# Metric won't setup because of bad certificates

**URL:** <https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [February 22, 2024, 1:42pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891 "2024-02-22T13:42:32Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Klheik](https://avatars.discourse-cdn.com/v4/letter/k/76d3ee/32.png) [@Klheik](https://discuss.elastic.co/u/Klheik)\
**Post date:** [February 22, 2024, 1:42pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/1 "2024-02-22T13:42:32Z")

</div>

Hi,  
I have a debian 11 install on a server, i am using the ELK satck with the 7.17 version and Elasticsearch, Logstash, Filebeat and kibana are installa and configure and works perfectly when it's about monitoring log files. Kibana is secured in https and now i would like to add metric to monitor my server healt. But when i exec "sudo metricbeat setup -e" i have 1 error :

```auto
< Loading dashboards (Kibana must be running and reachable)
2024-02-22T14:17:12.949+0100 INFO kibana/client.go:180 Kibana url: https://localhost:8492
2024-02-22T14:17:12.977+0100 ERROR instance/beat.go:1027 Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://localhost:8492/api/status fails: fail to execute the HTTP GET request: Get "https://localhost:8492/api/status": x509: certificate signed by unknown authority. Response: .
Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://localhost:8492/api/status fails: fail to execute the HTTP GET request: Get "https://localhost:8492/api/status": x509: certificate signed by unknown authority. Response: . 

```

- metric conf file :  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/b/6b9691dcdae0fbf0f5504c5ec1522616598cd9a1.png)  
elasticsearch, filebeat and logstash are not secured in TLS beacause they all are in local but kibana is accesible remotly so i use openssl to secure it.

Can someone help me to figure this out ?

Thanks !!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 22, 2024, 1:51pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/2 "2024-02-22T13:51:02Z")

</div>

In the certificate\_authorities configuration you need to put the certificate for the CA that you used to create the Kibana certificate, it seems that you put the kibana certificate instead.

---

<div class="post-metadata">

**Author:** ![Klheik](https://avatars.discourse-cdn.com/v4/letter/k/76d3ee/32.png) [@Klheik](https://discuss.elastic.co/u/Klheik)\
**Post date:** [February 22, 2024, 2:16pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/3 "2024-02-22T14:16:09Z")

</div>

I'm sorry, i am not good in the ssl domain. Can you explain me the difference and where can i find it then ?  
Thanks a lot

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 22, 2024, 2:31pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/4 "2024-02-22T14:31:38Z")

</div>

How did you create those certificates?

First you need a CA, which is a Certificate Authority, then you use this CA to create the certificate and keys.

The error means that the certificate in your Kibana was signed by an unknown authority (a CA), then you need to have this CA in the configuration.

---

<div class="post-metadata">

**Author:** ![Klheik](https://avatars.discourse-cdn.com/v4/letter/k/76d3ee/32.png) [@Klheik](https://discuss.elastic.co/u/Klheik)\
**Post date:** [February 22, 2024, 2:33pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/5 "2024-02-22T14:33:40Z")

</div>

I created the certificates with openssl but i really don't remember any CA, maybe they are store in a default dir. Do you know, by any chance, where it can be ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 22, 2024, 2:36pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/6 "2024-02-22T14:36:32Z")

</div>

> [@Klheik](#):
>
> I created the certificates with openssl but i really don't remember any CA, maybe they are store in a default dir. Do you know, by any chance, where it can be ?

Unfortunately no, but how you create it? Which commands?

Openssl will only create the files you tell it to create.

---

<div class="post-metadata">

**Author:** ![Klheik](https://avatars.discourse-cdn.com/v4/letter/k/76d3ee/32.png) [@Klheik](https://discuss.elastic.co/u/Klheik)\
**Post date:** [February 22, 2024, 2:39pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/7 "2024-02-22T14:39:06Z")

</div>

I did this like 2 months ago so i really don't remember but i will search, is there a chance i can maybe just generate again the certificates ? If not i will just look for it.

Thanks again !!

---

<div class="post-metadata">

**Author:** ![Klheik](https://avatars.discourse-cdn.com/v4/letter/k/76d3ee/32.png) [@Klheik](https://discuss.elastic.co/u/Klheik)\
**Post date:** [February 22, 2024, 3:33pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/8 "2024-02-22T15:33:51Z")

</div>

Can't i just "bypass" the error message ? Can i just skip the verification process ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 22, 2024, 4:09pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/9 "2024-02-22T16:09:43Z")

</div>

Looking at your config now it seems wrong.

You have `setup.kibana:` and then you also have `setup.kibana` again nested under it.

Try to remove the extra `setup.kibana` from all the `ssl` settings.

