# Kibana URL shows “Not Secure” when HTTPS enabled

**URL:** https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325
**Category:** Kibana
**Tags:** snapshot-and-restore
**Created:** [September 5, 2023, 9:48am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325 "2023-09-05T09:48:39Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [September 5, 2023, 9:48am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/1 "2023-09-05T09:48:39Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cdd04224687297f461709adf3c38cabc1f678664.png)

Please help me!

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [September 5, 2023, 9:50am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/2 "2023-09-05T09:50:06Z")

</div>

[![](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4e043da0bdfcae98c474790b5e5d8b1f8afd5e68.jpeg "08. Elastic Stack || Enable HTTPS for Kibana") ](https://www.youtube.com/watch?v=Zafi0laDQFk)

I followed this video to enable https

---

<div class="post-metadata">

### Author: ![miltonhultgren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miltonhultgren/32/100401_2.png) [@miltonhultgren](https://discuss.elastic.co/u/miltonhultgren)
#### Post date: [September 5, 2023, 12:35pm UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/3 "2023-09-05T12:35:24Z")

</div>

This is because you are generating and using a self signed certificate. The video explains this at 5:20.  
You'll need to get a proper certificate signed by a trusted CA to remove those warnings.

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [September 6, 2023, 12:46am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/4 "2023-09-06T00:46:47Z")

</div>

You'll need to get a proper certificate signed by a trusted CA to remove those warnings.  
Can you guide me on this part?

---

<div class="post-metadata">

### Author: ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)
#### Post date: [September 6, 2023, 2:33am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/5 "2023-09-06T02:33:08Z")

</div>

cert CN name not the ip change it.

---

<div class="post-metadata">

### Author: ![miltonhultgren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miltonhultgren/32/100401_2.png) [@miltonhultgren](https://discuss.elastic.co/u/miltonhultgren)
#### Post date: [September 6, 2023, 7:31am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/6 "2023-09-06T07:31:29Z")

</div>

That is a bit beyond the support we offer and my knowledge, but in general you'll need to find a Certificate Authority (CA) in your country or nearby and buy a signed certificate from them.

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [September 7, 2023, 1:43am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/7 "2023-09-07T01:43:01Z")

</div>

Is there any way to avoid using CA certificates?

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [September 7, 2023, 3:49am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/8 "2023-09-07T03:49:29Z")

</div>

> [@Nghia\_D\_ng](#):
>
> Is there any way to avoid using CA certificates?

No, other than do not use HTTPS

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [September 7, 2023, 3:52am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/9 "2023-09-07T03:52:13Z")

</div>

Hi Stephenb,  
After I finished like the video:

[![](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4e043da0bdfcae98c474790b5e5d8b1f8afd5e68.jpeg "08. Elastic Stack || Enable HTTPS for Kibana") ](https://www.youtube.com/watch?v=Zafi0laDQFk)

Now what should I do next, I haven't found the right instructions yet  
Can I create a CA certificate for free Lets Encrypt?

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [September 7, 2023, 4:10am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/10 "2023-09-07T04:10:56Z")

</div>

> [@Nghia\_D\_ng](#):
>
> Now what should I do next, I haven't found the right instructions yet

What OS is your browser on?  
If Mac add it to your Key Chain

If you followed the video that creates a self signed cert as long as you say ok you should be fine for testing.

> [@Nghia\_D\_ng](#):
>
> Can I create a CA certificate for free Lets Encrypt?

Yes it is what I do...

If you own a domain and create a Publicly signed Let's Encrypt Cert for that domain then then the CA is officially publicly signed will be accepted by your system and you won't get the error.

This is normal cert stuff, but we do not really teach that here it is no different than a cert for a webserver etc.

Find a friend or someone that is familiar with certs creation with Let's Encrypt

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [September 7, 2023, 4:16am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/11 "2023-09-07T04:16:21Z")

</div>

Hi Stephenb,  
I'm installing the ELK suite on a CentOS 8 virtual machine  
Do you have any instructions for creating certificates with Let's Encrypt?  
Thank you!

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [September 7, 2023, 4:19am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/12 "2023-09-07T04:19:40Z")

</div>

No not really.

Is this on a cloud provider?

They can also generate certs.

I use certbot

> **[Certbot Instructions](https://certbot.eff.org/instructions?ws=other&os=centosrhel8)**
>
> Tagline

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [September 19, 2023, 8:14am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/13 "2023-09-19T08:14:01Z")

</div>

Hi Stephenb,

I'm having problems  
After I have the CA as a .cer file  
How do I install SSL into kibana.yml

Method 1: convert .cer file to .key and .crt  
Method 2: convert .cer file to .pem  
I don't know what to do next.

Please help me

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [September 19, 2023, 8:14am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/14 "2023-09-19T08:14:50Z")

</div>

Hi Miltonhultgren,

I'm having problems  
After I have the CA as a .cer file  
How do I install SSL into kibana.yml

Method 1: convert .cer file to .key and .crt  
Method 2: convert .cer file to .pem  
I don't know what to do next.

Please help me!

---

<div class="post-metadata">

### Author: ![miltonhultgren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miltonhultgren/32/100401_2.png) [@miltonhultgren](https://discuss.elastic.co/u/miltonhultgren)
#### Post date: [September 19, 2023, 8:41am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/15 "2023-09-19T08:41:22Z")

</div>

I'm not a security expert so I'm hesitant to offer advice.

