy:
      mode: replicated
      replicas: 1
    ports:
      - "9200:9200"
      - "9300:9300"
    volumes:
      - es_data:/usr/share/elasticsearch/data

  kibana:
    image: docker.elastic.co/kibana/kibana:7.2.0
    restart: always
    environment:
      - "SERVER_NAME=kibana"
      - "ELASTICSEARCH_HOSTS=https://elasticsearch:9200"
      - "XPACK_SECURITY_ENABLED=true"
      - "ELASTICSEARCH_USERNAME=kibana"
      - "ELASTICSEARCH_PASSWORD=mykbpassword"
      - elasticsearch.ssl.certificateAuthorities=$CERTS_DIR/ca/ca.crt
      - elasticsearch.ssl.verificationMode=certificate
    secrets:
      - source: es_ssl_ca
        target: $CERTS_DIR/ca/ca.crt
    ports:
      - "5601:5601"
    depends_on:
      - elasticsearch

secrets:
  es_ssl_key:
    file: ./es_certs/elasticsearch/elasticsearch.key
  es_ssl_ca:
    file: ./es_certs/ca/ca.crt
  es_ssl_crt:
    file: ./es_certs/elasticsearch/elasticsearch.crt

volumes:
  es_data:

```

I am using same certificate for all the ES nodes and Kibana generated using the following  
**create-certs.yml** -

```
version: "2.2"
services:
  create_certs:
    container_name: create_certs
    image: docker.elastic.co/elasticsearch/elasticsearch:7.2.0
    command: >
      bash -c '
        yum install -y -q -e 0 unzip;
        if [[! -f /certs/bundle.zip]]; then
          bin/elasticsearch-certutil cert --silent --pem --in config/certificates/instances.yml -out /certs/bundle.zip;
          unzip /certs/bundle.zip -d /certs;
        fi;
        chown -R 1000:0 /certs '
    user: "0"
    working_dir: /usr/share/elasticsearch
    volumes:
      - ./es_certs:/certs
      - .:/usr/share/elasticsearch/config/certificates

```

**instances.yml**

```
instances:
  - name: elasticsearch
    dns:
      - elasticsearch
      - localhost
    ip:
      - 127.0.0.1

```

I am able to successfully perform a **curl** call from inside of the Kibana container to the **https** Elasticsearch endpoint using the following command-

`curl --cacert ca.crt -u kibana:mykbpassword https://elasticsearch:9200`

However normally Kibana cannot connect to the ES nodes and I receive the following logs-

