# Kibana http requests instead of https? i.e. without encryption

**URL:** https://discuss.elastic.co/t/kibana-http-requests-instead-of-https-i-e-without-encryption/64243
**Category:** Kibana
**Created:** [October 28, 2016, 6:11am UTC](https://discuss.elastic.co/t/kibana-http-requests-instead-of-https-i-e-without-encryption/64243 "2016-10-28T06:11:05Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![jasona](https://avatars.discourse-cdn.com/v4/letter/j/3bc359/32.png) [@jasona](https://discuss.elastic.co/u/jasona)
#### Post date: [October 28, 2016, 6:11am UTC](https://discuss.elastic.co/t/kibana-http-requests-instead-of-https-i-e-without-encryption/64243/1 "2016-10-28T06:11:05Z")

</div>

I'm running kibana 4.6.1 behind nginx configured as a reverse proxy to terminate TLS connections.

I'd like the nginx -\> kibana connections to happen over http rather that https so that my logging can be effective, and I save on cpu.

config/kibana.yml seems to assume SSL/TLS, and I can't seem to find an option to tell kibana to speak http instead of https.

How can I configure kibana to speak http without encyrption?

---

<div class="post-metadata">

### Author: ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)
#### Post date: [October 28, 2016, 6:02pm UTC](https://discuss.elastic.co/t/kibana-http-requests-instead-of-https-i-e-without-encryption/64243/2 "2016-10-28T18:02:37Z")

</div>

Hey there,

Are you using the Shield X-Plugin? This will require SSL in Kibana 4.x. By default, Kibana should not use SSL. If you're not using Shield, then I think the only other explanation is that in your config/kibana/yml, you have server.ssl.cert and server.ssl.key defined. Can you take a look there and make sure they're either not defined or commented out?

Thanks,  
CJ

---

<div class="post-metadata">

### Author: ![jasona](https://avatars.discourse-cdn.com/v4/letter/j/3bc359/32.png) [@jasona](https://discuss.elastic.co/u/jasona)
#### Post date: [October 28, 2016, 6:05pm UTC](https://discuss.elastic.co/t/kibana-http-requests-instead-of-https-i-e-without-encryption/64243/3 "2016-10-28T18:05:56Z")

</div>

oh interesting. I didn't realize that the default was no https. I'll try commenting out the server.ssl.cert and server.ssl.key and see what happens; they are definitely defined now from a leftover previous configuration.

Also, I have Shield installed, but not using Sheild X-Plugin, if that is different.

---

<div class="post-metadata">

### Author: ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)
#### Post date: [October 28, 2016, 10:24pm UTC](https://discuss.elastic.co/t/kibana-http-requests-instead-of-https-i-e-without-encryption/64243/4 "2016-10-28T22:24:35Z")

</div>

On Kibana 4.6.1 with Shield, it does require SSL (https). I'm trying to find if there's some parameters you could use to turn that off.

But on Kibana 5.0 that was just released, the default with X-Pack Security (the new name for the Shield plugin) the default is no SSL (http). So if you can upgrade to 5.0 with X-Pack (it's quite awesome) then you won't need to use https.

Regards,  
Lee

---

<div class="post-metadata">

### Author: ![jasona](https://avatars.discourse-cdn.com/v4/letter/j/3bc359/32.png) [@jasona](https://discuss.elastic.co/u/jasona)
#### Post date: [October 28, 2016, 11:45pm UTC](https://discuss.elastic.co/t/kibana-http-requests-instead-of-https-i-e-without-encryption/64243/5 "2016-10-28T23:45:12Z")

</div>

Good to know. I'll check out 5.0. Thanks Lee.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 1:35pm UTC](https://discuss.elastic.co/t/kibana-http-requests-instead-of-https-i-e-without-encryption/64243/6 "2017-07-06T13:35:08Z")

</div>


