# SSL/TLS on ELK cluster

**URL:** <https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 4, 2016, 11:30am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641 "2016-07-04T11:30:07Z")\
**Posts on this page:** 16\
**Page:** 3

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 15, 2016, 2:20pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/41 "2016-07-15T14:20:39Z")

</div>

Yes that is already configured in kibana.yml  
[elasticsearch.ssl.ca](http://elasticsearch.ssl.ca): /etc/elasticsearch/shield/cert.pem

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 15, 2016, 2:37pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/42 "2016-07-15T14:37:23Z")

</div>

What cert is that? Is it the intermediate CA cert?

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 15, 2016, 2:43pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/43 "2016-07-15T14:43:29Z")

</div>

No it is not intermediate cert.  
Using following we generated cert.pem and I am using this cert-

Here are the steps we followed to generate the certificate -  
1.Put the request using -

openssl req -nodes -newkey rsa:2048 -sha256 -keyout myserver.key -out server.csr  
2.On the CA website we got the certificates available in following formats -

DER, CRT, PKCS7b

( When I download PKCS7b file , it takes .pem extension )

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 15, 2016, 3:21pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/44 "2016-07-15T15:21:03Z")

</div>

So it is the cert of the elasticsearch server? It should be the intermediate certificate that you use for `elasticsearch.ssl.ca` and you may have also include the root CA certificate as well like:

```
elasticsearch.ssl.ca: ["/path/to/root.pem", "/path/to/intermediate.pem"]

```

Please make sure these are in PEM format. You may need to use the openssl commands we used before if they are not

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 15, 2016, 3:38pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/45 "2016-07-15T15:38:39Z")

</div>

Yes it was cert of ES server. Ok , I have int. cert and root cert in der format which I converted to pem format using -  
e.g.  
openssl x509 -inform der -in caintermediatecert.der -out caintermediatecert.pem

Did for both int and root certs and configured as given by you. Kibana service is still not starting.

The kiabana log entries are 1 day old after that its not generating any logs -

```
{"type":"log","@timestamp":"2016-07-15T05:35:24+00:00","tags":["warning","elasticsearch"],"pid":1960,"message":"No living connections"}
{"type":"log","@timestamp":"2016-07-15T05:35:27+00:00","tags":["warning","elasticsearch"],"pid":1960,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2016-07-15T05:35:27+00:00","tags":["warning","elasticsearch"],"pid":1960,"message":"No living connections"}
```

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 15, 2016, 3:52pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/46 "2016-07-15T15:52:03Z")

</div>

So you get not output at all from running "bin/kibana"?

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 15, 2016, 3:55pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/47 "2016-07-15T15:55:31Z")

</div>

I am running kibana using /etc/init.d/kibana start/stop

If I start using /bin/kibana , I get following -

[root@irldxvm022 kibana]# bin/kibana serve  
FATAL [Error: error:0906D06C:PEM routines:PEM\_read\_bio:no start line]

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 15, 2016, 4:21pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/48 "2016-07-15T16:21:18Z")

</div>

This implies that one of your certificate/key files isn't really a PEM file or has extra text in it outside of the ----BEGIN and -----END lines. I suggest you inspect each file

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 18, 2016, 6:12am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/49 "2016-07-18T06:12:05Z")

</div>

Ok I checked both files but I do not see any spaces or extra characters as such. I converted those from der format to pem and used as it is.

We have few days left of Shield trial license.  
To speed up the resolution , should I set up webex session. Is that fine with you ? Are you working in EST time zone ?

Thanks,  
Vinod

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 18, 2016, 1:01pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/50 "2016-07-18T13:01:14Z")

</div>

Hi Jay,

Now we trying with the commands given in the official document-  
We ran following commands -

> keytool -genkey -alias elk01 -keystore elk01.jks -keyalg RSA -keysize 2048 -validity 712 -ext san=dns:irldxvm022.irl.in.ibm.com,ip:9.126.112.72

> keytool -certreq -alias elk01 -keystore elk01.jks -file elk01.csr -keyalg rsa -ext san=dns:irldxvm022.irl.in.ibm.com,ip:9.126.112.72

After that we are uploading the csr file on the portal for signing , however we are getting the errors.  
PFA is the screenshot of errors.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/cb259708ad39d39f15575f9bbc299750fa7db54d.JPG)

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 18, 2016, 1:23pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/51 "2016-07-18T13:23:40Z")

</div>

Hi Vinod,

I am not sure what causes that. The keysize you specified has the proper minimum size. Did you use the same name when running keytool ("CN=9.126.112.72,OU=Research,L=New Delhi,ST=N/A,C=IN") ?

I think the portal administrators may be able to help you better as I am not familiar with it.

-Jay

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 19, 2016, 11:59am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/52 "2016-07-19T11:59:29Z")

</div>

If I use the openssl command to generate csr , its working. But again that is not helping us in any way, we have already tried that. Can you explain the first command mentioned in the - [https://www.elastic.co/guide/en/shield/current/ssl-tls.html#install-signed-cert](https://www.elastic.co/guide/en/shield/current/ssl-tls.html#install-signed-cert)  
i.e.

```
Create a node keystore and import your CA’s certificate with Java Keytool. This configures the node to trust certificates signed by the CA. For Elasticsearch to access the keystore, it must be located under the Elasticsearch configuration directory. For example, the following command creates a keystore for node01 and and imports the CA certificate cacert.pem.

cd CONFIG_DIR/shield
keytool -importcert -keystore node01.jks -file cacert.pem -alias my_ca
```

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 19, 2016, 2:19pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/53 "2016-07-19T14:19:40Z")

</div>

The command simply imports the CA certificate (`cacert.pem`) into `node01.jks`, which will be created if it does not exist. The certificate is also given an alias, which is not required.

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [August 1, 2016, 12:16pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/54 "2016-08-01T12:16:33Z")

</div>

Hi Jay,

Peter has sent us the document which helps to configure the self signed certs. I have carried out the steps but we are still getting errors.

Regards,  
Vinod

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [August 3, 2016, 4:57am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/55 "2016-08-03T04:57:45Z")

</div>

Hi

Ok I have configured now only one instance of ELK and configured shield on it. My logstash and ES logs are clean and communication between them is working. If I run curl on https its giving me the o/p

But kibana is throwing error -

```
> log [10:23:12.369] [warning][elasticsearch] Unable to revive connection: https://127.0.0.1:9200/
> log [10:23:12.370] [warning][elasticsearch] No living connections
> log [10:23:12.374] [error][status][plugin:elasticsearch] Status changed from yellow to red - Unable to connect to Elasticsearch at https://127.0.0.1:9200.
> log [10:23:14.909] [warning][elasticsearch] Unable to revive connection: https://127.0.0.1:9200/
> log [10:23:14.911] [warning][elasticsearch] No living connections
> ops [10:23:15.722] memory: 65.8MB uptime: 0:00:07 load: [0.74 0.56 0.52] delay: 3.218
> ^C
> [root@irldxvm074 kibana]# telnet 127.0.0.1 9200
> Trying 127.0.0.1...
> Connected to 127.0.0.1.
> Escape character is '^]'.
> '^]'.
> Connection closed by foreign host.

```

If I disable the elasticsearch.ssl.verify to false in kibana.yml , ELK works fine.

What could be the issue over here.

Regards,  
Vinod

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/56 "2017-07-06T13:42:31Z")

</div>



[Previous page](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641.md?page=2)
