# X-pack monitoring using Kibana error at start up =\> self signed certificate in certificate chain

**URL:** <https://discuss.elastic.co/t/x-pack-monitoring-using-kibana-error-at-start-up-self-signed-certificate-in-certificate-chain/76863>\
**Category:** Kibana\
**Created:** [February 28, 2017, 8:24pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-kibana-error-at-start-up-self-signed-certificate-in-certificate-chain/76863 "2017-02-28T20:24:06Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tamilselvan](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@Tamilselvan](https://discuss.elastic.co/u/Tamilselvan)\
**Post date:** [February 28, 2017, 8:24pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-kibana-error-at-start-up-self-signed-certificate-in-certificate-chain/76863/1 "2017-02-28T20:24:06Z")

</div>

Hi,

Here's what I am trying to do (setting up the xpack monitoring feature),

I am using elastic search 5.2.1 protected with x-pack 5.2.1.  
My test set up has 2 data node, 1 master and 1 client nodes.  
I am running my kibana(5.2.1) server in the same machine where I am running the client node.

I have set up a separate single node cluster in a different machine and was pointing my kibana monitoring to that url

xpack.monitoring.elasticsearch.url: "[https://xxx.xx.xx.xx:9200](https://xxx.xx.xx.xx:9200)"  
xpack.monitoring.elasticsearch.username: "kibana-user"  
xpack.monitoring.elasticsearch.password: "password"  
When I login to the kibana UI I don't see the tabs at the top and I see the status as RED.

kobana log shows:

{"type":"log","@timestamp":"2017-02-28T19:10:37Z","tags":["plugins","debug"],"pid":25817,"plugin":{"name":"spy\_modes","version":"kibana"},"message":"Initializing plugin spy\_modes@kibana"}  
{"type":"log","@timestamp":"2017-02-28T19:10:37Z","tags":["plugins","debug"],"pid":25817,"plugin":{"name":"status\_page","version":"kibana"},"message":"Initializing plugin status\_page@kibana"}  
{"type":"log","@timestamp":"2017-02-28T19:10:37Z","tags":["plugins","debug"],"pid":25817,"plugin":{"name":"table\_vis","version":"kibana"},"message":"Initializing plugin table\_vis@kibana"}  
{"type":"log","@timestamp":"2017-02-28T19:10:37Z","tags":["plugins","debug"],"pid":25817,"plugin":{"name":"tagcloud","version":"kibana"},"message":"Initializing plugin tagcloud@kibana"}  
{"type":"log","@timestamp":"2017-02-28T19:10:39Z","tags":["plugins","debug"],"pid":25817,"plugin":{"author":"Rashid Khan [rashid@elastic.co](mailto:rashid@elastic.co)","name":"timelion","version":"kibana"},"message":"Initializing plugin timelion@kibana"}  
{"type":"log","@timestamp":"2017-02-28T19:10:39Z","tags":["error","elasticsearch","monitoring-ui"],"pid":25817,"message":" **Request error,** retrying\nHEAD [https://xxx.xx.xx.xxx:9200/](https://xxx.xx.xx.xxx:9200/) =\> **self signed certificate in certificate chain**"}  
{"type":"log","@timestamp":"2017-02-28T19:10:39Z","tags":["status","plugin:timelion@5.2.1","info"],"pid":25817,"state":"green","message":"Status changed from uninitialized to green - Ready","prevState":"uninitialized","prevMsg":"uninitialized"}  
{"type":"log","@timestamp":"2017-02-28T19:10:39Z","tags":["listening","info"],"pid":25817,"message":"Server running at [https://xxx.xx.xx.xx:5601](https://xxx.xx.xx.xx:5601)"}  
{"type":"log","@timestamp":"2017-02-28T19:10:39Z","tags":["status","ui settings","info"],"pid":25817,"state":"green","message":"Status changed from uninitialized to green - Ready","prevState":"uninitialized","prevMsg":"uninitialized"}  
{"type":"log","@timestamp":"2017-02-28T19:10:39Z","tags":["warning","elasticsearch","monitoring-ui"],"pid":25817,"message":"Unable to revive connection: [https://xxx.xx.xx.xxx:9200/](https://xxx.xx.xx.xxx:9200/)"}  
{"type":"log","@timestamp":"2017-02-28T19:10:39Z","tags":["warning","elasticsearch","monitoring-ui"],"pid":25817,"message":"No living connections"}  
{"type":"log","@timestamp":"2017-02-28T19:10:39Z","tags":["status","plugin:monitoring@5.2.1","error"],"pid":25817,"state":"red","message":"Status changed from yellow to red - No Living connections","prevState":"yellow","prevMsg":"Waiting for Monitoring Health Check"}  
{"type":"log","@timestamp":"2017-02-28T19:10:40Z","tags":["plugin","debug"],"pid":25817,"message":"Checking Elasticsearch version"}

