# Unable to retrieve version information from Elasticsearch nodes. unable to verify the first certificate

**URL:** <https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-verify-the-first-certificate/375968>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [March 15, 2025, 10:40am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-verify-the-first-certificate/375968 "2025-03-15T10:40:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dylan\_Smart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dylan_smart/32/142075_2.png) [@Dylan\_Smart](https://discuss.elastic.co/u/Dylan_Smart)\
**Post date:** [March 15, 2025, 10:40am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-verify-the-first-certificate/375968/1 "2025-03-15T10:40:40Z")

</div>

Hi dear fellow elkers! I having the issue of Unable to retrieve version information from Elasticsearch nodes. unable to verify the first certificate. The server also gets stuck on Kibana server is not ready yet.

I am following the official process and minimal and basic security show no issues. But when i get to Encrypt traffic between Kibana and Elasticsearch it does not work. I chose to use CSR instead for the /usr/share/elasticsearch/bin/elasticsearch-certutil ca.

When I do elasticsearch.ssl.verificationMode: none it works but when commented out it fails. When i use curl it works, when provided a different file it fails.

Output of curl:

```auto
root@ip-10-0-0-39:/etc/kibana# curl -X GET "https://kibana.delicatehug.com:9200" --cacert certificate.pem -u kibana_system:IIklIRxz8bTAZKTKQnC1
{
  "name" : "node-1",
  "cluster_name" : "my-cluster",
  "cluster_uuid" : "M_aoZkBCS2KRsXz_yyXsKw",
  "version" : {
    "number" : "7.17.28",
    "build_flavor" : "default",
    "build_type" : "deb",
    "build_hash" : "139cb5a961d8de68b8e02c45cc47f5289a3623af",
    "build_date" : "2025-02-20T09:05:31.349013687Z",
    "build_snapshot" : false,
    "lucene_version" : "8.11.3",
    "minimum_wire_compatibility_version" : "6.8.0",
    "minimum_index_compatibility_version" : "6.0.0-beta1"
  },
  "tagline" : "You Know, for Search"
}

```

However it fails from Kibana.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 15, 2025, 3:32pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-verify-the-first-certificate/375968/2 "2025-03-15T15:32:40Z")

</div>

Hi @Dylan_Smart Welcome to the community.

3 things

can you run that `curl` with `-v` option.

Share your kibana.yml with the SSL enabled

Share the log messages from Kibana

---

<div class="post-metadata">

**Author:** ![Dylan\_Smart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dylan_smart/32/142075_2.png) [@Dylan\_Smart](https://discuss.elastic.co/u/Dylan_Smart)\
**Post date:** [March 17, 2025, 7:28am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-verify-the-first-certificate/375968/3 "2025-03-17T07:28:10Z")

</div>

This was fixed, I failed to set up the proper certificates, user error 😃
