# Unable to verify the first certificate on postman

**URL:** <https://discuss.elastic.co/t/unable-to-verify-the-first-certificate-on-postman/344071>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 28, 2023, 1:42pm UTC](https://discuss.elastic.co/t/unable-to-verify-the-first-certificate-on-postman/344071 "2023-09-28T13:42:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![stramzik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stramzik/32/112158_2.png) [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Post date:** [September 28, 2023, 1:42pm UTC](https://discuss.elastic.co/t/unable-to-verify-the-first-certificate-on-postman/344071/1 "2023-09-28T13:42:53Z")

</div>

Hi I've setup a Elastic and Kibana instance on Windows server

Both instances are secured with LetsEncrypt certificate. When I try to use the elasticsearch API on POSTMAN i get the "Unable to verify the first certificate" I am not sure what am I missing. Please advise I dont want to get that error. Its not necessarily post man because the certificate is not verified I am unable to use the elasticsearch API on other applications

However I do get the padlock on browser  
elasticsearch.yml is below

```auto
http.port: 9600
xpack.security.enabled: true

xpack.security.enrollment.enabled: true

xpack.security.http.ssl:
  enabled: true
  key: C:\Elasticsearch\elasticsearch\config\certs\mydomain.com-key.pem
  certificate: C:\Elasticsearch\elasticsearch\config\certs\mydomain.com-crt.pem

xpack.security.transport.ssl:
  enabled: true
  verification_mode: certificate
  keystore.path: certs/transport.p12
  truststore.path: certs/transport.p12

cluster.initial_master_nodes: ["mynode"]

http.host: 0.0.0.0

```

kibana.yml

```auto
server.port: 5801
server.host: "0.0.0.0"
server.publicBaseUrl: "https://mydomain.com"
server.ssl.enabled: true
server.ssl.certificate: C:\Elasticsearch\kibana\config\cert\mydomain.com-crt.pem
server.ssl.key: C:\Elasticsearch\kibana\config\cert\mydomain.com-key.pem

elasticsearch.hosts: ["https://mydomain.com:9600"]
elasticsearch.username: "kibana_system"
elasticsearch.password: "password"

elasticsearch.ssl.verificationMode: none

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 28, 2023, 4:11pm UTC](https://discuss.elastic.co/t/unable-to-verify-the-first-certificate-on-postman/344071/2 "2023-09-28T16:11:05Z")

</div>

Hi @stramzik

Sounds like a Postman issue, perhaps you should check that forum.

> **[Working with certificates | Postman Learning Center](https://learning.postman.com/docs/sending-requests/certificates/)**
>
> Working with certificates: documentation for Postman, the collaboration platform for API development. Create better APIs—faster.

If, from your command line you can run this and be successful then elasticsearch is setup correctly

`curl -v --cacert /path/to/http_ca.crt -u elastic https://localhost:9200`

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 29, 2023, 6:32am UTC](https://discuss.elastic.co/t/unable-to-verify-the-first-certificate-on-postman/344071/3 "2023-09-29T06:32:46Z")

</div>

> [@stramzik](#):
>
> Both instances are secured with LetsEncrypt certificate

> [@stramzik](#):
>
> "Unable to verify the first certificate"

This seems to be the result of two things:

1. Postman doesn't trust the issuing certificate from Let's Encrypt
2. Your ES node is configured to only send the leaf certificate in the SSL handshake

The background info is here

- [Chain of Trust - Let's Encrypt](https://letsencrypt.org/certificates/)

Let's encrypt has an offline root cert, and a separate issuing certificate. That's very normal for a CA.

But what it means is that, if you:

1. Are using a tool (like Postman, or any other client) that trusts Let's Encrypt's root cert (technically, ISRG's root cert), but knows nothing of the issuing cert, _and_
2. Your server has a cert issued by the Let's Encrypt issuer, but does not include a copy of that issuing cert

then, when you point that tool at the server, there's no way for the 2 of them to connect-the-dots. The chain is broken because neither the client or the server has a copy of the intermediate issuing certificate.  
The tool trusts anything signed by ISRG, and the server has something that _is_ signed by ISRG, but the only way to know that is if you have a copy of the Let's Encrypt issuing cert (R3).

I don't know if there's a way to change #1 (make Postman know about the LE issuing cert), but you can fix #2 by grabbing the issuing cert (R3) from Let's Encrypt and adding it to the cert chain in your ES instance.

I assume your cert is signed by the R3 issuing cert from Let's Encrypt (there are other possibilities, but they're very unlikely). You can grab that cert from here

- [https://letsencrypt.org/certs/lets-encrypt-r3.pem](https://letsencrypt.org/certs/lets-encrypt-r3.pem)

To tell ES to use it, you just append it to the existing `.crt` file you're using.

Here's what you could do on a Linux server.  
It looks like you're using Windows, so you'll need to make some adjustments for your needs.

```auto
# Get the R3 cert from let's encrypt
curl -o ./lets-encrypt-r3.pem https://letsencrypt.org/certs/lets-encrypt-r3.pem

# Check that it downloaded correctly and looks like a PEM file with a
# -----BEGIN CERTIFICATE-----
# header, etc.
cat ./lets-encrypt-r3.pem

# Add it to the end of your cert chain
cat ./lets-encrypt-r3.pem >> config/certs/mydomain.com-crt.pem

```

---

<div class="post-metadata">

**Author:** ![stramzik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stramzik/32/112158_2.png) [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Post date:** [September 29, 2023, 9:22am UTC](https://discuss.elastic.co/t/unable-to-verify-the-first-certificate-on-postman/344071/4 "2023-09-29T09:22:52Z")

</div>

> [@TimV](#):
>
> `cat ./lets-encrypt-r3.pem >> config/certs/mydomain.com-crt.pem`

Tim this worked like a charm. Thank you very much you have no idea how helpful your explanation was. I am really gratefully for your response thank you again 🙏 🙌 🫡

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 27, 2023, 9:23am UTC](https://discuss.elastic.co/t/unable-to-verify-the-first-certificate-on-postman/344071/5 "2023-10-27T09:23:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
