# Self-signed certificate in the chain

**URL:** https://discuss.elastic.co/t/self-signed-certificate-in-the-chain/324715
**Category:** Kibana
**Tags:** elastic-stack-security, fleet
**Created:** [February 4, 2023, 4:44pm UTC](https://discuss.elastic.co/t/self-signed-certificate-in-the-chain/324715 "2023-02-04T16:44:13Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Leonardo\_Henrique](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leonardo_henrique/32/79658_2.png) [@Leonardo\_Henrique](https://discuss.elastic.co/u/Leonardo_Henrique)
#### Post date: [February 4, 2023, 4:44pm UTC](https://discuss.elastic.co/t/self-signed-certificate-in-the-chain/324715/1 "2023-02-04T16:44:13Z")

</div>

Hey everyone! How have you been?

I configured the SSL for the Elastic cluster using the elasticsearch-certutil. So far, elasticsearch nodes can reach out each other, the Kibana can communicate with them and both are being accessed with https, but I am having a problem with integrations/fleet.

When I try to open the page nothing loads and in the logs I can see "Self-signed certificate in the chain". I set in kibana.yml the entry for kibana to trust in the Elastic certirficate (elasticsearch.ssl.certificateAuthorities: /etc/kibana/elasticsearch-ca.pem) file gererated when running elasticsearch-certutil http.  
Both Kibana and ES nodes are CentOS.

I also configured the proxy I am using with xpack.fleet.registryProxyUrl.

Could anyone help me to solve that?

I followed these two pages of documentation: [Set up basic security for the Elastic Stack | Elasticsearch Guide [8.6] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup.html) and [Set up basic security for the Elastic Stack plus secured HTTPS traffic | Elasticsearch Guide [8.6] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup-https.html)

---

<div class="post-metadata">

### Author: ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)
#### Post date: [February 8, 2023, 12:16am UTC](https://discuss.elastic.co/t/self-signed-certificate-in-the-chain/324715/2 "2023-02-08T00:16:55Z")

</div>

> [@Leonardo\_Henrique](#):
>
> When I try to open the page nothing loads and in the logs I can see "Self-signed certificate in the chain"

Does this mean you try to reach kibana's URL using a browser? If so, what certificate is used by Kibana itself (configured with Kibana settings like `server.ssl.certificate` and `server.ssl.key`)? If the certificate is self-signed, browsers won't automatically accept them. Unless this is a dev environment, you might want to consider using certs signed by a trusted CA as suggested by the [doc](https://www.elastic.co/guide/en/elasticsearch/reference/8.6/security-basic-setup-https.html#encrypt-kibana-browser).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 8, 2023, 12:17am UTC](https://discuss.elastic.co/t/self-signed-certificate-in-the-chain/324715/3 "2023-03-08T00:17:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
