# SSL Certificates used in ELK stack

**URL:** <https://discuss.elastic.co/t/ssl-certificates-used-in-elk-stack/224835>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 24, 2020, 12:40pm UTC](https://discuss.elastic.co/t/ssl-certificates-used-in-elk-stack/224835 "2020-03-24T12:40:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vladtepes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vladtepes/32/64982_2.png) [@vladtepes](https://discuss.elastic.co/u/vladtepes)\
**Post date:** [March 24, 2020, 12:40pm UTC](https://discuss.elastic.co/t/ssl-certificates-used-in-elk-stack/224835/1 "2020-03-24T12:40:51Z")

</div>

Greetings!

I am a rookie, getting started with ElasticSearch and have a question regarding the SSL certificates used in the ELK stack.  
From what I've read in the guides, an SSL certificate is needed for Kibana, but for Elasticsearch I am unsure which SANs are needed. In this [topic](https://discuss.elastic.co/t/using-single-certificate-which-contains-multiple-sans/148469) it is said that it needs to have the node hostnames and not a single URL. (like for typical web applications) This would mean when new nodes are added the certificate needs to be re-issued and I would like to avoid that.  
I also wanted to know to what extent can F5 loadbalancing be used? I read that there is also a coordinator role, which is a bit like a loadbalancer. So can F5 be used for Kibana load-balancing and what about the ingestion? (it is also documented that it needs to be pointed to a master node)  
I plan to build up as a start a 3 node cluster with master and data roles.

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [March 24, 2020, 1:00pm UTC](https://discuss.elastic.co/t/ssl-certificates-used-in-elk-stack/224835/2 "2020-03-24T13:00:20Z")

</div>

Hello @vladtepes,

I am just starting with SSL with Elasticsearch so I am by no means an expert.

I have setup my own CA and plan to use a wildcard cert for \*.mydomain.com. That way I can use the same SSL certs for the whole cluster and add nodes as I like. That is the plan, not fully tested yet...

How do you put data into Elasticsearch? If you use Logstash or Filebeat, they offer load-balancing for writing to Elasticsearch. For Kibana, you can put a load-balancer in front, like most other web services. I use Nginx in front of Kibana. Nginx does the SSL termination and the group of Kibana instances are listed as HTTP backends/upstreams.

---

<div class="post-metadata">

**Author:** ![vladtepes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vladtepes/32/64982_2.png) [@vladtepes](https://discuss.elastic.co/u/vladtepes)\
**Post date:** [March 24, 2020, 1:21pm UTC](https://discuss.elastic.co/t/ssl-certificates-used-in-elk-stack/224835/3 "2020-03-24T13:21:47Z")

</div>

Unfortunately a wildcard certificate is not an option in our environment. I do plan to use Logstash and Filebeat.  
So then only Kibana can be load-balanced using F5, it seems.  
Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2020, 1:21pm UTC](https://discuss.elastic.co/t/ssl-certificates-used-in-elk-stack/224835/4 "2020-04-21T13:21:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
