# Setting up TLS

**URL:** <https://discuss.elastic.co/t/setting-up-tls/254905>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [November 10, 2020, 12:38pm UTC](https://discuss.elastic.co/t/setting-up-tls/254905 "2020-11-10T12:38:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [November 10, 2020, 12:38pm UTC](https://discuss.elastic.co/t/setting-up-tls/254905/1 "2020-11-10T12:38:44Z")

</div>

Hi,  
I am trying to set up TLS encryption for accessing Kibana internally.  
I am trying to follow the following article: [Setting up TLS on a cluster | Elasticsearch Reference [7.9] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/ssl-tls.html)

On the first step in creating the X.509 certificate, I am struggling to run the following options, as I need to include the FQDN and IP address of the server in the certificate:

If you want to use hostname verification within your cluster, run the `elasticsearch-certutil cert` command once for each of your nodes and provide the `--name` , `--dns` and `--ip` options.

When I run the following command, it gives me an error, so not really sure if I am running it correctly:

```
`elasticsearch-certutil.bat cert --ca --name FQDN.local --dns FQDN.local --ip 10.10.10.10 elastic-ca.p12`

```

I am getting the following error:

```auto
Enter password for CA (--name) : I ENTER CA PASSWORD HERE
Exception in thread "main" java.nio.file.NoSuchFileException: --name
        at java.base/sun.nio.fs.WindowsException.translateToIOException(WindowsException.java:85)
        at java.base/sun.nio.fs.WindowsException.rethrowAsIOException(WindowsException.java:103)
        at java.base/sun.nio.fs.WindowsException.rethrowAsIOException(WindowsException.java:108)
        at java.base/sun.nio.fs.WindowsFileSystemProvider.newByteChannel(WindowsFileSystemProvider.java:235)
        at java.base/java.nio.file.Files.newByteChannel(Files.java:375)
        at java.base/java.nio.file.Files.newByteChannel(Files.java:426)
        at java.base/java.nio.file.spi.FileSystemProvider.newInputStream(FileSystemProvider.java:420)
        at java.base/java.nio.file.Files.newInputStream(Files.java:160)
        at org.elasticsearch.xpack.core.ssl.CertParsingUtils.readKeyStore(CertParsingUtils.java:72)
        at org.elasticsearch.xpack.core.ssl.CertParsingUtils.readKeyPairsFromKeystore(CertParsingUtils.java:141)
        at org.elasticsearch.xpack.core.ssl.CertParsingUtils.readPkcs12KeyPairs(CertParsingUtils.java:134)
        at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.lambda$loadPkcs12CA$1(CertificateTool.java:342)
        at org.elasticsearch.xpack.security.cli.CertificateTool.withPassword(CertificateTool.java:933)
        at org.elasticsearch.xpack.security.cli.CertificateTool.access$100(CertificateTool.java:85)
        at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.loadPkcs12CA(CertificateTool.java:341)
        at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.getCAInfo(CertificateTool.java:329)
        at org.elasticsearch.xpack.security.cli.CertificateTool$GenerateCertificateCommand.execute(CertificateTool.java:685)
        at org.elasticsearch.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:86)
        at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:127)
        at org.elasticsearch.cli.MultiCommand.execute(MultiCommand.java:91)
        at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:127)
        at org.elasticsearch.cli.Command.main(Command.java:90)
        at org.elasticsearch.xpack.security.cli.CertificateTool.main(CertificateTool.java:137)

D:\Elastic\Elastic-7.9.2\7.9.2\bin>

```

Any help would be greatly appreciated. Thanks

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [November 11, 2020, 1:54am UTC](https://discuss.elastic.co/t/setting-up-tls/254905/2 "2020-11-11T01:54:48Z")

</div>

> [@Craig2188](#):
>
> I am trying to set up TLS encryption for accessing Kibana internally.

Can you clarify what you mean here?

The step you seem to be performing is to generate certificates for your nodes to use when they connect to one another. That's important, but it doesn't have anything to do with Kibana. It's possible (depending on your circumstances) that you're making this step harder than it needs to be. For example, you are electing to generate a certificate per node, which is a fine thing to do, but it's harder, and isn't really necessary for the task that I think you're actually trying to do.

> [@Craig2188](#):
>
> ```auto
> `elasticsearch-certutil.bat cert --ca --name FQDN.local --dns FQDN.local --ip 10.10.10.10 elastic-ca.p12`
> 
> ```

The `--ca` option needs an argument that is the PKCS#12 file that contains your CA.  
So your command line should be:

```auto
elasticsearch-certutil.bat cert --ca elastic-ca.p12 --name FQDN.local --dns FQDN.local --ip 10.10.10.10

```

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [November 11, 2020, 7:36am UTC](https://discuss.elastic.co/t/setting-up-tls/254905/3 "2020-11-11T07:36:22Z")

</div>

So my aim is to just secure the connections to the Kibana portal so that when logging into it, passwords are not plain text... I presume this is not correct then

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 9, 2020, 7:36am UTC](https://discuss.elastic.co/t/setting-up-tls/254905/4 "2020-12-09T07:36:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
