# Reverse Proxy & Security Questions

**URL:** <https://discuss.elastic.co/t/reverse-proxy-security-questions/256972>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [November 29, 2020, 2:18am UTC](https://discuss.elastic.co/t/reverse-proxy-security-questions/256972 "2020-11-29T02:18:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ganymede](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@Ganymede](https://discuss.elastic.co/u/Ganymede)\
**Post date:** [November 29, 2020, 2:18am UTC](https://discuss.elastic.co/t/reverse-proxy-security-questions/256972/1 "2020-11-29T02:18:46Z")

</div>

Hello ES & Kibana aficionados!

I'm very new to this whole topic (ES/Kibana/Network Security) and have some burning questions I'm certain you can help me out with.

**General Setup:**

- Connection occurs via Citrix VPN.

- ES & Kibana on a server inside a network as services.

- ES has 1 node.

- ES & Kibana are running on the same physical machine.

- Standard passwords have been changed.

- User passwords added to the trust store and been removed from the kibana.yml file.

- XPACK Security is enabled and Kibana asks for login credentials.

- Both Kibana and ES are inplemented with SSL ([https://internal-ip:5601](https://internal-ip:5601) & [https://localhost:9200](https://localhost:9200)).

- Cert.crt & Cert.key were created with ES's certutil and the links to the files provided in the elasticsearch.yml and kibana.yml files.

**Everything is running fine so far.**

**Now my questions:**  
Did I miss a step in order to make my setup secure? Especially on the self signed certificate part.  
Just generating .crt. & .key seemed a little bit too easy for my taste.  
certutil just asked for the format (.pem), optional password and the name. Thats it? Did I miss a step?

Is there any good reason to set up a reverse proxy for both services (since my server is inside the network and theres only 1 node I guess a reverse proxy would be pretty much pointless or not?

Thanks in advance,  
Happy loggong!

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [November 30, 2020, 10:24am UTC](https://discuss.elastic.co/t/reverse-proxy-security-questions/256972/2 "2020-11-30T10:24:13Z")

</div>

Looks pretty good to me. In order for someone to have access to those certificates to be able to decrypt the communication they would need physical access to your machine. Then you have more problems than certificates. 😃  
If you followed everything in this guide, you should be good: [https://www.elastic.co/guide/en/elasticsearch/reference/current/security-getting-started.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-getting-started.html)

---

<div class="post-metadata">

**Author:** ![Ganymede](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@Ganymede](https://discuss.elastic.co/u/Ganymede)\
**Post date:** [December 11, 2020, 2:37am UTC](https://discuss.elastic.co/t/reverse-proxy-security-questions/256972/3 "2020-12-11T02:37:27Z")

</div>

Thank you. Haha good point. I believe so. I was just worried because everything went so awkwardly smooth while setting this up.

Thaks again 🙂

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [December 28, 2020, 12:45pm UTC](https://discuss.elastic.co/t/reverse-proxy-security-questions/256972/4 "2020-12-28T12:45:05Z")

</div>

I am happy that it went smooth. It was one of our goals during internal development after we required SSL/TLS for communications in production. Normally certificates are a headache for people that don't deal with them on a daily basis and we tried to make it straightforward as possible.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 25, 2021, 12:45pm UTC](https://discuss.elastic.co/t/reverse-proxy-security-questions/256972/5 "2021-01-25T12:45:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
