# SSL configuration not working in kibana on Linux

**URL:** https://discuss.elastic.co/t/ssl-configuration-not-working-in-kibana-on-linux/78640
**Category:** Kibana
**Created:** [March 15, 2017, 5:24am UTC](https://discuss.elastic.co/t/ssl-configuration-not-working-in-kibana-on-linux/78640 "2017-03-15T05:24:28Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)
#### Post date: [March 15, 2017, 5:24am UTC](https://discuss.elastic.co/t/ssl-configuration-not-working-in-kibana-on-linux/78640/1 "2017-03-15T05:24:28Z")

</div>

Hi,  
**Red Hat Enterprise Linux Server release 7.2 (Maipo)**  
**Kibana-4.3.0-linux-x64**  
**elasticsearch 2.1.1**

I am trying to configure ssl on kibana.  
The steps I followed:-

1. **Generated private key**  
openssl genrsa -out privatekey.key 2048  
The above command created a file names privatekey.key .

2. **Genrated CSR**  
openssl req -new -key privatekey.key -out linux.csr  
Entered the details this csr asked. and then linux.csr file was created.

3. **I submitted this linux.csr to my organization and I was issued a certificate certnew.cer**  
The certificate contents were like:  
-----BEGIN CERTIFICATE-----  
-----END CERTIFICATE-----

4. **Now kibana-4.3.0-linux-x64 folder was present on home path of linux machine**  
I made the following changes to kibana.yml file  
ssl.server..cert : certnew.cer  
ssl.server.key : privatekey.key

5. **Now, I start kibana and get the following log:-**  
In the log it says:-  
log [17:49:38.853] [info][status][plugin:kibana] Status changed from uninitialized to green - Ready  
log [17:49:38.925] [info][status][plugin:elasticsearch] Status changed from uninitialized to yellow - Waiting for Elasticsearch  
log [17:49:38.965] [info][status][plugin:kbn\_vislib\_vis\_types] Status changed from uninitialized to green - Ready  
log [17:49:38.977] [info][status][plugin:markdown\_vis] Status changed from uninitialized to green - Ready  
log [17:49:38.994] [info][status][plugin:metric\_vis] Status changed from uninitialized to green - Ready  
log [17:49:39.002] [info][status][plugin:spyModes] Status changed from uninitialized to green - Ready  
log [17:49:39.009] [info][status][plugin:elasticsearch] Status changed from yellow to green - Kibana index ready  
log [17:49:39.013] [info][status][plugin:statusPage] Status changed from uninitialized to green - Ready  
log [17:49:39.021] [info][status][plugin:table\_vis] Status changed from uninitialized to green - Ready  
log [17:49:39.046] [info][listening] Server running at [https://xx.xx.xx.xxx:8601](https://xx.xx.xx.xxx:8601)

6. **In the Browser when I try to open [https://xx.xx.xx.xxx:8601](https://xx.xx.xx.xxx:8601). It runs but it is specified as Not secure and https is crossed in red colour.**  
Can anybody help me what steps I am missing ?

---

<div class="post-metadata">

### Author: ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)
#### Post date: [March 15, 2017, 8:18pm UTC](https://discuss.elastic.co/t/ssl-configuration-not-working-in-kibana-on-linux/78640/2 "2017-03-15T20:18:02Z")

</div>

@aviral_srivastava you'll need to install the certificate in your certificate database so that your computer/browsers knows to trust the self-signed certificate. There are a few ways to do so per [https://access.redhat.com/documentation/en-US/Red\_Hat\_Certificate\_System/8.1/html/Admin\_Guide/Managing\_the\_Certificate\_Database.html#Installing\_Certificates\_in\_the\_Certificate\_System\_Database](https://access.redhat.com/documentation/en-US/Red_Hat_Certificate_System/8.1/html/Admin_Guide/Managing_the_Certificate_Database.html#Installing_Certificates_in_the_Certificate_System_Database)

---

<div class="post-metadata">

### Author: ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)
#### Post date: [March 16, 2017, 12:25pm UTC](https://discuss.elastic.co/t/ssl-configuration-not-working-in-kibana-on-linux/78640/3 "2017-03-16T12:25:04Z")

</div>

Hi Brandon,

I have added the certnew.cer and privatekey.key to all these, but still my kibana runs on Not secure connection :

./etc/pki/nssdb/cert8.db  
./etc/httpd/alias/cert8.db  
./etc/ipsec.d/cert8.db

Please guide me ?

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [March 19, 2017, 11:45pm UTC](https://discuss.elastic.co/t/ssl-configuration-not-working-in-kibana-on-linux/78640/4 "2017-03-19T23:45:14Z")

</div>

> [@aviral\_srivastava](#):
>
> It runs but it is specified as Not secure and https is crossed in red colour.

The first step is to dig into the details of that error and see exactly what is causing the problem.

The exact steps will depend on which browser you are running, but you need to pull up the security/certificate details for your site, and see what the browser thinks is wrong.

In recent versions of Chrome that requires opening up the developer tools, and then selecting the "security" tab.

In Firefox, you can click on the `Not Secure` mark and then navigate through to the certificate details.

Depending on what the browser thinks the problem is, we might be able to offer advice on the next steps to take.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 16, 2017, 11:45pm UTC](https://discuss.elastic.co/t/ssl-configuration-not-working-in-kibana-on-linux/78640/5 "2017-04-16T23:45:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
