# Kibana can't connect to elasticsearch using self signed certificates

**URL:** <https://discuss.elastic.co/t/kibana-cant-connect-to-elasticsearch-using-self-signed-certificates/294255>\
**Category:** Kibana\
**Created:** [January 13, 2022, 10:15am UTC](https://discuss.elastic.co/t/kibana-cant-connect-to-elasticsearch-using-self-signed-certificates/294255 "2022-01-13T10:15:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![proxymoxy](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@proxymoxy](https://discuss.elastic.co/u/proxymoxy)\
**Post date:** [January 13, 2022, 10:15am UTC](https://discuss.elastic.co/t/kibana-cant-connect-to-elasticsearch-using-self-signed-certificates/294255/1 "2022-01-13T10:15:35Z")

</div>

Hi, I have enabled TLS certificates for connection between Kibana and Elasticsearch as described here: [Set up basic security for the Elastic Stack plus secured HTTPS traffic | Elasticsearch Guide [7.16] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/security-basic-setup-https.html#encrypt-kibana-elasticsearch)

I use rsyslog to send data straight to Elasticsearch and that works fine, I can also use curl to talk to Elasticsearch so certificates are working fine for the [https://localhost:9200](https://localhost:9200) URL.

But when I try to do the same with Kibana then all I get is the dreaded "Unable to retrieve version information from Elasticsearch nodes. self signed certificate in certificate chain" log in /var/log/kibana/kibana.log

I used the Elasticsearch-certutil to create a CA, and a certificate/key pair for https using that CA, that also created a kibana directory in the zip file that included a .pem file that I use for telling kibana to trust the Elasticsearch certificate.

Here is the kibana.yml file:

```auto
server.publicBaseUrl: "my-dns-server-name"
elasticsearch.hosts: ["https://localhost:9200"]
elasticsearch.username: "kibana_system"
elasticsearch.ssl.certificate: "/etc/kibana/elasticsearch-ssl/elasticsearch-ca.pem"
xpack.encryptedSavedObjects.encryptionKey: "xxxxxxx"
xpack.security.encryptionKey: "xxxxxxx"

```

And here is the Elasticsearch.yml file:

```auto
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
network.host: localhost
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate 
xpack.security.transport.ssl.client_authentication: required
xpack.security.transport.ssl.key: elasticsearch-ssl/elasticsearch.key.pem
xpack.security.transport.ssl.certificate: elasticsearch-ssl/elasticsearch.cert.pem
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: elasticsearch-ssl/http.p12
discovery.type: single-node

```

All the referenced certificates are from the Elasticsearch-certutil program.

Anyone have ideas on why kibana does not trust the certificate?

---

<div class="post-metadata">

**Author:** ![unsecur3d](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/unsecur3d/32/101570_2.png) [@unsecur3d](https://discuss.elastic.co/u/unsecur3d)\
**Post date:** [February 9, 2022, 6:31am UTC](https://discuss.elastic.co/t/kibana-cant-connect-to-elasticsearch-using-self-signed-certificates/294255/2 "2022-02-09T06:31:40Z")

</div>

Yeah looks like you are missing to specify the CA in the Kibana config and the key as well? see my kibana.yml:

server.ssl.enabled: true  
server.ssl.certificate: /etc/kibana/Elasticsearch-ca.pem  
server.ssl.key: /etc/ssl/kibana/kibana-key.key  
Elasticsearch.ssl.certificateAuthorities: ["/etc/kibana/Elasticsearch-ca.pem"]  
Elasticsearch.ssl.verificationMode: none

Elasticsearch.yml:

cluster.initial\_master\_nodes: ["node-1"]  
xpack.security.transport.ssl.enabled: true  
xpack.security.enabled: true  
xpack.security.http.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: none  
xpack.security.http.ssl.keystore.path: http.p12  
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12  
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

They do not have to have the same certs, I created a different cert for Kibana and a different one for Elasticsearch but used the same key and CA and used openssl i believe to generate the p12 format certs which include the ca into it, so i could actually technically be able to point kibana to those .p12 and it should work just fine as well.

To generate new cert w/openssl:

cd /etc/Elasticsearch/  
openssl pkcs12 -in elastic-certificates.p12 -out newfile.crt.pem -clcerts -nokeys  
openssl pkcs12 -in elastic-certificates.p12 -out newfile.key.pem -nocerts -nodes

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2022, 6:32am UTC](https://discuss.elastic.co/t/kibana-cant-connect-to-elasticsearch-using-self-signed-certificates/294255/3 "2022-03-09T06:32:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