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 28, 2017, 11:43pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-kibana-error-at-start-up-self-signed-certificate-in-certificate-chain/76863/2 "2017-02-28T23:43:13Z")

</div>

@Tamilselvan if the certificate that you're using with Elasticsearch is a self-signed certificate, you'll have to set the `xpack.monitoring.elasticsearch.ssl.ca: /path/to/cert.crt` setting in the kibana.yml

---

<div class="post-metadata">

**Author:** ![Tamilselvan](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@Tamilselvan](https://discuss.elastic.co/u/Tamilselvan)\
**Post date:** [March 1, 2017, 12:25am UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-kibana-error-at-start-up-self-signed-certificate-in-certificate-chain/76863/3 "2017-03-01T00:25:21Z")

</div>

@Brandon_Kobel,

Thanks a ton. You saved me a day!!

I was having the ca configuration as '[elasticsearch.ssl.ca](http://elasticsearch.ssl.ca): /path/to/cert.crt' without the **xpack.monitoring** prefix.  
You hit right at the point.

Thanks!!!

---

<div class="post-metadata">

**Author:** ![Tamilselvan](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@Tamilselvan](https://discuss.elastic.co/u/Tamilselvan)\
**Post date:** [March 1, 2017, 2:20am UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-kibana-error-at-start-up-self-signed-certificate-in-certificate-chain/76863/4 "2017-03-01T02:20:41Z")

</div>

Hi @Brandon_Kobel,

I am now receiving the below error while trying to query the

**Client request error: Hostname/IP doesn't match certificate's altnames: "IP: xxx.xx.xxx.xx is not in the cert's list:**  
In the chrome developer console, I see Bad Gateway ( **502** ) error code.

From [https://github.com/elastic/kibana/issues/8932](https://github.com/elastic/kibana/issues/8932) - it looks like a known issue.

I have the below config set up in my kibana.yml

```
console.enabled: true
console.proxyFilter: .*
console.proxyConfig: 
  - match: 
      protocol: https
      host: "*"
      port: "{9200..9299}"
      
    ssl: 
      ca: /etc/kibana/path/ca.pem
      verify: false
      
  - timeout: 180000

```

**Is there a workaround? Is it fixed in the current version 5.2.1 / 5.2.2?**

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [March 1, 2017, 8:40pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-kibana-error-at-start-up-self-signed-certificate-in-certificate-chain/76863/5 "2017-03-01T20:40:38Z")

</div>

That issue that you linked to is for the 'Dev Tools' application inside of Kibana itself:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/d7d9789fb5d9c39224cd4cd87851d45ad5fca1a1.png)

Where exactly are you seeing that error? Could you post a screenshot?

---

<div class="post-metadata">

**Author:** ![Tamilselvan](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@Tamilselvan](https://discuss.elastic.co/u/Tamilselvan)\
**Post date:** [March 1, 2017, 9:51pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-kibana-error-at-start-up-self-signed-certificate-in-certificate-chain/76863/6 "2017-03-01T21:51:15Z")

</div>

@Brandon_Kobel  
Here's the screenshot

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/ec9199caa1bf0ff09da6906b18648aa1bab01b32.jpg)

I have the console.proxyConfig.0.ssl.verify: false, which is expected to skip the certificate hostname validation, but that doesn't seem to be the case.

For now as a workaround, I have modified the console/index.js - default setting for verify to false, to make it working.

But would like to confirm whether the console setting being not picked is a bug and when (which version) would the fix be out?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [March 2, 2017, 3:27pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-kibana-error-at-start-up-self-signed-certificate-in-certificate-chain/76863/7 "2017-03-02T15:27:29Z")

</div>

@Tamilselvan version 5.3.0 will remove the need to specify the console.proxyConfig section and will instead use the values specified in Elasticsearch config section.

---

<div class="post-metadata">

**Author:** ![Tamilselvan](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@Tamilselvan](https://discuss.elastic.co/u/Tamilselvan)\
**Post date:** [March 6, 2017, 6:10pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-kibana-error-at-start-up-self-signed-certificate-in-certificate-chain/76863/8 "2017-03-06T18:10:05Z")

</div>

Yes, Thats what I read from one of the topics in the forum.  
Thanks for the confirmation!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2017, 6:10pm UTC](https://discuss.elastic.co/t/x-pack-monitoring-using-kibana-error-at-start-up-self-signed-certificate-in-certificate-chain/76863/9 "2017-04-03T18:10:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
