# Kibana quit not able to connect to elasticsearch

**URL:** <https://forum.search-guard.com/t/kibana-quit-not-able-to-connect-to-elasticsearch/1419>\
**Category:** Search Guard\
**Created:** [April 4, 2019, 3:22am UTC](https://forum.search-guard.com/t/kibana-quit-not-able-to-connect-to-elasticsearch/1419 "2019-04-04T03:22:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![chan.chunlok](https://avatars.discourse-cdn.com/v4/letter/c/ac8455/32.png) [@chan.chunlok](https://forum.search-guard.com/u/chan.chunlok)\
**Post date:** [April 4, 2019, 3:22am UTC](https://forum.search-guard.com/t/kibana-quit-not-able-to-connect-to-elasticsearch/1419/1 "2019-04-04T03:22:10Z")

</div>

- Elasticsearch version - 6.5.1  
kibana version 6.5.1  
SearchGuard plugin 6.5.1

OS: centos 7

TLS offline to generate certificate.

JVM - Java 1.8.0

Hello all,

I have installed elasticsearch, kibana and searchguard. All version 6.5.1

And all are working fine till I wanna connect kibana to elasticsearch

But the program keep exiting and is due to this error.

waiting for elasticsearch\_tls\_common.js:104

c.context.setkey(options.key,options.passhrase)  
error:06065064: digital envelope routines: EVP\_DecryptFinal\_ex: bad\_decrypt:

Does anyone know if there is any missing configuration from the file.

Kindly help.

Urgent.

sg\_config.yml is default from the demo version

elasticsearch.yml[elasticsearch.yml](https://forum.search-guard.com/uploads/short-url/jdy6Bz6MXYaWCLJ1YabK0sO02xM.yml) (3.8 KB)  
[kibana.yml](https://forum.search-guard.com/uploads/short-url/p5ccujIILzNioHIwPJC8GNPhDI4.yml) (5.4 KB)

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [April 4, 2019, 6:31pm UTC](https://forum.search-guard.com/t/kibana-quit-not-able-to-connect-to-elasticsearch/1419/2 "2019-04-04T18:31:50Z")

</div>

From the error message I’d say that the key you configured here:

`elasticsearch.ssl.key: AdminNode.key`

is actually password protected, is this correct?

If so you probably also need to set:

`elasticsearch.ssl.keyPassphrase`

For debugging purposes, can you just comment these two lines in your kibana.yml and see if it makes a difference?

```
elasticsearch.ssl.certificate: AdminNode.pem
elasticsearch.ssl.key: AdminNode.key

```

Also, if you set the verification mode to none:

`elasticsearch.ssl.verificationMode: none`

You actually do not need to specify the root CA:

`elasticsearch.ssl.certificateAuthorities: ["root-ca.pem"]`

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [April 4, 2019, 6:31pm UTC](https://forum.search-guard.com/t/kibana-quit-not-able-to-connect-to-elasticsearch/1419/3 "2019-04-04T18:31:57Z")

</div>



---

<div class="post-metadata">

**Author:** ![chan.chunlok](https://avatars.discourse-cdn.com/v4/letter/c/ac8455/32.png) [@chan.chunlok](https://forum.search-guard.com/u/chan.chunlok)\
**Post date:** [April 8, 2019, 7:30am UTC](https://forum.search-guard.com/t/kibana-quit-not-able-to-connect-to-elasticsearch/1419/4 "2019-04-08T07:30:26Z")

</div>

Hi jkressin,

Thanks for the reply.

By commenting out both the pem and .key, I able to connect es with kibana with search guard.

But may I know whats the actual reason behind commenting this two lines.

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/system/32/1870_2.png) [@system](https://forum.search-guard.com/u/system)\
**Post date:** [April 29, 2019, 7:30am UTC](https://forum.search-guard.com/t/kibana-quit-not-able-to-connect-to-elasticsearch/1419/5 "2019-04-29T07:30:26Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