```
es_stack_kibana.1.bl9aozgf1b0z@node1 | {"type":"log","@timestamp":"2019-08-07T09:46:12Z","tags":["error","elasticsearch","admin"],"pid":1,"message":"Request error, retrying\nGET https://elasticsearch:9200/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip => connect ECONNREFUSED 10.0.3.2:9200"}
es_stack_kibana.1.bl9aozgf1b0z@node1 | {"type":"log","@timestamp":"2019-08-07T09:46:12Z","tags":["warning","elasticsearch","admin"],"pid":1,"message":"Unable to revive connection: https://elasticsearch:9200/"}
es_stack_kibana.1.bl9aozgf1b0z@node1 | {"type":"log","@timestamp":"2019-08-07T09:46:12Z","tags":["warning","elasticsearch","admin"],"pid":1,"message":"No living connections"}
es_stack_kibana.1.bl9aozgf1b0z@node1 | {"type":"log","@timestamp":"2019-08-07T09:46:12Z","tags":["status","plugin:xpack_main@7.2.0","error"],"pid":1,"state":"red","message":"Status changed from yellow to red - No Living connections","prevState":"yellow","prevMsg":"Waiting for Elasticsearch"}
es_stack_kibana.1.bl9aozgf1b0z@node1 | {"type":"log","@timestamp":"2019-08-07T09:46:12Z","tags":["status","plugin:graph@7.2.0","error"],"pid":1,"state":"red","message":"Status changed from yellow to red - No Living connections","prevState":"yellow","prevMsg":"Waiting for Elasticsearch"}
es_stack_kibana.1.bl9aozgf1b0z@node1 | {"type":"log","@timestamp":"2019-08-07T09:46:12Z","tags":["status","plugin:elasticsearch@7.2.0","error"],"pid":1,"state":"red","message":"Status changed from yellow to red - No Living connections","prevState":"yellow","prevMsg":"Waiting for Elasticsearch"}
es_stack_kibana.1.bl9aozgf1b0z@node1 | {"type":"log","@timestamp":"2019-08-07T09:46:12Z","tags":["error","elasticsearch","data"],"pid":1,"message":"Request error, retrying\nGET https://elasticsearch:9200/_xpack => connect ECONNREFUSED 10.0.3.2:9200"}
es_stack_kibana.1.bl9aozgf1b0z@node1 | {"type":"log","@timestamp":"2019-08-07T09:46:12Z","tags":["warning","elasticsearch","data"],"pid":1,"message":"Unable to revive connection: https://elasticsearch:9200/"}
es_stack_kibana.1.bl9aozgf1b0z@node1 | {"type":"log","@timestamp":"2019-08-07T09:46:12Z","tags":["warning","elasticsearch","data"],"pid":1,"message":"No living connections"}
```

---

<div class="post-metadata">

**Author:** ![antcas](https://avatars.discourse-cdn.com/v4/letter/a/ee59a6/32.png) [@antcas](https://discuss.elastic.co/u/antcas)\
**Post date:** [August 7, 2019, 12:03pm UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/2 "2019-08-07T12:03:11Z")

</div>

What happens if you remove the ES user and ES password from Kibana config file?

---

<div class="post-metadata">

**Author:** ![saifat29](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@saifat29](https://discuss.elastic.co/u/saifat29)\
**Post date:** [August 7, 2019, 12:44pm UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/3 "2019-08-07T12:44:27Z")

</div>

Receiving the same errors-

```
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:16Z","tags":["error","elasticsearch","admin"],"pid":1,"message":"Request error, retrying\nGET https://elasticsearch:9200/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip => unable to verify the first certificate"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:16Z","tags":["warning","elasticsearch","admin"],"pid":1,"message":"Unable to revive connection: https://elasticsearch:9200/"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:16Z","tags":["warning","elasticsearch","admin"],"pid":1,"message":"No living connections"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:16Z","tags":["status","plugin:xpack_main@7.2.0","error"],"pid":1,"state":"red","message":"Status changed from yellow to red - No Living connections","prevState":"yellow","prevMsg":"Waiting for Elasticsearch"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:16Z","tags":["status","plugin:graph@7.2.0","error"],"pid":1,"state":"red","message":"Status changed from yellow to red - No Living connections","prevState":"yellow","prevMsg":"Waiting for Elasticsearch"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:16Z","tags":["error","elasticsearch","data"],"pid":1,"message":"Request error, retrying\nGET https://elasticsearch:9200/_xpack => unable to verify the first certificate"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:16Z","tags":["warning","elasticsearch","data"],"pid":1,"message":"Unable to revive connection: https://elasticsearch:9200/"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:16Z","tags":["warning","elasticsearch","data"],"pid":1,"message":"No living connections"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:16Z","tags":["license","warning","xpack"],"pid":1,"message":"License information from the X-Pack plugin could not be obtained from Elasticsearch for the [data] cluster. Error: No Living connections"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:17Z","tags":["reporting","browser-driver","warning"],"pid":1,"message":"Enabling the Chromium sandbox provides an additional layer of protection."}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:17Z","tags":["reporting","warning"],"pid":1,"message":"Generating a random key for xpack.reporting.encryptionKey. To prevent pending reports from failing on restart, please set xpack.reporting.encryptionKey in kibana.yml"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:17Z","tags":["status","plugin:reporting@7.2.0","error"],"pid":1,"state":"red","message":"Status changed from uninitialized to red - No Living connections","prevState":"uninitialized","prevMsg":"uninitialized"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:18Z","tags":["status","plugin:security@7.2.0","error"],"pid":1,"state":"red","message":"Status changed from green to red - No Living connections","prevState":"green","prevMsg":"Ready"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:18Z","tags":["warning","elasticsearch","data"],"pid":1,"message":"Unable to revive connection: https://elasticsearch:9200/"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:18Z","tags":["warning","elasticsearch","data"],"pid":1,"message":"No living connections"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:18Z","tags":["warning","telemetry"],"pid":1,"message":"Error scheduling task, received NotInitialized: Tasks cannot be scheduled until after task manager is initialized!"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:18Z","tags":["warning","elasticsearch","admin"],"pid":1,"message":"Unable to revive connection: https://elasticsearch:9200/"}
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:18Z","tags":["warning","elasticsearch","admin"],"pid":1,"message":"No living connections"}
```

---

<div class="post-metadata">

**Author:** ![saifat29](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@saifat29](https://discuss.elastic.co/u/saifat29)\
**Post date:** [August 7, 2019, 12:46pm UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/4 "2019-08-07T12:46:13Z")

</div>

The following lines from the above logs catch my eye-

