# Kibana to reload certificates on change

**URL:** <https://discuss.elastic.co/t/kibana-to-reload-certificates-on-change/214310>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [January 8, 2020, 10:00pm UTC](https://discuss.elastic.co/t/kibana-to-reload-certificates-on-change/214310 "2020-01-08T22:00:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![danlsgiga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danlsgiga/32/60513_2.png) [@danlsgiga](https://discuss.elastic.co/u/danlsgiga)\
**Post date:** [January 8, 2020, 10:00pm UTC](https://discuss.elastic.co/t/kibana-to-reload-certificates-on-change/214310/1 "2020-01-08T22:00:59Z")

</div>

I have Kibana 7.5.1 running on Docker and certificates being managed by Vault (short lived certificates) in our environment. I noticed that when Vault replace the certificate and private\_key files, Kibana is not aware of that and continues to serve the expired certificates.

How can I signal Kibana to reload the certificates without a full restart? I've tried SIGHUP and it only reloads the config file.

Here's the error that shows up in the logs when I try to connect to Kibana after the certificate files have been replaced by Vault.

```auto
{"type":"error","@timestamp":"2020-01-08T21:41:49Z","tags":["connection","client","error"],"pid":10585,"level":"error","error":{"message":"140388375709568:error:14094412:SSL routines:ssl3_read_bytes:sslv3 alert bad certificate:../deps/openssl/openssl/ssl/record/rec_layer_s3.c:1407:SSL alert number 42\n","name":"Error","stack":"Error: 140388375709568:error:14094412:SSL routines:ssl3_read_bytes:sslv3 alert bad certificate:../deps/openssl/openssl/ssl/record/rec_layer_s3.c:1407:SSL alert number 42\n"},"message":"140388375709568:error:14094412:SSL routines:ssl3_read_bytes:sslv3 alert bad certificate:../deps/openssl/openssl/ssl/record/rec_layer_s3.c:1407:SSL alert number 42\n"}

```

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [January 9, 2020, 4:40pm UTC](https://discuss.elastic.co/t/kibana-to-reload-certificates-on-change/214310/2 "2020-01-09T16:40:00Z")

</div>

It sounds like this is a feature that is not available yet in Kibana. Would you mind creating a feature request in the Github repo? [https://github.com/elastic/kibana/issues/new?template=Feature\_request.md](https://github.com/elastic/kibana/issues/new?template=Feature_request.md)

---

<div class="post-metadata">

**Author:** ![danlsgiga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danlsgiga/32/60513_2.png) [@danlsgiga](https://discuss.elastic.co/u/danlsgiga)\
**Post date:** [January 9, 2020, 4:53pm UTC](https://discuss.elastic.co/t/kibana-to-reload-certificates-on-change/214310/3 "2020-01-09T16:53:09Z")

</div>

Sure, will do! I assumed the behaviour would be the same as Elasticsearch.

---

<div class="post-metadata">

**Author:** ![danlsgiga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danlsgiga/32/60513_2.png) [@danlsgiga](https://discuss.elastic.co/u/danlsgiga)\
**Post date:** [January 9, 2020, 4:58pm UTC](https://discuss.elastic.co/t/kibana-to-reload-certificates-on-change/214310/4 "2020-01-09T16:58:40Z")

</div>

For tracking purposes... [https://github.com/elastic/kibana/issues/54368](https://github.com/elastic/kibana/issues/54368)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2020, 5:10pm UTC](https://discuss.elastic.co/t/kibana-to-reload-certificates-on-change/214310/5 "2020-02-06T17:10:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