---

<div class="post-metadata">

**Author:** ![Klheik](https://avatars.discourse-cdn.com/v4/letter/k/76d3ee/32.png) [@Klheik](https://discuss.elastic.co/u/Klheik)\
**Post date:** [February 23, 2024, 8:34am UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/10 "2024-02-23T08:34:04Z")

</div>

this is the new conf file :

```auto
setup.kibana:

  # Kibana Host
  # Scheme and port can be left out and will be set to the default (http and 5601)
  # In case you specify and additional path, the scheme is required: http://localhost:5601/path
  # IPv6 addresses should always be defined as: https://[2001:db8::1]:5601
   host: "https://localhost:8492"
   ssl.enabled: true
   ssl.certificate: /etc/kibana/kibana.crt
   ssl.key: /etc/kibana/kibana.key
   ssl.certificate_authorities: /etc/kibana/kibana.crt
   ssl.supportedProtocols: ["TLSv1.2"]
# setup.kibana.ssl.verification_mode: none

```

And this is the new error :

```auto
Loading dashboards (Kibana must be running and reachable)
2024-02-23T09:32:29.458+0100 WARN [cfgwarn] tlscommon/config.go:100 DEPRECATED: Treating the CommonName field on X.509 certificates as a host name when no Subject Alternative Names are present is going to be removed. Please update your certificates if needed. Will be removed in version: 8.0.0
2024-02-23T09:32:29.460+0100 INFO kibana/client.go:180 Kibana url: https://localhost:8492
2024-02-23T09:32:29.464+0100 ERROR instance/beat.go:1027 Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://localhost:8492/api/status fails: fail to execute the HTTP GET request: Get "https://localhost:8492/api/status": x509: certificate is not valid for any names, but wanted to match localhost. Response: .
Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://localhost:8492/api/status fails: fail to execute the HTTP GET request: Get "https://localhost:8492/api/status": x509: certificate is not valid for any names, but wanted to match localhost. Response: .

```

I checked a little and it seems like my CA wasnt store, i just generated it with openssl to be able to generate the keys.

---

<div class="post-metadata">

**Author:** ![Klheik](https://avatars.discourse-cdn.com/v4/letter/k/76d3ee/32.png) [@Klheik](https://discuss.elastic.co/u/Klheik)\
**Post date:** [February 23, 2024, 8:37am UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/11 "2024-02-23T08:37:55Z")

</div>

and if just remove the "https://" in the metric conf file for kibana and i just use "localhost:8492" i have an other error message :

```auto
Loading dashboards (Kibana must be running and reachable)
2024-02-23T09:36:29.512+0100 WARN [cfgwarn] tlscommon/config.go:100 DEPRECATED: Treating the CommonName field on X.509 certificates as a host name when no Subject Alternative Names are present is going to be removed. Please update your certificates if needed. Will be removed in version: 8.0.0
2024-02-23T09:36:29.514+0100 INFO kibana/client.go:180 Kibana url: http://localhost:8492
2024-02-23T09:36:29.519+0100 ERROR instance/beat.go:1027 Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to http://localhost:8492/api/status fails: fail to execute the HTTP GET request: Get "http://localhost:8492/api/status": EOF. Response: .
Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to http://localhost:8492/api/status fails: fail to execute the HTTP GET request: Get "http://localhost:8492/api/status": EOF. Response: .

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 23, 2024, 12:35pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/12 "2024-02-23T12:35:28Z")

</div>

> [@Klheik](#):
>
> `setup.kibana.ssl.verification_mode: none`

Add this back, as this should make metricbeat ignore the certificate errors.

But add this as `ssl.verification_mode: none`, without the redundant `setup.kibana`.

---

<div class="post-metadata">

**Author:** ![Klheik](https://avatars.discourse-cdn.com/v4/letter/k/76d3ee/32.png) [@Klheik](https://discuss.elastic.co/u/Klheik)\
**Post date:** [February 23, 2024, 1:38pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/13 "2024-02-23T13:38:51Z")

</div>

Ok that's amazing it worked, thank you a lot man really but i have 2 questions ahah.  
First, is it normal that my metric beat isnt giving info like i have some info just when i type `metricbeat setup` and i would like info all the time not type it and then watch on kibana.  
And ths second one, disable the tls verification mode is going to be a security problem ? Like does it create some issues with the security of my server ?

Thanks a lot !!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 23, 2024, 1:55pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/14 "2024-02-23T13:55:42Z")

</div>

> [@Klheik](#):
>
> First, is it normal that my metric beat isnt giving info like i have some info just when i type `metricbeat setup` and i would like info all the time not type it and then watch on kibana.

Can you give more context on this? It is not clear wht you want, what kind of info? `metricbeat setup` will just setup the dashboards and ingest pipelines in Kibana.

> [@Klheik](#):
>
> And ths second one, disable the tls verification mode is going to be a security problem ? Like does it create some issues with the security of my server ?

This disable the verification on metricbeat side, it affects only the client.

But you already have a bigger security issue because as you mentioned you disabled TLS in Elasticsearch as well, also, from what you shared is not clear if you are using authentication or not.

---

<div class="post-metadata">

**Author:** ![Klheik](https://avatars.discourse-cdn.com/v4/letter/k/76d3ee/32.png) [@Klheik](https://discuss.elastic.co/u/Klheik)\
**Post date:** [February 23, 2024, 2:01pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/15 "2024-02-23T14:01:43Z")

</div>

I have every modules as elasticsearch logstash beats and kibana on the same server so i just enanled the authentification and enabled tls encryption for kibana because it can be acces remotly.  
For metricbeat i just want my server's health in the kibana interface but it seems like i can't unless i just type the command and i would like to have my server health accessible automatically.  
I am sorry if this is not clear but english isn't my native langage.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2024, 4:01pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891/16 "2024-03-22T16:01:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
