# Kibana \<---\> Elasticsearch integration with SSL enable

**URL:** https://discuss.elastic.co/t/kibana-elasticsearch-integration-with-ssl-enable/312298
**Category:** Kibana
**Tags:** elastic-stack-security, docker
**Created:** [August 17, 2022, 2:33pm UTC](https://discuss.elastic.co/t/kibana-elasticsearch-integration-with-ssl-enable/312298 "2022-08-17T14:33:35Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Diego\_Lopes\_Penna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/diego_lopes_penna/32/42465_2.png) [@Diego\_Lopes\_Penna](https://discuss.elastic.co/u/Diego_Lopes_Penna)
#### Post date: [August 17, 2022, 2:33pm UTC](https://discuss.elastic.co/t/kibana-elasticsearch-integration-with-ssl-enable/312298/1 "2022-08-17T14:33:35Z")

</div>

Hello,

I've tried to find a solution for this on this forum but I was not able to find a solution that solves the problem.  
I'm trying to configure a Kibana/Elasticsearch integration. Each one of them is running on its own server on DigitalOcean. For the certificates, I'm using let'sencript. ([https://certbot.eff.org/](https://certbot.eff.org/))

Everything is running inside docker containers.

My Elasticsearch is working and I'm able to communicate with it. The problem occurs when I try to connect Kibana to it. I'm getting the message:

```auto
[elasticsearch-service] Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate

```

My kibana.yml is:  
\</  
server.name: kibana

```auto
server.host: "0.0.0.0"

# Elasticsearch Connection

elasticsearch.hosts: ["${ELASTICSEARCH_HOST_PORT}"]

# SSL settings

server.ssl.enabled: true

server.ssl.certificate: /certs/kibana.crt

server.ssl.key: /certs/kibana.key

#server.ssl.certificateAuthorities: ["/certs/ca.crt"]

xpack.security.encryptionKey: ***********

xpack.encryptedSavedObjects.encryptionKey: ***********

xpack.reporting.encryptionKey: ***********

xpack.reporting.kibanaServer.hostname: ***********.***********. ***********

## X-Pack security credentials

elasticsearch.serviceAccountToken: "${KIBANA_SERVICE_ACCOUNT_TOKEN}" # !!! Get token !!

#elasticsearch.ssl.certificateAuthorities: ["/certs/ca.crt"]

## Misc

elasticsearch.requestTimeout: 90000

server.publicBaseUrl: https:// ***********.***********. ***********

```

> 

Each one of my servers has its own certificates since they have separate domains.

Can someone point me in the right direction? I'm losing a lot of time trying to find the correct configuration...

Thanks in advance...

---

<div class="post-metadata">

### Author: ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)
#### Post date: [August 18, 2022, 8:41am UTC](https://discuss.elastic.co/t/kibana-elasticsearch-integration-with-ssl-enable/312298/2 "2022-08-18T08:41:29Z")

</div>

Hello there!

> [@Diego\_Lopes\_Penna](#):
>
> `[elasticsearch-service] Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate`

Please tell me how did you set ES host in kibana.yml - I can't see this setting.

---

<div class="post-metadata">

### Author: ![Diego\_Lopes\_Penna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/diego_lopes_penna/32/42465_2.png) [@Diego\_Lopes\_Penna](https://discuss.elastic.co/u/Diego_Lopes_Penna)
#### Post date: [August 18, 2022, 10:07am UTC](https://discuss.elastic.co/t/kibana-elasticsearch-integration-with-ssl-enable/312298/3 "2022-08-18T10:07:46Z")

</div>

> [@Diego\_Lopes\_Penna](#):
>
> `elasticsearch.hosts: ["${ELASTICSEARCH_HOST_PORT}"]`

Hey @cheshirecat . Yes, I've set the ES host. You can find it on this line:  
`elasticsearch.hosts: ["${ELASTICSEARCH_HOST_PORT}"]`  
ELASTICSEARCH\_HOST\_PORT is a enviroment variable ---\> "[https://myelasticaddress:9200](https://myelasticaddress:9200)"

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [August 19, 2022, 12:24am UTC](https://discuss.elastic.co/t/kibana-elasticsearch-integration-with-ssl-enable/312298/4 "2022-08-19T00:24:03Z")

</div>

most likely you need the ca for the the elasticsearch connection... as the error says

`[elasticsearch-service] Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate`

You probably need the elasticsearch CA you have it commented out...see [here](https://www.elastic.co/guide/en/kibana/current/settings.html#server-ssl-enabled)

`#elasticsearch.ssl.certificateAuthorities: ["/certs/ca.crt"]`

or set `verificationMode : none` which is not recommended.

`elasticsearch.ssl.verificationMode : none`

---

<div class="post-metadata">

### Author: ![Diego\_Lopes\_Penna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/diego_lopes_penna/32/42465_2.png) [@Diego\_Lopes\_Penna](https://discuss.elastic.co/u/Diego_Lopes_Penna)
#### Post date: [August 19, 2022, 12:49pm UTC](https://discuss.elastic.co/t/kibana-elasticsearch-integration-with-ssl-enable/312298/5 "2022-08-19T12:49:09Z")

</div>

Hi @stephenb, thank you for the reply

I've tried to enable "server.ssl.certificateAuthorities" on a test but I had the same result.

I'm using let'sencrypt certificates as follows:

```auto
server.ssl.certificateAuthorities ----> fullchain.pem
server.ssl.certificate ----> fullchain.pem 
server.ssl.key ----> privkey.pem

```

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [August 19, 2022, 2:07pm UTC](https://discuss.elastic.co/t/kibana-elasticsearch-integration-with-ssl-enable/312298/6 "2022-08-19T14:07:00Z")

</div>

It's not the `server.ssl...`  
That's for the Kibana connection to the browser

It's the `elasticsearch.ssl...`  
Which is Kibana connecting to Elasticsearch which is what you're having trouble with.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 16, 2022, 2:07pm UTC](https://discuss.elastic.co/t/kibana-elasticsearch-integration-with-ssl-enable/312298/7 "2022-09-16T14:07:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
