# Unable to retrieve version information from elasticsearch nodes

**URL:** <https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/321072>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [December 12, 2022, 9:49pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/321072 "2022-12-12T21:49:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eduard\_Abril](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eduard_abril/32/49885_2.png) [@Eduard\_Abril](https://discuss.elastic.co/u/Eduard_Abril)\
**Post date:** [December 12, 2022, 9:49pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/321072/1 "2022-12-12T21:49:04Z")

</div>

Hi guys,

I'm using elasticsearch and kibana 7.17.6 and currently I'm facing some problems with the security settings.

I'm trying to setup basic security for a 3 nodes elasticsearch cluster and 1 node kibana using certificates signed by an external CA. Everything works just fine with the elasticsearch cluster when I test it using curl command, but when I start Kibana it seems Kibana cannot verify the cluster certificates and I got the next error message in Kibana Log.

```auto
{"type":"log","@timestamp":"2022-12-12T15:18:29-05:00","tags":["error","elasticsearch-service"],"pid":1125039,"message":"Unable to retrieve version information from Elasticsearch nodes. unable to verify the first certificate"}

```

I would appreciate any suggestions you could give to solve this.

These are the config files for kibana and ES nodes.

**elasticsearch.yml - Node 1**

```auto
# ---------------------------------- Security ----------------------------------
#
# ***WARNING***
#
# Elasticsearch security features are not enabled by default.
# These features are free, but require configuration changes to enable them.
# This means that users don’t have to provide credentials and can get full access
# to the cluster. Network connections are also not encrypted.
#
# To protect your data, we strongly encourage you to enable the Elasticsearch security features.
# Refer to the following documentation for instructions.
#
# https://www.elastic.co/guide/en/elasticsearch/reference/7.16/configuring-stack-security.html
#
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.client_authentication: required
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/elastic-certificates.p12
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.certificate: /etc/elasticsearch/certs/SV934Dashmoni3.cer
xpack.security.http.ssl.key: /etc/elasticsearch/certs/http-SV934Dashmoni3.key
xpack.security.http.ssl.certificate_authorities: /etc/elasticsearch/certs/ca.cer

```

**elasticsearch.yml - Node 2**

```auto
# ---------------------------------- Security ----------------------------------
#
# ***WARNING***
#
# Elasticsearch security features are not enabled by default.
# These features are free, but require configuration changes to enable them.
# This means that users don’t have to provide credentials and can get full access
# to the cluster. Network connections are also not encrypted.
#
# To protect your data, we strongly encourage you to enable the Elasticsearch security features.
# Refer to the following documentation for instructions.
#
# https://www.elastic.co/guide/en/elasticsearch/reference/7.16/configuring-stack-security.html
#
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.client_authentication: required
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/elastic-certificates.p12
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.certificate: /etc/elasticsearch/certs/SV934Dashmoni4.cer
xpack.security.http.ssl.key: /etc/elasticsearch/certs/http-SV934Dashmoni4.key
xpack.security.http.ssl.certificate_authorities: /etc/elasticsearch/certs/ca.cer

```

**elasticsearch.yml - Node 3**

```auto
# ---------------------------------- Security ----------------------------------
#
# ***WARNING***
#
# Elasticsearch security features are not enabled by default.
# These features are free, but require configuration changes to enable them.
# This means that users don’t have to provide credentials and can get full access
# to the cluster. Network connections are also not encrypted.
#
# To protect your data, we strongly encourage you to enable the Elasticsearch security features.
# Refer to the following documentation for instructions.
#
# https://www.elastic.co/guide/en/elasticsearch/reference/7.16/configuring-stack-security.html
#
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.client_authentication: required
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/elastic-certificates.p12
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.certificate: /etc/elasticsearch/certs/SV934Dashmoni5.cer
xpack.security.http.ssl.key: /etc/elasticsearch/certs/http-SV934Dashmoni5.key
xpack.security.http.ssl.certificate_authorities: /etc/elasticsearch/certs/ca.cer

```

**kibana.yml**

To clarify: The elasticsearch-ca.pem certificate shown in this file is the exactly the same _/etc/elasticsearch/certs/ca.cer_ used in the ES cluster but converted from .cer to .pem format.

```auto
# The URLs of the Elasticsearch instances to use for all your queries.
elasticsearch.hosts: ["https://SV934Dashmoni3:9210", "https://SV934Dashmoni4:9210", "https://SV934Dashmoni5:9210"]

# Kibana uses an index in Elasticsearch to store saved searches, visualizations and
# dashboards. Kibana creates a new index if the index doesn't already exist.
#kibana.index: ".kibana"

# The default application to load.
#kibana.defaultAppId: "home"

# If your Elasticsearch is protected with basic authentication, these settings provide
# the username and password that the Kibana server uses to perform maintenance on the Kibana
# index at startup. Your Kibana users still need to authenticate with Elasticsearch, which
# is proxied through the Kibana server.
elasticsearch.username: "kibana_system"
elasticsearch.password: " *****"

# Kibana can also authenticate to Elasticsearch via "service account tokens".
# If may use this token instead of a username/password.
# elasticsearch.serviceAccountToken: "my_token"

# Enables SSL and paths to the PEM-format SSL certificate and SSL key files, respectively.
# These settings enable SSL for outgoing requests from the Kibana server to the browser.
#server.ssl.enabled: true
#server.ssl.certificate: /etc/kibana/certs/SV934Dashmoni2.cer
#server.ssl.key: /etc/kibana/certs/SV934Dashmoni2.key

# Optional settings that provide the paths to the PEM-format SSL certificate and key files.
# These files are used to verify the identity of Kibana to Elasticsearch and are required when
# xpack.security.http.ssl.client_authentication in Elasticsearch is set to required.
#elasticsearch.ssl.certificate: /path/to/your/client.crt
#elasticsearch.ssl.key: /path/to/your/client.key

# Optional setting that enables you to specify a path to the PEM file for the certificate
# authority for your Elasticsearch instance.
elasticsearch.ssl.certificateAuthorities: /etc/kibana/certs/selfsigned/elasticsearch-ca.pem

# To disregard the validity of SSL certificates, change this setting's value to 'none'.
#elasticsearch.ssl.verificationMode: full

```

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [December 13, 2022, 5:43am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/321072/2 "2022-12-13T05:43:49Z")

</div>

Can you share logs from the elasticsearch nodes when Kibana fails to connect? They should give out more information.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2023, 5:43am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/321072/3 "2023-01-10T05:43:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
