# SSL Configuration in Kibana

**URL:** https://discuss.elastic.co/t/ssl-configuration-in-kibana/77926
**Category:** Kibana
**Created:** [March 9, 2017, 2:48am UTC](https://discuss.elastic.co/t/ssl-configuration-in-kibana/77926 "2017-03-09T02:48:15Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)
#### Post date: [March 9, 2017, 2:48am UTC](https://discuss.elastic.co/t/ssl-configuration-in-kibana/77926/1 "2017-03-09T02:48:15Z")

</div>

My company has issued an ssl certificate in 3 formats xxxxBase64.cer, xxxxDERCert.cer and xxxx.p7b

Kibana-4.3.0 on linux machine  
I want to have ssl configuration for kibana when opened in browser, not for requests between elasticsearch and kibana.  
My elasticsearch still runs on http:// and not https://  
I have not installed shield neither on elasticsearch nor kibana. I think that ssl configuration on kibana is independent of shield, correct me if I am wrong.

I found two options in kibana  
ssl.server.cert  
ssl.server.key

Guide me if only these two configuration is sufficient.

My question is the key asked here is private or public key.  
If it is private key, then I have read on the net that .p7b files does not contain private key.  
I am not able to find solutions to generate .cert and .key from certificates issued to me.

Kindly help

---

<div class="post-metadata">

### Author: ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)
#### Post date: [March 9, 2017, 1:33pm UTC](https://discuss.elastic.co/t/ssl-configuration-in-kibana/77926/2 "2017-03-09T13:33:56Z")

</div>

@aviral_srivastava you'll want to convert the certificates into PEM format. You're on the right track for which kibana settings to use, `server.ssl.cert` and `server.ssl.key` should be a path to the PEM encoded format of the certificate and key.

The following is an example of converting the xxxxDERCert.cer: `openssl x509 -inform der -in xxxxDERCert.cer -out certificate.pem`

and you can do a similar thing for the xxxx.p7b with: `openssl pkcs7 -print_certs -in xxxx.p7b -out certificate.pem`

None of those appear to be the private key.

---

<div class="post-metadata">

### Author: ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)
#### Post date: [March 10, 2017, 1:19pm UTC](https://discuss.elastic.co/t/ssl-configuration-in-kibana/77926/3 "2017-03-10T13:19:45Z")

</div>

> [@Brandon\_Kobel](#):
>
> pkcs7 -print\_certs -in xxxx.p7b -out certificate.pem

Hi Brandon\_Kobel,

I tried both of your commands:-

1. In first command , certificate.pem file is not created and there are also no warnings.
2. In second command for.p7b file I am getting  
unable to load PKCS7 object  
12576:error:0906D06C:PEM routines:PEM\_read\_bio:no start line:./crypto/pem/pem\_lib.c:647:Expecting: PKCS7  
error in pkcs7

And about the private key, how can I check for private key ? or what is telling there is no private key ?

---

<div class="post-metadata">

### Author: ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)
#### Post date: [March 14, 2017, 12:37pm UTC](https://discuss.elastic.co/t/ssl-configuration-in-kibana/77926/4 "2017-03-14T12:37:36Z")

</div>

Hi Brandon\_Kobel,

I have generated the ssl certificate and key on linux machine.  
When I am starting kibana.  
In the log it says:-  
log [17:49:38.853] [info][status][plugin:kibana] Status changed from uninitialized to green - Ready  
log [17:49:38.925] [info][status][plugin:elasticsearch] Status changed from uninitialized to yellow - Waiting for Elasticsearch  
log [17:49:38.965] [info][status][plugin:kbn\_vislib\_vis\_types] Status changed from uninitialized to green - Ready  
log [17:49:38.977] [info][status][plugin:markdown\_vis] Status changed from uninitialized to green - Ready  
log [17:49:38.994] [info][status][plugin:metric\_vis] Status changed from uninitialized to green - Ready  
log [17:49:39.002] [info][status][plugin:spyModes] Status changed from uninitialized to green - Ready  
log [17:49:39.009] [info][status][plugin:elasticsearch] Status changed from yellow to green - Kibana index ready  
log [17:49:39.013] [info][status][plugin:statusPage] Status changed from uninitialized to green - Ready  
log [17:49:39.021] [info][status][plugin:table\_vis] Status changed from uninitialized to green - Ready  
log [17:49:39.046] [info][listening] Server running at [https://xx.xx.xx.xxx:8601](https://xx.xx.xx.xxx:8601)

But on browser, it shows Not secure( in red colour ), although kibana running. Do I need to install the ssl certificate on linux machine too.  
Can you guide me with the installation.

---

<div class="post-metadata">

### Author: ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)
#### Post date: [March 15, 2017, 6:09pm UTC](https://discuss.elastic.co/t/ssl-configuration-in-kibana/77926/5 "2017-03-15T18:09:14Z")

</div>

@aviral_srivastava yes, you'll have to install the public certificate so Linux recognizes it. Which linux distro are you using?

---

<div class="post-metadata">

### Author: ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)
#### Post date: [March 16, 2017, 4:00am UTC](https://discuss.elastic.co/t/ssl-configuration-in-kibana/77926/6 "2017-03-16T04:00:55Z")

</div>

Hi Brandon,

My Linux distro is :-  
Red Hat Enterprise Linux Server release 7.2 (Maipo)

---

<div class="post-metadata">

### Author: ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)
#### Post date: [March 16, 2017, 12:02pm UTC](https://discuss.elastic.co/t/ssl-configuration-in-kibana/77926/7 "2017-03-16T12:02:50Z")

</div>

@aviral_srivastava you'll need to install the certificate in your certificate database so that your computer/browsers knows to trust the self-signed certificate. There are a few ways to do so per [https://access.redhat.com/documentation/en-US/Red\_Hat\_Certificate\_System/8.1/html/Admin\_Guide/Managing\_the\_Certificate\_Database.html#Installing\_Certificates\_in\_the\_Certificate\_System\_Database](https://access.redhat.com/documentation/en-US/Red_Hat_Certificate_System/8.1/html/Admin_Guide/Managing_the_Certificate_Database.html#Installing_Certificates_in_the_Certificate_System_Database)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 13, 2017, 12:03pm UTC](https://discuss.elastic.co/t/ssl-configuration-in-kibana/77926/8 "2017-04-13T12:03:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
