# Kibana/enterprise search SSL connection error

**URL:** <https://discuss.elastic.co/t/kibana-enterprise-search-ssl-connection-error/322329>\
**Category:** Elastic Search\
**Tags:** docker, elastic-app-search\
**Created:** [January 2, 2023, 5:54pm UTC](https://discuss.elastic.co/t/kibana-enterprise-search-ssl-connection-error/322329 "2023-01-02T17:54:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![RRdev](https://avatars.discourse-cdn.com/v4/letter/r/b9e5f3/32.png) [@RRdev](https://discuss.elastic.co/u/RRdev)\
**Post date:** [January 2, 2023, 5:54pm UTC](https://discuss.elastic.co/t/kibana-enterprise-search-ssl-connection-error/322329/1 "2023-01-02T17:54:26Z")

</div>

I'm trying to stablish an https connection between Kibana and Enterprise Search, but I'm having this error:

"Could not perform access check to Enterprise Search: FetchError: request to api/ent/v2/internal/client\_config failed, reason: unable to get local issuer certificate".

I've found some similar issues here, but could not find a workable solution for my case ☹

With ssl disabled, it works fine, but I really need ssl enabled. Here is part of the docker-compose configs.

```auto
Stack version: 8.5.0

elasticsearch:
    container_name: elasticsearch
    environment:
      - node.name=elasticsearch
      - cluster.name=${CLUSTER_NAME}
      - cluster.initial_master_nodes=elasticsearch
      - ELASTIC_PASSWORD=${ELASTIC_PASSWORD}
      - bootstrap.memory_lock=true
      - xpack.security.enabled=true
      - xpack.security.http.ssl.enabled=true
      - xpack.security.http.ssl.key=certs/privkey.pem
      - xpack.security.http.ssl.certificate=certs/fullchain.pem
      - xpack.security.http.ssl.verification_mode=certificate
      - xpack.security.transport.ssl.enabled=true
      - xpack.security.transport.ssl.key=certs/privkey.pem
      - xpack.security.transport.ssl.certificate=certs/fullchain.pem
      - xpack.security.transport.ssl.verification_mode=certificate
      - xpack.license.self_generated.type=${LICENSE}

  kibana:
    container_name: kibana
    environment:
      - SERVERNAME=myhost
      - SERVER_SSL_ENABLED=true
      - SERVER_SSL_CERTIFICATE=/usr/share/elasticsearch/config/certs/fullchain.pem
      - SERVER_SSL_KEY=/usr/share/elasticsearch/config/certs/privkey.pem
      - SERVER_PUBLICBASEURL=https://myhost:5601
      - ELASTICSEARCH_HOSTS=https://myhost:9200
      - ELASTICSEARCH_USERNAME=kibana_system
      - ELASTICSEARCH_PASSWORD=${KIBANA_PASSWORD}
      - ELASTICSEARCH_SSL_ENABLED=true
      - ENTERPRISESEARCH_HOST=https://myip:3002
      - XPACK_SECURITY_ENCRYPTIONKEY= *************
      - XPACK_ENCRYPTEDSAVEDOBJECTS_ENCRYPTIONKEY= *************
      - XPACK_REPORTING_ENCRYPTIONKEY= *************
     - XPACK_REPORTING_KIBANASERVER_HOSTNAME=myhost
    
enterprisesearch:
    environment:
      - SERVERNAME=myhost
      - secret_management.encryption_keys=[encryption_keys]
      - allow_es_settings_modification=true
      - elasticsearch.host=https://myhost:9200
      - elasticsearch.username=elastic
      - elasticsearch.password=${ELASTIC_PASSWORD}
      - elasticsearch.ssl.enabled=true
      - kibana.external_url=https://myhost:5601
      - kibana.host=https://myhost:5601
      - kibana.startup_retry.enabled=true
      - kibana.startup_retry.interval=5
      - kibana.startup_retry.fail_after=60
      - ent_search.ssl.enabled=true
      - ent_search.external_url=https://myip:
     - ent_search.ssl.keystore.path=/usr/share/enterprise-search/cacert/keystore.jks
      - ent_search.ssl.keystore.password=KEYSTORE_PASSWORD
      - ent_search.ssl.keystore.key_password=KEYSTORE_PASSWORD
      - ent_search.listen_port=3002
          
volumes:
  enterprisesearchdata:
  esdata:
  kibanadata:

```

---

<div class="post-metadata">

**Author:** ![Rich\_Kuzsma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rich_kuzsma/32/66159_2.png) [@Rich\_Kuzsma](https://discuss.elastic.co/u/Rich_Kuzsma)\
**Post date:** [January 4, 2023, 4:17pm UTC](https://discuss.elastic.co/t/kibana-enterprise-search-ssl-connection-error/322329/2 "2023-01-04T16:17:41Z")

</div>

Hello RRdev, thanks for your question. Sorry you're running into difficulty configuring this, it isn't easy and I'm sure you're not the only one struggling.

When configuring TLS/SSL between Enterprise Search and Kibana, we have to consider TLS/SSL traffic going in both directions: from the Enterprise Search server to the Kibana server, and from the Kibana server to the Enterprise Search server.

When the Enterprise Search server connects to the Kibana server via the `kibana.host` URL specified in `config/enterprise-search.yml`, Enterprise Search connects using the **Elasticsearch** TLS/SSL settings configured in `config/enterprise-search.yml`:

```yaml
elasticsearch.ssl.enabled: 
elasticsearch.ssl.certificate:
elasticsearch.ssl.certificate_authority:
elasticsearch.ssl.key:
elasticsearch.ssl.key_passphrase:
elasticsearch.ssl.verify: true

```

There isn't currently a way to configure different TLS/SSL settings for Enterprise Search to use when connecting to Kibana. Enterprise Search always uses the Elasticsearch TLS/SSL settings.

Note that the Enterprise Search server only connects to the Kibana server for the purposes of checking telemetry settings and verify the version of Kibana.

Going in the _other_ direction... When the Kibana server connects to the Enterprise Search server over TLS/SSL, Kibana must be configured to trust Enterprise Search's certificate authority. There is documentation explaining [how to configure the Enterprise Search TLS/SSL certs in Kibana](https://www.elastic.co/guide/en/enterprise-search/8.5/configure-ssl-tls.html#configure-ssl-tls-in-kibana). Specifically, these settings need to be configured in Kibana `config/kibana.yml`:

```yaml
enterpriseSearch.host: https://some-host.tld:3002
enterpriseSearch.ssl.verificationMode: certificate
enterpriseSearch.ssl.certificateAuthorities:
  - /path/to/your/ca.pem

```

When running in docker, you can specify _most_ Kibana configuration settings using environment variables. For example, specify `enterpriseSearch.host` as the `ENTERPRISESEARCH_HOST` env var (replace `.` with `_` and use uppercase).

Unfortunately, the `enterpriseSearch.ssl.verificationMode` and `enterpriseSearch.ssl.certificateAuthorities` are not listed in the [Kibana docker ENV variable settings mapping list](https://github.com/elastic/kibana/blob/8.5/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker#L81).

I also don't see these variables documented in the Kibana documentation for [supported Enterprise Search configuration settings](https://www.elastic.co/guide/en/kibana/8.5/enterprise-search-settings-kb.html).

I'll file an issue to fix the docs and add these settings to the ENV var mappings list in a future release.

In the interim, it may be possible to specify an entire `kibana.yml` file with all the necessary settings for Docker using a [bind-mounted configuration file](https://www.elastic.co/guide/en/kibana/8.5/docker.html#bind-mount-config).

Hope this helps,  
Rich

---

<div class="post-metadata">

**Author:** ![RRdev](https://avatars.discourse-cdn.com/v4/letter/r/b9e5f3/32.png) [@RRdev](https://discuss.elastic.co/u/RRdev)\
**Post date:** [January 6, 2023, 6:05pm UTC](https://discuss.elastic.co/t/kibana-enterprise-search-ssl-connection-error/322329/3 "2023-01-06T18:05:30Z")

</div>

Hi Rich\_Kuzsma, thank you very much for your reply, I appreciate it.  
I'll try your suggestions and I'll keep up with documentation updates.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2023, 6:06pm UTC](https://discuss.elastic.co/t/kibana-enterprise-search-ssl-connection-error/322329/4 "2023-02-03T18:06:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
