Elasticsearch unable to get issuer certificate

Viewed 496

I am trying to encrypt tls certificate using LetsEncrypt. But my server page says: Kibana server is not ready yet.

Here is the error in /etc/kibana/kibana.yml:

{"type":"log","@timestamp":"2022-05-29T09:48:26+00:00","tags":["error","elasticsearch-service"],"pid":476059,"message":"Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate"}

I was using the same config with a self signed CA before, but it was working. But when I switched to LetsEncrypt, it does not work. The .pem files are same for both Kibana and Elasticsearch, and are copied from /etc/letsencrypt/archive/my.exampledomain.com/.

Elasticsearch Configuration:

path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch

#network.host: 192.168.0.1
#network.host: localhost
#network.host: 0.0.0.0
network.host: [ _eth0_, _local_ ]

http.port: 9200

#discovery.seed_hosts: my.exampledomain.com
discovery.type: single-node
xpack.security.authc.api_key.enabled: true

xpack.security.enabled: true

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.verification_mode: certificate
xpack.security.http.ssl.key: /etc/elasticsearch/ssl/my.exampledomain.com/privkey2.pem
xpack.security.http.ssl.certificate: /etc/elasticsearch/ssl/my.exampledomain.com/cert2.pem
xpack.security.http.ssl.certificate_authorities: [ "/etc/elasticsearch/ssl/my.exampledomain.com/fullchain2.pem" ]

xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.key: /etc/elasticsearch/ssl/my.exampledomain.com/privkey2.pem
xpack.security.transport.ssl.certificate: /etc/elasticsearch/ssl/my.exampledomain.com/cert2.pem
xpack.security.transport.ssl.certificate_authorities: [ "/etc/elasticsearch/ssl/my.exampledomain.com/fullchain2.pem" ]

Kibana Configuration:

server.port: 5601

#server.host: "localhost"
#server.host: "my.exampledomain.com"
server.host: "0.0.0.0"

server.publicBaseUrl: "https://my.exampledomain.com"

#elasticsearch.hosts: ["http://localhost:9200"]
#elasticsearch.hosts: ["http://0.0.0.0:9200"]
elasticsearch.hosts: ["https://my.exampledomain.com:9200"]

elasticsearch.ssl.certificateAuthorities: ["/etc/kibana/ssl/my.exampledomain.com/fullchain2.pem"]
elasticsearch.ssl.verificationMode: "certificate"
#elasticsearch.ssl.verify: true


xpack.security.sameSiteCookies: "None"
xpack.security.secureCookies: true

xpack.security.authc.providers:
  basic.basic1:
    order: 0

# Enable Kibana TLS over HTTPS

server.ssl.enabled: true
server.ssl.certificate: /etc/kibana/ssl/my.exampledomain.com/fullchain2.pem
server.ssl.key: /etc/kibana/ssl/my.exampledomain.com/privkey2.pem

Elasticsearch Test: Elasticsearch server Response

2 Answers

We had a similar issue. It was resolved by including the cert for each step in the chain, including the root certificate in both certificateAuthorities properties.

Something that Elastic didn't seem to need.

This is on Kibana 8.2.0.

I had this same problem and after days of searching I finally figured out that although Elasticsearch accepts chain.pem as a certificate authority cert when using privkey.pem and fullchain.pem as your key and cert, respectively, Kibana does not.

For some reason Kibana needs the public root CA cert from letsencrypt, isrgrootx1.pem, which can be downloaded from letsencrypt.org/certs/isrgrootx1.pem

Once you have this cert downloaded your cert configuration can be as follows:

ES cert setup:
xpack.security.http.ssl.key=privkey.pem
xpack.security.http.ssl.certificate=fullchain.pem
xpack.security.http.ssl.certificate_authorities=chain.pem
xpack.security.transport.ssl.key=privkey.pem
xpack.security.transport.ssl.certificate=fullchain.pem
xpack.security.transport.ssl.certificate_authorities=chain.pem

Kibana cert setup:
elasticsearch.ssl.certificateAuthorities=isrgrootx1.pem
server.ssl.key=privkey.pem
server.ssl.certificate=fullchain.pem
server.ssl.certificateAuthorities=chain.pem

And everything should work!

Related