# Kibana Service Fails when SSL Cert Enabled

**URL:** <https://discuss.elastic.co/t/kibana-service-fails-when-ssl-cert-enabled/59417>\
**Category:** Kibana\
**Created:** [August 31, 2016, 11:05am UTC](https://discuss.elastic.co/t/kibana-service-fails-when-ssl-cert-enabled/59417 "2016-08-31T11:05:55Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mike\_Sanders](https://avatars.discourse-cdn.com/v4/letter/m/2bfe46/32.png) [@Mike\_Sanders](https://discuss.elastic.co/u/Mike_Sanders)\
**Post date:** [August 31, 2016, 11:05am UTC](https://discuss.elastic.co/t/kibana-service-fails-when-ssl-cert-enabled/59417/1 "2016-08-31T11:05:55Z")

</div>

I did a search but haven't found anything. I have a certificate that is working on 3 other servers but when I try to point Kibana to it I get the following error on service start:

● kibana.service - no description given  
Loaded: loaded (/lib/systemd/system/kibana.service; disabled; vendor preset: enabled)  
Active: inactive (dead)

Aug 31 01:47:23 kibana kibana[35250]: code: 'EACCES',  
Aug 31 01:47:23 kibana kibana[35250]: syscall: 'open',  
Aug 31 01:47:23 kibana kibana[35250]: path: '/etc/letsencrypt/live/api.domain.com/privkey.pem' }  
Aug 31 01:47:23 kibana systemd[1]: kibana.service: Main process exited, code=exited, status=1/FAILURE  
Aug 31 01:47:23 kibana systemd[1]: kibana.service: Unit entered failed state.  
Aug 31 01:47:23 kibana systemd[1]: kibana.service: Failed with result 'exit-code'.  
Aug 31 01:47:23 kibana systemd[1]: kibana.service: Service hold-off time over, scheduling restart.  
Aug 31 01:47:23 kibana systemd[1]: Stopped no description given.  
Aug 31 01:47:23 kibana systemd[1]: kibana.service: Start request repeated too quickly.  
Aug 31 01:47:23 kibana systemd[1]: Failed to start no description given.

I noticed that the SSL cert wasn't part of the ssl-cert group so I added the directories and files to that group and added the kibana user to that group but it didn't help so I removed it. I'm really stuck now so any help would be appreciated. Thanks in advance!

Ubuntu 16.04  
Kibana 4.5.4  
SSL cert signed by letsencrypt

My YML File has the following entries for SSL:

server.ssl.cert: /etc/letsencrypt/live/api.domain.com/fullchain.pem  
server.ssl.key: /etc/letsencrypt/live/api.domain.com/privkey.pem

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [August 31, 2016, 6:18pm UTC](https://discuss.elastic.co/t/kibana-service-fails-when-ssl-cert-enabled/59417/2 "2016-08-31T18:18:26Z")

</div>

It looks like you're on the right track, the error seems to indicate an issue opening the file. Kibana packages using systemd run as the user 'kibana' Can you make sure permissions on your certificates allow for read access to the file as either user or group kibana? If you chown kibana /etc/letsencrypt/live/api.domain.com/privkey.pem for example are you able to start the server?

---

<div class="post-metadata">

**Author:** ![Mike\_Sanders](https://avatars.discourse-cdn.com/v4/letter/m/2bfe46/32.png) [@Mike\_Sanders](https://discuss.elastic.co/u/Mike_Sanders)\
**Post date:** [August 31, 2016, 9:29pm UTC](https://discuss.elastic.co/t/kibana-service-fails-when-ssl-cert-enabled/59417/3 "2016-08-31T21:29:27Z")

</div>

Hi Jon,

Unfortunately I did try that and even with the permissions set to kibana as the owner of the files it still gives the same error.

---

<div class="post-metadata">

**Author:** ![imHarshj](https://avatars.discourse-cdn.com/v4/letter/i/e495f1/32.png) [@imHarshj](https://discuss.elastic.co/u/imHarshj)\
**Post date:** [October 4, 2016, 8:12pm UTC](https://discuss.elastic.co/t/kibana-service-fails-when-ssl-cert-enabled/59417/4 "2016-10-04T20:12:41Z")

</div>

Mike - did you resolve this problem?

I'm having the same issue.

---

<div class="post-metadata">

**Author:** ![Mike\_Sanders](https://avatars.discourse-cdn.com/v4/letter/m/2bfe46/32.png) [@Mike\_Sanders](https://discuss.elastic.co/u/Mike_Sanders)\
**Post date:** [October 4, 2016, 11:44pm UTC](https://discuss.elastic.co/t/kibana-service-fails-when-ssl-cert-enabled/59417/5 "2016-10-04T23:44:31Z")

</div>

Not yet.Haven't had time to spend on it though but I'm going to have to get back on it soon so I'll post whatever I find here.

---

<div class="post-metadata">

**Author:** ![Mike\_Sanders](https://avatars.discourse-cdn.com/v4/letter/m/2bfe46/32.png) [@Mike\_Sanders](https://discuss.elastic.co/u/Mike_Sanders)\
**Post date:** [November 4, 2016, 12:54am UTC](https://discuss.elastic.co/t/kibana-service-fails-when-ssl-cert-enabled/59417/6 "2016-11-04T00:54:49Z")

</div>

Hi Harsh,

Did you ever figure it out. I'm still stumped.

---

<div class="post-metadata">

**Author:** ![imHarshj](https://avatars.discourse-cdn.com/v4/letter/i/e495f1/32.png) [@imHarshj](https://discuss.elastic.co/u/imHarshj)\
**Post date:** [November 10, 2016, 11:48pm UTC](https://discuss.elastic.co/t/kibana-service-fails-when-ssl-cert-enabled/59417/7 "2016-11-10T23:48:04Z")

</div>

I did resolve it. If I remember correctly this might help:  
Try moving your .pem and .key files to the /opt/kibana/installedPlugins/shield directory.  
Then update the paths for the .pem/.key files in the kibana.yml file.

let me know if that works.

---

<div class="post-metadata">

**Author:** ![Mike\_Sanders](https://avatars.discourse-cdn.com/v4/letter/m/2bfe46/32.png) [@Mike\_Sanders](https://discuss.elastic.co/u/Mike_Sanders)\
**Post date:** [November 15, 2016, 11:04pm UTC](https://discuss.elastic.co/t/kibana-service-fails-when-ssl-cert-enabled/59417/8 "2016-11-15T23:04:32Z")

</div>

That did work! Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:34pm UTC](https://discuss.elastic.co/t/kibana-service-fails-when-ssl-cert-enabled/59417/9 "2017-07-06T13:34:12Z")

</div>