My understanding is that you should have three files:

1. The certificate for your specific instance (.crt)
2. The key to the certificate in 1 (.key)
3. The certificate for your CA chain (.crt)

I don't know what files you have obtained and how **but** once you have those files, your config will look like this:

```auto
server.ssl.certificate: /path/to/file/1.crt
server.ssl.key: /path/to/file/2.key
server.ssl.certificateAuthorities: /path/to/file/3.crt

```

If you have bought a certificate from a CA you should reach out to their support to get help with obtaining the right files to use. That is not something we can help you with.

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [September 19, 2023, 8:47am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/16 "2023-09-19T08:47:59Z")

</div>

OK I understand  
Thank you for your help!

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [September 29, 2023, 7:09am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/17 "2023-09-29T07:09:45Z")

</div>

Hi Miltonhultgren,

I have found the right direction  
Install nginx as a reverse proxy and put kibana ssl in the nginx.conf file. But currently kibana port is 80 which coincides with nginx port. I changed the port in the kibana.yml file to the default 5601 and got this error, the web interface is not displayed. Check netstat, kibana has received port 5601. Please help me!

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/a/2a373cc8357dd68c8ce54447e5e2b131d9a3d423.jpeg)

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [September 29, 2023, 7:10am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/18 "2023-09-29T07:10:32Z")

</div>

HI @stephenb and @miltonhultgren ,  
Please help me!

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [September 29, 2023, 1:05pm UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/19 "2023-09-29T13:05:19Z")

</div>

Hi @Nghia_D_ng  
Unfortunately I am not an nginx expert.

But please don't paste images of text. It's really hard to read and can't be searched or debugged... It makes it much harder for people to help.

We can't even see the whole error messages

Perhaps look at this

> [@Setting https for Kibana with NGINX and a FQDN](https://discuss.elastic.co/t/setting-https-for-kibana-with-nginx-and-a-fqdn/205010):
>
> I have a Droplet on Digital Ocean which runs CentOS 7 and I run an ELK stack on it. I've also successfully configured an NGINX web server with a FQDN (got one from namecheap.com ) and I also have an SSL certificate managed by Let's Encrypt. In order to set-up my nginx web server and the SSL certificate, I followed [this](https://www.digitalocean.com/community/tutorials/how-to-secure-nginx-with-let-s-encrypt-on-centos-7#step-4-%E2%80%94-obtaining-a-certificate) straightforward tutorial from Digital Ocean. I can now basically access my website from any browser. You can see it form yourself [here](https://basavyr.live). The connection is https and has a valid ce…

---

<div class="post-metadata">

### Author: ![Nghia\_D\_ng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_d_ng/32/123483_2.png) [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)
#### Post date: [October 2, 2023, 12:59am UTC](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325/20 "2023-10-02T00:59:10Z")

</div>

Hi @stephenb ,

\<Sep 27 17:14:31 Kibana kibana[1251275]: {"type":"log","@timestamp":"2023-09-27T10:14:31Z","tags"🙁"error","plugins","reporting","validations"],"pid":1251275,"message":"The Reporting plugin encountered issues launching Chromium in a self-test. You may have trouble generating reports."}\>

\<Sep 27 17:14:31 Kibana kibana[1251275]: {"type":"log","@timestamp":"2023-09-27T10:14:31Z","tags"🙁"error","plugins","reporting","validations"],"pid":1251275,"message":"ErrorEvent {\n target:\n WebSocket {\n \_events:\n [Object: null prototype] { open: [Function], error: [Function] },\n \_eventsCount: 2,\n \_maxListeners: undefined,\n readyState: 3,\n protocol: '',\n \_binaryType: 'nodebuffer',\n \_closeFrameReceived: false,\n \_closeFrameSent: false,\n \_closeMessage: '',\n \_closeTimer: null,\n \_closeCode: 1006,\n \_extensions: {},\n \_receiver: null,\n \_sender: null,\n \_socket: null,\n \_isServer: false,\n \_redirects: 0,\n url:\n 'ws://127.0.0.1:45265/devtools/browser/3f83980b-db25-4b6b-a162-1aacefb57be4',\n \_req: null },\n type: 'error',\n message :'socket hang up',\n error:\n { Error: socket hang up\n at createHangUpError (\_http\_client.js:332:15)\n at Socket.socketOnEnd (\_http\_client.js:435:23)\n at Socket.emit (events.js:203:15)\n at endReadableNT (\_stream\_readable.js:1145:12)\n at process.\_tickCallback (internal/process/next\_tick.js:63:19) at endReadableNT (\_stream\_readable.js:1145:12)\n at process.\_tickCallback (internal/process/next\_tick.js:63:19) code: 'ECONNRESET' } }"}\>

\<Sep 27 17:14:31 Kibana kibana[1251275]: {"type":"log","@timestamp":"2023-09-27T10:14:31Z","tags"🙁"error","plugins","reporting","validations"],"pid":1251275,"message":"Error: Could not close browser client handle!\n at browserFactory.test.then.browser (/u01/kibana-7.9.0-linux-x86\_64/x-pack/plugins/reporting/server/lib/validate/validate\_browser.js:26:15)\n at process.\_tickCallback (internal\>\>

\<Sep 27 17:14:31 Kibana kibana[1251275]: {"type":"log","@timestamp":"2023-09-27T10:14:31Z","tags"🙁"warning","plugins","reporting","validations"],"pid":1251275,"message":"Reporting plugin self-check generated a warning: Error: Could not close browser client handle!"}\>

[Next page](https://discuss.elastic.co/t/kibana-url-shows-not-secure-when-https-enabled/342325.md?page=2)
