# \[timelion\] \> unable to verify the first certificate

**URL:** <https://discuss.elastic.co/t/timelion-unable-to-verify-the-first-certificate/158431>\
**Category:** Kibana\
**Tags:** canvas\
**Created:** [November 27, 2018, 10:49pm UTC](https://discuss.elastic.co/t/timelion-unable-to-verify-the-first-certificate/158431 "2018-11-27T22:49:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_Vasquez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_vasquez/32/22088_2.png) [@Matt\_Vasquez](https://discuss.elastic.co/u/Matt_Vasquez)\
**Post date:** [November 27, 2018, 10:49pm UTC](https://discuss.elastic.co/t/timelion-unable-to-verify-the-first-certificate/158431/1 "2018-11-27T22:49:13Z")

</div>

While working with Canvas using the "[eCommerce] Revenue Tracking" template Workpad. The embedded timelion visualization are throwing errors and showing a exclamation point graphic.

When I click on the error graphic is displays the following:

Whoops! Expression failed  
Expression failed with the message:

[timelion] \> unable to verify the first certificate

{  
"error": {  
"stack": "Error: unable to verify the first certificate  
at TLSSocket.\<anonymous\> (\_tls\_wrap.js:1105:38)  
at emitNone (events.js:106:13)  
at TLSSocket.emit (events.js:208:7)  
at TLSSocket.\_finishInit (\_tls\_wrap.js:639:8)  
at TLSWrap.ssl.onhandshakedone (\_tls\_wrap.js:469:38)",  
"message": "[timelion] \> unable to verify the first certificate"  
}  
}

I understand Canvas is in beta but this seems like a timelion issue with TLS. I am using a specified CA for TLS via HTTP and Transport layers across all of the Elastic Stack. From researching this error it seems to be specific from Node.js. I have double checked that the certificate chain is present in the CA PEM file which is set in all of the configs across elastic stack:

xpack.security.http.ssl.certificate\_authorities: E:/Elastic Stack\Elasticsearch\config\certs  
ootca.pem  
xpack.security.transport.ssl.certificate\_authorities: E:\Elastic Stack\Elasticsearch\config\certs  
ootca.pem

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [November 27, 2018, 11:05pm UTC](https://discuss.elastic.co/t/timelion-unable-to-verify-the-first-certificate/158431/2 "2018-11-27T23:05:21Z")

</div>

Hey @Matt_Vasquez,

Sorry you're having trouble with Canvas. I do believe this is a bug on our side, so I've opened [https://github.com/elastic/kibana/issues/26308](https://github.com/elastic/kibana/issues/26308) to track progress and alert the Canvas team.

---

<div class="post-metadata">

**Author:** ![Matt\_Vasquez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_vasquez/32/22088_2.png) [@Matt\_Vasquez](https://discuss.elastic.co/u/Matt_Vasquez)\
**Post date:** [November 28, 2018, 8:56pm UTC](https://discuss.elastic.co/t/timelion-unable-to-verify-the-first-certificate/158431/3 "2018-11-28T20:56:39Z")

</div>

@Larry_Gregory I was able to fix this issue by exporting an environment variable named  
NODE\_EXTRA\_CA\_CERTS pointing to my CA certificate file path

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2018, 8:56pm UTC](https://discuss.elastic.co/t/timelion-unable-to-verify-the-first-certificate/158431/4 "2018-12-26T20:56:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
