# SSL connection between Kibana and Elasticsearch

**URL:** <https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 11, 2021, 4:47pm UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978 "2021-03-11T16:47:22Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![sk1f](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sk1f](https://discuss.elastic.co/u/sk1f)\
**Post date:** [March 11, 2021, 4:47pm UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978/1 "2021-03-11T16:47:22Z")

</div>

Hello, would like to ask for help in configuring SSL connection.  
When using https: i get this error: Error code: SSL\_ERROR\_RX\_RECORD\_TOO\_LONG.

If I try

```auto
curl --cacert /etc/kibana/elasticsearch-ca.pem https://localhost:9200/ -u elastic:pword -v

```

I receive output of :

```auto
SSL: certificate subject name 'elasticsearch' does not match target host name

```

---

<div class="post-metadata">

**Author:** ![sk1f](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sk1f](https://discuss.elastic.co/u/sk1f)\
**Post date:** [March 11, 2021, 4:58pm UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978/2 "2021-03-11T16:58:31Z")

</div>

Where or how I can change target host name or certificate subject name?

---

<div class="post-metadata">

**Author:** ![sk1f](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sk1f](https://discuss.elastic.co/u/sk1f)\
**Post date:** [March 12, 2021, 2:32am UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978/3 "2021-03-12T02:32:02Z")

</div>

After creating new certificate I receive output :

matched cert's IP address!  
SSL certificate verify ok.

- Connection #0 to host 0.0.0.0 left intact

However, same error from the browser:

Error code: SSL\_ERROR\_RX\_RECORD\_TOO\_LONG

Is that means that I have to configure browser as well or I am trying to use https on http?

---

<div class="post-metadata">

**Author:** ![sk1f](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sk1f](https://discuss.elastic.co/u/sk1f)\
**Post date:** [March 12, 2021, 5:17am UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978/4 "2021-03-12T05:17:08Z")

</div>

( sorry in advance - im new here, so there will be many silly questions 🙂

When I do

```auto
curl --insecure -X GET "https://0.0.0.0:9200/?pretty" -u elastic:pword

```

I get that "you know, you search" message.  
If i use Mozilla browser - i cant access.  
And my cluster is all gone - by that I mean I do not see filebeat, auditbeat, packetbeat - through metricbeat.

But now I am able to see Detections tab - its empty but without that "setting up" warning message.  
So this means that TLS connection established between elasticsearch and kibana?  
If so, how do I get all beats back to live? Sorry to say but it is very unclear in the guides.

For example.

```
setup.kibana.host: "https://192.0.2.255:5601"
setup.kibana.ssl.enabled: true
setup.kibana.ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]
setup.kibana.ssl.certificate: "/etc/pki/client/cert.pem"
setup.kibana.ssl.key: "/etc/pki/client/cert.key"

```

- I do not have ca.pem in kpi folder, kpi folder is empty. I dont see any .key files.  
When I was doing certificate I received elasticsearch-ssl-http.zip file, so I have unzipped it and done like so:

In elastisearch.yml :

```
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: "http.p12"

```

Afterwards,

`cp /usr/share/elasticsearch/kibana/elasticsearch-ca.pem /etc/kibana/`

into kibana config:

```
elasticsearch.ssl.certificateAuthorities: ["/etc/kibana/elasticsearch-ca.pem"]
elasticsearch.ssl.verificationMode: none

```

Please correct me if I am doing something wrong and would like to ask for advice on next steps.

---

<div class="post-metadata">

**Author:** ![sk1f](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sk1f](https://discuss.elastic.co/u/sk1f)\
**Post date:** [March 12, 2021, 8:20pm UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978/5 "2021-03-12T20:20:28Z")

</div>

Can anyone help with the issue?  
Main question is how do I properly secure Kibana and Elasticsearch + all beats that I am using (metricbeat, auditbeat, packetbeat, filebeat). Possibly any links that can be useful in doing this?

---

<div class="post-metadata">

**Author:** ![sk1f](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sk1f](https://discuss.elastic.co/u/sk1f)\
**Post date:** [March 13, 2021, 5:22pm UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978/6 "2021-03-13T17:22:32Z")

</div>

If this type of topic should not be discussed on the forum - possibly I can contact any moderator privately? So I can discuss and describe the steps I have done?

---

<div class="post-metadata">

**Author:** ![sk1f](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sk1f](https://discuss.elastic.co/u/sk1f)\
**Post date:** [March 15, 2021, 11:24pm UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978/7 "2021-03-15T23:24:16Z")

</div>

1. created directory : /home/es/config/certs

2. copied certificates.p12 : cp /etc/elasticsearch/elastic-certificates.p12 /home/es/config/certs

3. copied HTTP certs to the same directory : cp /etc/elasticsearch/http.p12 /home/es/config/certs  
And to http

4. For each additional Elastic product that you want to configure, copy the certificates to the relevant configuration directory. - ???  
Does it include beats products? If it does where are "relevant" configuration directories? under /etc/..?