```
es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:16Z","tags":["error","elasticsearch","admin"],"pid":1,"message":"Request error, retrying\nGET https://elasticsearch:9200/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip => unable to verify the first certificate"}

es_stack_kibana.1.trlyzkb3sa01@node1 | {"type":"log","@timestamp":"2019-08-07T12:40:16Z","tags":["error","elasticsearch","data"],"pid":1,"message":"Request error, retrying\nGET https://elasticsearch:9200/_xpack => unable to verify the first certificate"}
```

---

<div class="post-metadata">

**Author:** ![saifat29](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@saifat29](https://discuss.elastic.co/u/saifat29)\
**Post date:** [August 9, 2019, 8:38am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/5 "2019-08-09T08:38:04Z")

</div>

Can somebody please help me out, I'm stuck for days.😢

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [August 9, 2019, 8:42am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/6 "2019-08-09T08:42:52Z")

</div>

So they can reach each other, if you have tried the connection with cURL inside the container?  
If the error is "unable to verify the first certificate", then the issue is with those.  
I would proceed by starting up the containers and opening a shell to both of them and checking the configs inside containers and double checking certs (both client and CA).

---

<div class="post-metadata">

**Author:** ![saifat29](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@saifat29](https://discuss.elastic.co/u/saifat29)\
**Post date:** [August 9, 2019, 8:57am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/7 "2019-08-09T08:57:19Z")

</div>

I am using the same certificate for both the ES clusters and Kibana.  
ES clusters are able to discover and communicate each other over TLS successfully.

Performing a cURL call from inside the Kibana container to the ES cluster is successful which implies the certificate used for performing cURL is perfect. But Kibana doesn't connect to ES clusters automatically as it should using the same exact certificate.

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [August 9, 2019, 9:05am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/8 "2019-08-09T09:05:39Z")

</div>

And the cert is valid for both the dns name and IP address ?

---

<div class="post-metadata">

**Author:** ![saifat29](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@saifat29](https://discuss.elastic.co/u/saifat29)\
**Post date:** [August 9, 2019, 9:11am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/9 "2019-08-09T09:11:27Z")

</div>

I'm using the following **instances.yml** to generate the certificates-  
Reference- [Encrypting communications in an Elasticsearch Docker Container](https://www.elastic.co/guide/en/elasticsearch/reference/7.2/configuring-tls-docker.html)

```
instances:
  - name: elasticsearch
    dns:
      - elasticsearch
      - localhost
    ip:
      - 127.0.0.1

```

I am not using a Domain name for my node's IP address.

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [August 9, 2019, 9:18am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/10 "2019-08-09T09:18:23Z")

</div>

I always use mutual authentication with certificates, so I am not sure if this setting exists:

