# On-prem Kibana can't join elastic-package-registry (EPR) behind a proxy due to certificate issue - workaround tested

**URL:** <https://discuss.elastic.co/t/on-prem-kibana-cant-join-elastic-package-registry-epr-behind-a-proxy-due-to-certificate-issue-workaround-tested/324486>\
**Category:** Kibana\
**Created:** [February 1, 2023, 10:20pm UTC](https://discuss.elastic.co/t/on-prem-kibana-cant-join-elastic-package-registry-epr-behind-a-proxy-due-to-certificate-issue-workaround-tested/324486 "2023-02-01T22:20:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![antoine\_duriez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/antoine_duriez/32/70402_2.png) [@antoine\_duriez](https://discuss.elastic.co/u/antoine_duriez)\
**Post date:** [February 1, 2023, 10:20pm UTC](https://discuss.elastic.co/t/on-prem-kibana-cant-join-elastic-package-registry-epr-behind-a-proxy-due-to-certificate-issue-workaround-tested/324486/1 "2023-02-01T22:20:35Z")

</div>

Hi,  
I have an on-prem stack 8.5.3 on RHEL 8 with high customer's restriction.  
Access to internet is done throught a proxy.  
Access to [epr. elastic.co](https://epr.elastic.co/) was opened and tested well with the command:

```auto
nc epr.elastic.co 443 -x [PROXY]:8080

```

I have setup the kibana variable xpack.fleet.registryProxyUrl in the kibana.yml.  
But, when I started kibana I had this error in the log:

```auto
"message":"Failed to fetch latest version of synthetics from registry: Error connecting to package registry: request to https://epr.elastic.co/search?package=synthetics&experimental=true&kibana.version=8.5.3 failed, reason: write EPROTO 140442458298304:error:1408F10B:SSL routines:ssl3_get_record:wrong version number:../deps/openssl/openssl/ssl/record/ssl3_record.c:332:\n","log":{"level":"ERROR","logger":"plugins.fleet"},"process":{"pid":772042},"trace":{"id":"a442a55639a3c988c1b5aaeae4c3e6ea"},"transaction":{"id":"cd123646eda8e425"}}

```

After a long search I found some tips about the NODE\_EXTRA\_CA\_CERTS variable [here](https://discuss.elastic.co/t/kibana-fleet-error-connecting-to-package-registry/257956/7)

But this not solved my issue.  
In the same time, I saw that this variable is link to NodeJS and some other articles refers to another variable [here](https://github.com/elastic/app-search-node/issues/25)

So I use it and now it's working fine.  
This is the detailed fix:  
open file /etc/sysconfig/kibana  
Add the following line:

```auto
NODE_TLS_REJECT_UNAUTHORIZED=0

```

Restart Kibana and "Le tour est joué" !  
Kibana reach now the EPR and is able to download elastic-agent integrations.

Regards.  
Antoine

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2023, 10:21pm UTC](https://discuss.elastic.co/t/on-prem-kibana-cant-join-elastic-package-registry-epr-behind-a-proxy-due-to-certificate-issue-workaround-tested/324486/2 "2023-03-01T22:21:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
