# Kibana Kubernetes with HTTPS

**URL:** https://discuss.elastic.co/t/kibana-kubernetes-with-https/174967
**Category:** Kibana
**Created:** [April 2, 2019, 10:51am UTC](https://discuss.elastic.co/t/kibana-kubernetes-with-https/174967 "2019-04-02T10:51:45Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)
#### Post date: [April 2, 2019, 10:51am UTC](https://discuss.elastic.co/t/kibana-kubernetes-with-https/174967/1 "2019-04-02T10:51:45Z")

</div>

Hi, everyone:

I would like to know how to configure **HTTPS** in **Kibana** on **Kubernetes**. I have created my own certificate with **OpenSSL** :

> openssl req -x509 -newkey rsa:2048 -nodes -keyout /home/{{my\_user}}/main-certs/main.key -out /home/{{my\_user}}/main-certs/main.crt -days 365 -subj /C=ES/ST=Spain/L=Madrid/O=Entreprise/OU=IT/CN={{kubernetes-master}}

**kibana.yml**

* * *

> server.ssl.enabled: true  
> server.ssl.key: /usr/share/kibana/https/main.key  
> server.ssl.certificate: /usr/share/kibana/https/main.crt

I have a issue related to this when I deploy **Kibana** :

> {"type":"error","@timestamp":"2019-04-02T09:32:44Z","tags":["connection","client","error"],"pid":1,"level":"error","error":{"message":"139651378964352:error:14094412:SSL routines:ssl3\_read\_bytes:sslv3 alert bad certificate:../deps/openssl/openssl/ssl/s3\_pkt.c:1498:SSL alert number 42\n","name":"Error","stack":"Error: 139651378964352:error:14094412:SSL routines:ssl3\_read\_bytes:sslv3 alert bad certificate:../deps/openssl/openssl/ssl/s3\_pkt.c:1498:SSL alert number 42\n"},"message":"139651378964352:error:14094412:SSL routines:ssl3\_read\_bytes:sslv3 alert bad certificate:../deps/openssl/openssl/ssl/s3\_pkt.c:1498:SSL alert number 42\n"}

**StatefulSet**

* * *

```
apiVersion: apps/v1
kind: StatefulSet
metadata:
  name: kibana
  labels:
    k8s-app: kibana
spec:
  serviceName: kibana
  replicas: 1
  selector:
    matchLabels:
      k8s-app: kibana
  template:
    metadata:
      labels:
        k8s-app: kibana
    spec:
      containers:
      - name: kibana
        image: docker.elastic.co/kibana/kibana:6.5.4
        ports:
        - name: http
          containerPort: 5601
        volumeMounts:
        - name: https
          mountPath: /usr/share/kibana/https
        - name: config
          mountPath: /usr/share/kibana/config/kibana.yml
          subPath: kibana.yml
      volumes:
      - name: https
        secret:
         secretName: main-tls-secret
      - name: config
        configMap:
         name: kibana-config

```

**Service**

* * *

```
apiVersion: v1
kind: Service
metadata:
  name: kibana
  labels:
    k8s-app: kibana
spec:
  type: NodePort
  ports:
  - name: http
    port: 5601
    nodePort: 30100
  selector:
    k8s-app: kibana

```

Thanks in advance,

Regards

---

<div class="post-metadata">

### Author: ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)
#### Post date: [April 3, 2019, 12:39am UTC](https://discuss.elastic.co/t/kibana-kubernetes-with-https/174967/2 "2019-04-03T00:39:13Z")

</div>

I believe this error is from connecting to ES, not from the Kibana server itself. Are you by chance using SSL keys for the Elasticsearch connection as well?

Can you provide your entire Kibana configuration?

To get around this now, you should be able to set `elasticsearch.ssl.verify: false`

---

<div class="post-metadata">

### Author: ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)
#### Post date: [April 3, 2019, 8:45am UTC](https://discuss.elastic.co/t/kibana-kubernetes-with-https/174967/3 "2019-04-03T08:45:04Z")

</div>

> [@tylersmalley](#):
>
> elasticsearch.ssl.verify: false

Hi, @tylersmalley

I use `elasticsearch.ssl.verificationMode` parameter, because `elasticsearch.ssl.verify` is deprecated ( [Since 5.3.0](https://www.elastic.co/guide/en/kibana/6.5/settings.html) )

This is my **Kibana config** :

```
server.port: 5601

server.host: 0.0.0.0

server.name: kibana-0

elasticsearch.url: https://elasticsearch:9200

kibana.defaultAppId: "dashboard/Main-dashboard"

elasticsearch.username: elastic_user

elasticsearch.password: topsecret

searchguard.readonly_mode.roles: ["sg_kibana_user"]

server.ssl.enabled: true

server.ssl.key: /usr/share/kibana/https/main.key

server.ssl.certificate: /usr/share/kibana/https/main.crt

elasticsearch.ssl.verificationMode: none

elasticsearch.ssl.certificateAuthorities: ["/usr/share/kibana/searchguard/ssl/root-ca.pem"]

searchguard.basicauth.login.title: "Welcome"
searchguard.basicauth.login.subtitle: "If you have forgotten your username or password, please contact your system administrator"

# Monitoring
xpack.monitoring.enabled: true

# Apps
xpack.grokdebugger.enabled: true
xpack.reporting.enabled: true
timelion.enabled: false
xpack.apm.ui.enabled: false
xpack.graph.enabled: false
xpack.ml.enabled: false
xpack.security.enabled: false

```

Thanks in advance,

Rodrigo

---

<div class="post-metadata">

### Author: ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)
#### Post date: [April 4, 2019, 2:04pm UTC](https://discuss.elastic.co/t/kibana-kubernetes-with-https/174967/4 "2019-04-04T14:04:02Z")

</div>

Hi, @tylersmalley

I have done some tests with **Firefox** & **Google Chrome**. With **Firefox** , there is not any problem, however with **Google Chrome** , **Kibana** shows `handshake error`.

From my point of view, If **Kibana** kept **tls open sessions** , this kind of issue would be mitigated.

Regards

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 2, 2019, 2:04pm UTC](https://discuss.elastic.co/t/kibana-kubernetes-with-https/174967/5 "2019-05-02T14:04:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
