# SSL Alert Number 46 in Kibana.log

**URL:** https://discuss.elastic.co/t/ssl-alert-number-46-in-kibana-log/186405
**Category:** Kibana
**Created:** [June 19, 2019, 8:00am UTC](https://discuss.elastic.co/t/ssl-alert-number-46-in-kibana-log/186405 "2019-06-19T08:00:58Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![vsalunkhe](https://avatars.discourse-cdn.com/v4/letter/v/eada6e/32.png) [@vsalunkhe](https://discuss.elastic.co/u/vsalunkhe)
#### Post date: [June 19, 2019, 8:00am UTC](https://discuss.elastic.co/t/ssl-alert-number-46-in-kibana-log/186405/1 "2019-06-19T08:00:58Z")

</div>

Hi,

I am seeing the below issue in kiabna.log

**{"type":"error","@timestamp":"2019-06-19T07:47:31Z","tags":["connection","client","error"],"pid":122332,"level":"error","error":{"message":"139992275834752:error:14094416:SSL routines:ssl3\_read\_bytes:sslv3 alert certificate unknown:../deps/openssl/openssl/ssl/record/rec\_layer\_s3.c:1407:SSL alert number 46\n","name":"Error","stack":"Error: 139992275834752:error:14094416:SSL routines:ssl3\_read\_bytes:sslv3 alert certificate unknown:../deps/openssl/openssl/ssl/record/rec\_layer\_s3.c:1407:SSL alert number 46\n"},"message":"139992275834752:error:14094416:SSL routines:ssl3\_read\_bytes:sslv3 alert certificate unknown:../deps/openssl/openssl/ssl/record/rec\_layer\_s3.c:1407:SSL alert number 46\n"}**

I have created separate set of self-signed certificates for kibana server and imported the same Client Certificate in Browser--\> Personal Certificates

I have also imported the ca.crt used to sign the above client certificate in the Trusted Root Certification Authorities of the browser.

I dont get errors when I access from my machines browser. and the https is not strikethrough.

But when I copy the same set of certificates to my colleague's browser with same process, it still shows the error.

Also there is no IP or Hostname in the Error Message to identify exactly from where the logs are generated.

---

<div class="post-metadata">

### Author: ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)
#### Post date: [June 19, 2019, 3:16pm UTC](https://discuss.elastic.co/t/ssl-alert-number-46-in-kibana-log/186405/2 "2019-06-19T15:16:39Z")

</div>

Hi, could you provide the steps you used to generate the certificate on your machine?

---

<div class="post-metadata">

### Author: ![vsalunkhe](https://avatars.discourse-cdn.com/v4/letter/v/eada6e/32.png) [@vsalunkhe](https://discuss.elastic.co/u/vsalunkhe)
#### Post date: [June 20, 2019, 1:38pm UTC](https://discuss.elastic.co/t/ssl-alert-number-46-in-kibana-log/186405/3 "2019-06-20T13:38:39Z")

</div>

vim kibanacert.yml  
instances:

- name: "kibana-server"  
dns:  
- "[kibanadv.nseroot.com](http://kibanadv.nseroot.com)"

bin/elasticsearch-certutil cert --silent --pem --in kibanacert.yml --out kibana-server.zip  
copy the zip file to kibana installation directory

The two certificates need to be installed as follows:

1. **kibana-server.p12** -- this is the client certificate

2. **ca.crt** -- This we need to add in the Trusted Root Certificate, to tell the browser that the certificate (mentioned in point no.1 ) is signed by a Trusted Source.

---

<div class="post-metadata">

### Author: ![AndrewMcQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewmcq/32/23131_2.png) [@AndrewMcQ](https://discuss.elastic.co/u/AndrewMcQ)
#### Post date: [July 5, 2019, 2:44pm UTC](https://discuss.elastic.co/t/ssl-alert-number-46-in-kibana-log/186405/4 "2019-07-05T14:44:34Z")

</div>

+1 We're seeing something similar. Watching thread to see if the solution would be applicable to us.

We don't have errors hitting Kibana normally... we're just seeing these alerts every now and then in big batches.

---

<div class="post-metadata">

### Author: ![anapsix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anapsix/32/51440_2.png) [@anapsix](https://discuss.elastic.co/u/anapsix)
#### Post date: [August 1, 2019, 1:58pm UTC](https://discuss.elastic.co/t/ssl-alert-number-46-in-kibana-log/186405/5 "2019-08-01T13:58:02Z")

</div>

check out this thread: [Encrypting communications in Kibana](https://discuss.elastic.co/t/encrypting-communications-in-kibana/186369/3)

in short: **Due to clients(Web Browsers) not trusting self-signed Kibana certificates, you will see a message similar to the following in your Kibana logs, until proper trust is established by using certificates generated by an enterprise or public CA** (here's the [link to the issue in the Kibana repo](https://github.com/elastic/kibana/issues/35004)). This issue does not affect your ability to work in Kibana:

```auto
[18:22:31.675] [error][client][connection] Error: 4443837888:error:14094416:SSL routines:ssl3_read_bytes:sslv3 alert certificate unknown:../deps/openssl/openssl/ssl/s3_pkt.c:1498:SSL alert number 46

```

As a result, Kibana's error logs is normal.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 29, 2019, 1:58pm UTC](https://discuss.elastic.co/t/ssl-alert-number-46-in-kibana-log/186405/6 "2019-08-29T13:58:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
