diff --git a/ansible/roles/kibana/templates/kibana.yml.j2 b/ansible/roles/kibana/templates/kibana.yml.j2
index bf0043a700..d613c3c980 100644
--- a/ansible/roles/kibana/templates/kibana.yml.j2
+++ b/ansible/roles/kibana/templates/kibana.yml.j2
@@ -6,4 +6,6 @@ elasticsearch.url: "{{ internal_protocol }}://{{ kolla_internal_fqdn | put_addre
 elasticsearch.requestTimeout: {{ kibana_elasticsearch_request_timeout }}
 elasticsearch.shardTimeout: {{ kibana_elasticsearch_shard_timeout }}
 elasticsearch.ssl.verificationMode: "{{ 'full' if kibana_elasticsearch_ssl_verify | bool else 'none' }}"
+{% if openstack_cacert | length > 0 %}
 elasticsearch.ssl.certificateAuthorities: {{ openstack_cacert }}
+{% endif %}
diff --git a/releasenotes/notes/kibana-no-cacert-1994d03bc915dfc0.yaml b/releasenotes/notes/kibana-no-cacert-1994d03bc915dfc0.yaml
new file mode 100644
index 0000000000..c7376fbef4
--- /dev/null
+++ b/releasenotes/notes/kibana-no-cacert-1994d03bc915dfc0.yaml
@@ -0,0 +1,6 @@
+---
+fixes:
+  - |
+    Fixes an issue with Kibana deployment when ``openstack_cacert`` is unset.
+    See `bug 1864180 <https://bugs.launchpad.net/kolla-ansible/+bug/1864180>`_
+    for details.