# Received plaintext http traffic on an https channel

**URL:** <https://discuss.elastic.co/t/received-plaintext-http-traffic-on-an-https-channel/286987>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 18, 2021, 11:53am UTC](https://discuss.elastic.co/t/received-plaintext-http-traffic-on-an-https-channel/286987 "2021-10-18T11:53:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![armughan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/armughan/32/95804_2.png) [@armughan](https://discuss.elastic.co/u/armughan)\
**Post date:** [October 18, 2021, 11:53am UTC](https://discuss.elastic.co/t/received-plaintext-http-traffic-on-an-https-channel/286987/1 "2021-10-18T11:53:10Z")

</div>

I'm configuring a single node Elasticsearch & Kibana (7.15.1) set up with FQDN behind Nginx Proxy on a single EC2 instance.  
Everything is correctly set up when I tried to turn on Alerts in heartbeat (Observability) it said to set up SSL/TLS communication between Kibana & Elasticsearch. from the articles on [Elastic.co](http://Elastic.co) I have added the below configuration but having log in Elasticsearch even after turning off kibana.

```auto
 received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=/127.0.0.1:9200, remoteAddress=/127.0.0.1:60414}

```

These are the configuration added for TLS/SSL set u in Elasticsearch

```auto
xpack.security.enabled: true
xpack.security.http.ssl.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.authc.api_key.enabled: true
xpack.security.authc.api_key.hashing.algorithm: pbkdf2
xpack.security.http.ssl.key: /etc/elasticsearch/ssl/privkey.pem
xpack.security.http.ssl.certificate: /etc/elasticsearch/ssl/fullchain.pem
xpack.security.http.ssl.supported_protocols: ["TLSv1.2", "TLSv1.1"]

```

Please any one help me in this issue.

---

<div class="post-metadata">

**Author:** ![Roberto\_Seldner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto_seldner/32/85416_2.png) [@Roberto\_Seldner](https://discuss.elastic.co/u/Roberto_Seldner)\
**Post date:** [October 19, 2021, 1:51am UTC](https://discuss.elastic.co/t/received-plaintext-http-traffic-on-an-https-channel/286987/2 "2021-10-19T01:51:21Z")

</div>

Welcome Armughan. What does your heartbeat output config look like? Is it still using http (default)?

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 19, 2021, 6:54pm UTC](https://discuss.elastic.co/t/received-plaintext-http-traffic-on-an-https-channel/286987/3 "2021-10-19T18:54:24Z")

</div>

> [@armughan](#):
>
> `remoteAddress`

Hi @armughan,

Usually the beat agent or node sending the information via http is specified in the remote address. You can then check that this is sending information via http to the https endpoint.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2021, 6:55pm UTC](https://discuss.elastic.co/t/received-plaintext-http-traffic-on-an-https-channel/286987/4 "2021-11-16T18:55:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
