# Unable to get issuer certificate with TLS enabled Kibana & Elasticsearch in k8s

**URL:** https://discuss.elastic.co/t/unable-to-get-issuer-certificate-with-tls-enabled-kibana-elasticsearch-in-k8s/296779
**Category:** Kibana
**Created:** [February 9, 2022, 6:42pm UTC](https://discuss.elastic.co/t/unable-to-get-issuer-certificate-with-tls-enabled-kibana-elasticsearch-in-k8s/296779 "2022-02-09T18:42:30Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Scottapotamus](https://avatars.discourse-cdn.com/v4/letter/s/3bc359/32.png) [@Scottapotamus](https://discuss.elastic.co/u/Scottapotamus)
#### Post date: [February 9, 2022, 6:42pm UTC](https://discuss.elastic.co/t/unable-to-get-issuer-certificate-with-tls-enabled-kibana-elasticsearch-in-k8s/296779/1 "2022-02-09T18:42:30Z")

</div>

I am trying to enable TLS on Elasticsearch and kibana in kubernetes using the ECK operator. But when kibana tries to connect to Elasticsearch I get

```auto
{"type":"log","@timestamp":" **********","tags":["error","elasticsearch-servce"[],"pid":14,"message":"Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate"}

```

I am able to curl Elasticsearch, but have not been able to get any configuration working with kibana. I am using cert-manager to create my certificates.

**kibana.yaml**

```auto
apiVersion: kibana.k8s.elastic.co/v1
kind: Kibana
metadata:
  name: kibana
spec:
  config:
    server.basePath: /kibana
    server.rewriteBasePath: false
    server.ssl.enabled: true
    server.ssl.key: /mnt/usr/tls.key
    server.ssl.certificate: /mnt/usr/tls.crt
    elasticsearch.ssl.certificateAuthorities: 
      - /mnt/usr/ca.crt
    elasticsearch.hosts:
      - https://default-es-http.elastic-cloud:9200
  count: 1
  http:
    service:
      metadata:
        annotations:
          konghq.com/protocol: https
    tls:
      certificate:
        secretName: kibana-certs-tls
  podTemplate:
    spec:
      containers:
      - name: kibana
        volumeMounts:
        - name: certs
          mountPath: /mnt/usr
      volumes:
      - name: certs
        secret:
          secretName: kibana-certs-tls
  version: 7.17.0

```

**default-Elasticsearch.yaml**

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: default
spec:
  nodeSets:
  - config:
      xpack.security.http.ssl.enabled: true
      xpack.security.http.ssl.client_authentication: optional
      node.master: true
      node.data: true
      node.ingest: true
      node.store.allow_mmap: false
    count: 1
    name: default
    podTemplate:
      spec:
        containers:
        - name: elasticsearch
  http:
    service:
      spec:
        # expose this cluster Service with a ClusterIP and add public ingress for access
        type: ClusterIP
    tls:
      certificate:
        secretName: default-es-certs-tls
  version: 7.17.0

```

Any help would be appreciated. Thanks!

---

<div class="post-metadata">

### Author: ![Michael\_Montgomery](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_montgomery/32/82242_2.png) [@Michael\_Montgomery](https://discuss.elastic.co/u/Michael_Montgomery)
#### Post date: [February 28, 2022, 6:42pm UTC](https://discuss.elastic.co/t/unable-to-get-issuer-certificate-with-tls-enabled-kibana-elasticsearch-in-k8s/296779/2 "2022-02-28T18:42:29Z")

</div>

@Scottapotamus can we get more information around secret `kibana-certs-tls`? When I use cert-manager to create certificates for Elasticsearch, I get a secret with keys: `tls.crt`, and `tls.key`, but not `ca.crt`. Since the error message you're getting is saying that Kibana doesn't trust the CA that issued the ES certificate, it makes me think that the key `ca.crt` in the secret `kibana-certs-tls` is not the CA that created the certificates in the ES secret `default-es-certs-tls`. Hope this makes sense.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 28, 2022, 6:43pm UTC](https://discuss.elastic.co/t/unable-to-get-issuer-certificate-with-tls-enabled-kibana-elasticsearch-in-k8s/296779/3 "2022-03-28T18:43:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
