What?
Describe the feature
Add a global, deployment-wide setting to configure trusted certificate authorities for all
connector (action) TLS connections, in addition to the existing per-host customHostSettings.
Proposed settings (naming aligned with existing customHostSettings[n].ssl.*):
xpack.actions.ssl.certificateAuthoritiesData: |
-----BEGIN CERTIFICATE-----
...intermediate...
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
...root...
-----END CERTIFICATE-----
# and for self-managed:
xpack.actions.ssl.certificateAuthoritiesFiles: ["/path/to/ca-chain.pem"]
Why?
My customer runs Kibana on Elastic Cloud Enterprise (ECE). Alerting rules send webhooks to
dozens of internal HTTPS endpoints, all signed by the internal (private) CA chain.
Current options and why they don't scale for us:
pack.actions.customHostSettings[n].ssl.certificateAuthoritiesData
Requires one entry per host:port (no wildcards). With dozens of endpoints the user settings become huge and must be updated for every new endpoint.
customHostSettings[n].ssl.certificateAuthoritiesFiles
Not supported on ECE / Elastic Cloud (self-managed only).
NODE_EXTRA_CA_CERTS (documented via #75870 / #84578)
Not possible on ECE: no way to set env vars for the Kibana process.
Custom Kibana Docker image
We don't want to maintain a modified version of the official image.
CA per webhook connector (config.ca, #160812 / #161894)
Has to be set on every connector; easy to forget and hard to rotate when the CA changes.
verificationMode: none
Not acceptable
Acceptance Criteria
A single global CA setting would solve this with one entry in the Kibana user settings, and
make CA rotation a single change.
Priority
Important (workaround exists)
Blocked By
No response
Additional Context
On premise, security aware environment. All external webhooks use Custom CA.
What?
Describe the feature
Add a global, deployment-wide setting to configure trusted certificate authorities for all
connector (action) TLS connections, in addition to the existing per-host
customHostSettings.Proposed settings (naming aligned with existing
customHostSettings[n].ssl.*):Why?
My customer runs Kibana on Elastic Cloud Enterprise (ECE). Alerting rules send webhooks to
dozens of internal HTTPS endpoints, all signed by the internal (private) CA chain.
Current options and why they don't scale for us:
pack.actions.customHostSettings[n].ssl.certificateAuthoritiesData
Requires one entry per host:port (no wildcards). With dozens of endpoints the user settings become huge and must be updated for every new endpoint.
customHostSettings[n].ssl.certificateAuthoritiesFiles
Not supported on ECE / Elastic Cloud (self-managed only).
NODE_EXTRA_CA_CERTS (documented via #75870 / #84578)
Not possible on ECE: no way to set env vars for the Kibana process.
Custom Kibana Docker image
We don't want to maintain a modified version of the official image.
CA per webhook connector (config.ca, #160812 / #161894)
Has to be set on every connector; easy to forget and hard to rotate when the CA changes.
verificationMode: none
Not acceptable
Acceptance Criteria
A single global CA setting would solve this with one entry in the Kibana user settings, and
make CA rotation a single change.
Priority
Important (workaround exists)
Blocked By
No response
Additional Context
On premise, security aware environment. All external webhooks use Custom CA.