# Mixed Content: This request has been blocked; the content must be served over HTTPS

**URL:** <https://discuss.elastic.co/t/mixed-content-this-request-has-been-blocked-the-content-must-be-served-over-https/310425>\
**Category:** Elastic Search\
**Tags:** docker, elastic-app-search\
**Created:** [July 22, 2022, 9:04pm UTC](https://discuss.elastic.co/t/mixed-content-this-request-has-been-blocked-the-content-must-be-served-over-https/310425 "2022-07-22T21:04:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rustin\_Spencer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rustin_spencer/32/103495_2.png) [@Rustin\_Spencer](https://discuss.elastic.co/u/Rustin_Spencer)\
**Post date:** [July 22, 2022, 9:04pm UTC](https://discuss.elastic.co/t/mixed-content-this-request-has-been-blocked-the-content-must-be-served-over-https/310425/1 "2022-07-22T21:04:48Z")

</div>

Do I have to run Enterprise Search over HTTPS? How can I configure SSL/TLS on Enterprise Search.  
I'm running with docker-compose. I've read this [Configure SSL/TLS | Elastic Enterprise Search documentation [8.4] | Elastic](https://www.elastic.co/guide/en/enterprise-search/current/configure-ssl-tls.html), not quite understand what exactly do I have to do.

---

<div class="post-metadata">

**Author:** ![Sean\_Story](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean_story/32/69987_2.png) [@Sean\_Story](https://discuss.elastic.co/u/Sean_Story)\
**Post date:** [July 22, 2022, 10:05pm UTC](https://discuss.elastic.co/t/mixed-content-this-request-has-been-blocked-the-content-must-be-served-over-https/310425/2 "2022-07-22T22:05:47Z")

</div>

Hi @Rustin_Spencer ,

Docker compose allows you to pass Enterprise Search configurations as environment variables. You need to follow the guide that you'd linked to create yourself an SSL certificate and trust store, configure Enterprise Search to use that certificate and trust store through your docker-compose file, and then configure Kibana to trust that certificate. All of this is described in the guide you've linked. Is there a specific question that you have?

---

<div class="post-metadata">

**Author:** ![Rustin\_Spencer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rustin_spencer/32/103495_2.png) [@Rustin\_Spencer](https://discuss.elastic.co/u/Rustin_Spencer)\
**Post date:** [July 23, 2022, 11:00pm UTC](https://discuss.elastic.co/t/mixed-content-this-request-has-been-blocked-the-content-must-be-served-over-https/310425/3 "2022-07-23T23:00:09Z")

</div>

I don't understand enterprise search SSL certificate creation. How can I get .crt and .key files?

---

<div class="post-metadata">

**Author:** ![Sean\_Story](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean_story/32/69987_2.png) [@Sean\_Story](https://discuss.elastic.co/u/Sean_Story)\
**Post date:** [July 25, 2022, 2:00pm UTC](https://discuss.elastic.co/t/mixed-content-this-request-has-been-blocked-the-content-must-be-served-over-https/310425/4 "2022-07-25T14:00:31Z")

</div>

You need to read and follow that guide that you linked. It gives very explicit instructions:

> In a development environment (do not use this in production), you can use they they `keytool` command to create a self-signed certificate and add it to a keystore for use with a server running on `localhost`:
> 
> `keytool -genkey -alias server-alias -keyalg RSA \ -storepass changeme -keypass changeme -keystore keystore.jks \ -dname 'CN=localhost, OU=Unknown, O=Unknown, L=Unknown, ST=Unknown, C=Unknown'`
> 
> Note that the values used in `-keypass changeme` and `-storepass changeme` correspond directly to the values that must be set for `ent_search.ssl.keystore.key_password` and `ent_search.ssl.keystore.password`, respectively.

If you're not familiar with the terminology, you may first want to read up on SSL/TLS, Certificates/Keys, and Certificate Authorities:

- [Public key certificate - Wikipedia](https://en.wikipedia.org/wiki/Public_key_certificate)
- [Certificate authority - Wikipedia](https://en.wikipedia.org/wiki/Certificate_authority)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2022, 2:01pm UTC](https://discuss.elastic.co/t/mixed-content-this-request-has-been-blocked-the-content-must-be-served-over-https/310425/5 "2022-08-22T14:01:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
