# Ssl key file

**URL:** https://discuss.elastic.co/t/ssl-key-file/41797
**Category:** Kibana
**Created:** [February 15, 2016, 2:34pm UTC](https://discuss.elastic.co/t/ssl-key-file/41797 "2016-02-15T14:34:32Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![theo.bot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theo.bot/32/5739_2.png) [@theo.bot](https://discuss.elastic.co/u/theo.bot)
#### Post date: [February 15, 2016, 2:34pm UTC](https://discuss.elastic.co/t/ssl-key-file/41797/1 "2016-02-15T14:34:32Z")

</div>

Hi

I followed the instructions in the online manual for create a self signed certificate and generating a csr file with the keytool. However kibana is asking for a .key file. Which is not mentioned in the manual.

How do I generate this?

Kind regards

Theo

---

<div class="post-metadata">

### Author: ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)
#### Post date: [February 15, 2016, 4:09pm UTC](https://discuss.elastic.co/t/ssl-key-file/41797/2 "2016-02-15T16:09:38Z")

</div>

Which instructions did you follow to generate the CSR?

Kibana .key and .crt files are independent of the other certificates and keys you use in Shield. As [Kibana docs](https://www.elastic.co/guide/en/kibana/current/kibana-server-properties.html) suggest, you can use any tools, including [openssl](https://www.sslshopper.com/article-most-common-openssl-commands.html), to generate a key/cert pair for use within Kibana. Elastic does not provide these instructions as every environment may have their own processes for generating these types of certificates in the production environment.

---

<div class="post-metadata">

### Author: ![theo.bot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theo.bot/32/5739_2.png) [@theo.bot](https://discuss.elastic.co/u/theo.bot)
#### Post date: [February 16, 2016, 9:55am UTC](https://discuss.elastic.co/t/ssl-key-file/41797/3 "2016-02-16T09:55:35Z")

</div>

Tanya

This link: [https://www.elastic.co/guide/en/shield/current/ssl-tls.html](https://www.elastic.co/guide/en/shield/current/ssl-tls.html)

I got the whole thing working. Indeed the kibana certificate/key pair is independent from the Elasticsearch.

Thanks for the assistance.

Theo

---

<div class="post-metadata">

### Author: ![theo.bot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theo.bot/32/5739_2.png) [@theo.bot](https://discuss.elastic.co/u/theo.bot)
#### Post date: [February 16, 2016, 10:17am UTC](https://discuss.elastic.co/t/ssl-key-file/41797/4 "2016-02-16T10:17:05Z")

</div>

Tanya

The sense plugin doesn't accept the self signed certificate for some reason. I get:  
Client request error: self signed certificate in certificate chain

Theo

---

<div class="post-metadata">

### Author: ![owjprice](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/owjprice/32/9670_2.png) [@owjprice](https://discuss.elastic.co/u/owjprice)
#### Post date: [September 22, 2016, 7:29pm UTC](https://discuss.elastic.co/t/ssl-key-file/41797/5 "2016-09-22T19:29:05Z")

</div>

@theo.bot Did you make any progress with this? I am having the same issue.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 1:38pm UTC](https://discuss.elastic.co/t/ssl-key-file/41797/6 "2017-07-06T13:38:22Z")

</div>