```auto
xpack.security.http.ssl.verification_mode

```

If it does, I think you should set it to "certificate" too, because I think it defaults to "full" which doesn't work in your case if you use one cert for both kibana and elasticsearch, and you have only written it for "elasticsearch" and not "kibana".  
You can also add "kibana" in the dns list in your instances.yml if you want to see if that is the issue.

---

<div class="post-metadata">

**Author:** ![saifat29](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@saifat29](https://discuss.elastic.co/u/saifat29)\
**Post date:** [August 9, 2019, 9:26am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/11 "2019-08-09T09:26:52Z")

</div>

I've used the following  
`elasticsearch.ssl.verificationMode=certificate`  
as you can see in the above posted `docker-compose.yml` file.

I found this setting in this [Configuring Kibana](https://www.elastic.co/guide/en/kibana/7.2/settings.html)  
and I don't find this `xpack.security.http.ssl.verification_mode` setting in it.

However I'll try and let you know.

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [August 9, 2019, 9:28am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/12 "2019-08-09T09:28:35Z")

</div>

> I've used the following  
> `elasticsearch.ssl.verificationMode=certificate`  
> as you can see in the above posted `docker-compose.yml` file.

Yes, but that is for Kibana. Not Elasticsearch.

---

<div class="post-metadata">

**Author:** ![saifat29](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@saifat29](https://discuss.elastic.co/u/saifat29)\
**Post date:** [August 10, 2019, 10:53am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/13 "2019-08-10T10:53:49Z")

</div>

I added `kibana` in the DNS field of `instances.yml` and this setting `xpack.security.http.ssl.verification_mode` too.

Still same error-  
`=> unable to verify the first certificate`

---

<div class="post-metadata">

**Author:** ![saifat29](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@saifat29](https://discuss.elastic.co/u/saifat29)\
**Post date:** [August 10, 2019, 10:57am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/14 "2019-08-10T10:57:46Z")

</div>

If somebody can share their configuration wherein they have successfully connected ES and Kibana over TLS it would be so nice.

I don't understand why the procedures from the documentation doesn't work out of the box.

---

<div class="post-metadata">

**Author:** ![saifat29](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@saifat29](https://discuss.elastic.co/u/saifat29)\
**Post date:** [August 10, 2019, 1:16pm UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/15 "2019-08-10T13:16:12Z")

</div>

This error **"`unable to verify the first certificate`"** is a waste.  
At least there should be some descriptive message to point developers in the correct direction.

I've been reading the docs repeatedly for the past 1 week, going through logs, scraping forums looking for a solution.

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [August 10, 2019, 3:50pm UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/16 "2019-08-10T15:50:33Z")

</div>

Also check Elasticsearch logs if there is an error.  
Other than that, I would start deconstructing the config one by one until it works, and then retry.

I have seen the same error before and in that case it was more of a symptom but not the root cause.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 13, 2019, 6:48am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/17 "2019-08-13T06:48:20Z")

</div>

> [@saifat29](#):
>
> ```auto
> kibana:
> image: docker.elastic.co/kibana/kibana:7.2.0
> restart: always
> environment:
> - "SERVER_NAME=kibana" 
> - "ELASTICSEARCH_HOSTS=https://elasticsearch:9200"
> - "XPACK_SECURITY_ENABLED=true"
> - "ELASTICSEARCH_USERNAME=kibana"
> - "ELASTICSEARCH_PASSWORD=mykbpassword"
> - elasticsearch.ssl.certificateAuthorities=$CERTS_DIR/ca/ca.crt
> - elasticsearch.ssl.verificationMode=certificate
> 
> ```

I believe your problem here is that you are trying to pass environment variables using a settings syntax.

From: [Running Kibana on Docker | Kibana Guide [7.2] | Elastic](https://www.elastic.co/guide/en/kibana/7.2/docker.html)

> For compatibility with container orchestration systems, these environment variables are written in all capitals, with underscores as word separators. The helper translates these names to valid Kibana setting names.

Your first 5 variables are in the correct format, but the last 2 have not been converted.

---

<div class="post-metadata">

**Author:** ![saifat29](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@saifat29](https://discuss.elastic.co/u/saifat29)\
**Post date:** [August 13, 2019, 9:46am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/18 "2019-08-13T09:46:53Z")

</div>

Thanks @TimV  
The solution was exactly that you suggested.  
All my configuration files were perfect, the only wrong thing that I was doing was **not** passing Kibana environment variables the way it was mentioned in the docs.

Thank you again, saved my day.😍

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2019, 9:46am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201/19 "2019-09-10T09:46:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
