# SHA2 cert on 4.6.4 kibana

**URL:** <https://discuss.elastic.co/t/sha2-cert-on-4-6-4-kibana/89763>\
**Category:** Kibana\
**Created:** [June 16, 2017, 6:41pm UTC](https://discuss.elastic.co/t/sha2-cert-on-4-6-4-kibana/89763 "2017-06-16T18:41:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [June 16, 2017, 6:41pm UTC](https://discuss.elastic.co/t/sha2-cert-on-4-6-4-kibana/89763/1 "2017-06-16T18:41:05Z")

</div>

I have a newly created certificate that I want to use to secure browser-to-kibana communication. Our previous cert was sha1 and the new one is sha2 and it is issued by a different certificate authority. After editing the kibana.yml and restarting kibana I get an error saying the certificate is not trusted and offering the "I understand the risk" option of adding an exception, something I don't want to have to do.

A couple things cross my mind:

1. is kibana 4.6.4 capable of using a sha2 cert?
2. does my truststore have my new certificate authority? I suspect not but I don't know what truststore is being used. How do I determine which truststore I need to upgrade?

Craig

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [June 19, 2017, 7:12pm UTC](https://discuss.elastic.co/t/sha2-cert-on-4-6-4-kibana/89763/2 "2017-06-19T19:12:33Z")

</div>

This might depend on who you got your certificate from. I don't know a lot about this but you might have to bundle that cert and others together. Maybe this would help;

> **[Root & Intermediate Certificate Bund...](https://support.globalsign.com/customer/portal/articles/1224583-root-intermediate-certificate-bundles)**
>
> Some Apache and Java based applications require the Root & Intermediate certificates to be bundled in a single f...

But my understanding is that Kibana would just send info about the cert you configured to the user's browser, and it's that browser (not Kibana) that is trying to reconcile the chain of certs to some authority.

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2017, 7:12pm UTC](https://discuss.elastic.co/t/sha2-cert-on-4-6-4-kibana/89763/3 "2017-07-17T19:12:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