5. cp elasticsearch-ssl-http.zip /home/es/config/certs

6. unzip elasticsearch-ssl-http.zip

7. copy http.p12 to /etc/elasticsearch/

8. elasticsearch.yml :

9. Update all clients, tools, and applications that connect to Elasticsearch  
to use the https protocol in their configuration URL.  
For example, Kibana, Beats, Logstash, language clients, and custom applications.

- for me that is:  
/etc/kibana/kibana.yml  
/etc/filebeat/filebeat.yml #protocol: "https" - for elasticsearch output  
/etc/auditbeat/auditbeat.yml #protocol: "https"  
/etc/metricbeat/metricbeat.yml #protocol: "https"  
/etc/metricbeat/modules.d/lasticsearch-xpack.yml #https  
/etc/packetbeat/packetbeat.yml #protocol: "https"

1. Encrypting traffic between the browser and Kibana.  
[Encrypt communications in Kibana | Kibana Guide [7.11] | Elastic](https://www.elastic.co/guide/en/kibana/7.11/configuring-tls.html#configuring-tls-browser-kib)

bin/elasticsearch-certutil cert -name sk1f\_kibana -dns localhost, 0.0.0.0  
Certificates written to /usr/share/elasticsearch/sk1f\_kibana.p12

Certificates written to /usr/share/elasticsearch/certificate-bundle.zip

/usr/share/elasticsearch/bin/elasticsearch-certutil cert -name sk1f\_kibana -dns localhost,0.0.0.0 -pem #here tried to use pem to see if there will be .key output.  
cp /usr/share/elasticsearch/certificate-bundle.zip /home/es/config/certs/

1. cp /usr/share/elasticsearch/sk1f\_kibana.p12 /home/es/config/certs/  
sudo cp certificate-bundle.zip /home/es/config/certs/kibana-server/ # -tried to use pem format in case if p12 not going to work

in kibana.yml : server.ssl.keystore.path: "/path/to/kibana-server.p12"

server.ssl.keystore.path: /etc/kibana/sk1f\_kibana.p12  
server.ssl.keystore.password: ""  
server.ssl.enabled: true

elasticsearch.ssl.certificateAuthorities: ["/etc/kibana/elasticsearch-ca.pem"]

when try to launch kibana :

```auto
["error","plugins","securitySolution"],"pid":13097,"message":"The following index patterns did not match any indices: [\"logs-endpoint.alerts-*\"] name: \"Endpoint Security\" id: \"f98df1a8-82db-11eb-906e-3fd6825689af\" rule id: \"9a1a2dae-0b5f-4c3d-8305-a268d404c306\" signals index: \".siem-signals-default\""}

["error","elasticsearch","data"],"pid":13097,"message":"Request error, retrying\nPOST https://localhost:9200/_bulk => socket hang up"}

```

Any advice on where is the error/how to fix it/ any help/ any reply?

---

<div class="post-metadata">

**Author:** ![sk1f](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sk1f](https://discuss.elastic.co/u/sk1f)\
**Post date:** [March 15, 2021, 11:52pm UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978/8 "2021-03-15T23:52:48Z")

</div>

All im trying to achieve is to get automatic alarm notifications from auditbeat rules. From what I can see I can do that only from activating trial licence and making tls connection. Other thing is - I have tried to use your guides - doesn't work.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 16, 2021, 1:17am UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978/9 "2021-03-16T01:17:26Z")

</div>

> [@sk1f](#):
>
> Can anyone help with the issue?

You asked a rapid series of not-completely-related questions over a weekend. Please be patient, and please take the time to ask clear questions with all necessary details.  
Comments like "I have tried to use your guides - doesn't work" provide no useful information. What didn't work? Where did you get stuck?

I'm having a lot of trouble working out which of your issues still exist, and which issues you have resolved.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 16, 2021, 1:25am UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978/10 "2021-03-16T01:25:29Z")

</div>

> [@sk1f](#):
>
> For each additional Elastic product that you want to configure, copy the certificates to the relevant configuration directory. - ???  
> Does it include beats products? If it does where are "relevant" configuration directories? under /etc/..?

Yes, if you enable SSL for Elasticsearch's HTTP server, then you need to configure that within beats.  
Here is the relevant documentation for filebeat: [Secure communication with Elasticsearch | Filebeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/securing-communication-elasticsearch.html)

---

<div class="post-metadata">

**Author:** ![sk1f](https://avatars.discourse-cdn.com/v4/letter/s/db5fbb/32.png) [@sk1f](https://discuss.elastic.co/u/sk1f)\
**Post date:** [March 17, 2021, 9:52am UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978/11 "2021-03-17T09:52:22Z")

</div>

Thank you for your reply. Sorry, did overreacted a bit - because previous to the stage of "securing" stack, guides are clear and understandable.  
Before moving to configuring beats I cannot launch kibana - explained my steps in the last post written above. Possibly you will be able to see where is the mistake.

-looks like I have found error why Kibana was not able to start :  
I had to `chmod 660 /etc/kibana/kibana_server.p12`  
For next steps I will try to follow your guide and configure beats.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2021, 9:52am UTC](https://discuss.elastic.co/t/ssl-connection-between-kibana-and-elasticsearch/266978/12 "2021-04-14T09:52:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
