# Webhook action with https fails

**URL:** <https://discuss.elastic.co/t/webhook-action-with-https-fails/270699>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [April 20, 2021, 12:01pm UTC](https://discuss.elastic.co/t/webhook-action-with-https-fails/270699 "2021-04-20T12:01:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mtoivo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtoivo/32/87399_2.png) [@mtoivo](https://discuss.elastic.co/u/mtoivo)\
**Post date:** [April 20, 2021, 12:01pm UTC](https://discuss.elastic.co/t/webhook-action-with-https-fails/270699/1 "2021-04-20T12:01:16Z")

</div>

Hi.

I'm trying to https-enable a webhook-action, which works fine over plain http. The endpoint is nginx server, where ssl-setup is verified and working. Watcher webhook to the same server works fine over https. I understand that actions-webook uses another method (axios) for the webhook and am looking for a proper way to debug that part.

Debugged the traffic in wireshark and and found out that after client key exchange the nginx server sends "change cipher spec" message, and after that kibana (or axios) just replies with TCP FIN and terminates the connection. I suspect the axios in the kibana end is failing to agree on ciphers and just dies away.

Any suggestions how to dig deeper in this issue? Where can I even tune ssl-options for axios (CA, cipher suite etc)? And most importantly, how to get more verbose logging? Kibana's verbose -option for logging does not give specifics on why the connection dies. I've seen some people have managed to catch the actual exception also, but I have no clue where that takes place.

Have not yet tried 7.12, still using 7.9.

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![mtoivo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtoivo/32/87399_2.png) [@mtoivo](https://discuss.elastic.co/u/mtoivo)\
**Post date:** [April 26, 2021, 12:27pm UTC](https://discuss.elastic.co/t/webhook-action-with-https-fails/270699/2 "2021-04-26T12:27:19Z")

</div>

Managed to get this work. Could not find any info from the logs on why the failure was occuring, but figured out that it might be CA-issue. We use self-signed CA, which was configured correctly in kibana.yml. But when using alert / actions via axios -module, it does not care about what is written in there. Instead, it relies on it's own definition for custom CA's, which have to be provided via environment-variable `NODE_EXTRA_CA_CERTS`.

Might be good idea to point these things out in the documention of the actions/connectors for example.

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [April 30, 2021, 2:47pm UTC](https://discuss.elastic.co/t/webhook-action-with-https-fails/270699/3 "2021-04-30T14:47:11Z")

</div>

Thanks for the comment, and you're right. We also have some kibana config that can help here, and may be required in some environments if the env var can't be used. See [Alerting and action settings in Kibana | Kibana Guide [7.12] | Elastic](https://www.elastic.co/guide/en/kibana/current/alert-action-settings-kb.html#action-settings) `xpack.actions.rejectUnauthorized`

I opened issue [[docs][actions] add info on custom TLS settings to webhook doc · Issue #98924 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/98924) to track this - again, thanks!

We also recently merged some code, that should appear in a future release, to allow for per-host customization of CA's. [https://github.com/elastic/kibana/pull/96630](https://github.com/elastic/kibana/pull/96630)

---

<div class="post-metadata">

**Author:** ![mtoivo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtoivo/32/87399_2.png) [@mtoivo](https://discuss.elastic.co/u/mtoivo)\
**Post date:** [May 3, 2021, 10:49am UTC](https://discuss.elastic.co/t/webhook-action-with-https-fails/270699/4 "2021-05-03T10:49:50Z")

</div>

Hi.

Thanks a bunch! Nice to know things are going forward on this issue, too. I found the reference to the `xpack.actions.rejectUnauthorized` -option, but as we have to actually verify the self-signed certificates, this could not be used.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2021, 10:50am UTC](https://discuss.elastic.co/t/webhook-action-with-https-fails/270699/5 "2021-05-31T10:50:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
