# Azure Plugin - Error 403 can not get list of azure nodes

**URL:** <https://discuss.elastic.co/t/azure-plugin-error-403-can-not-get-list-of-azure-nodes/17733>\
**Category:** Elasticsearch\
**Created:** [May 26, 2014, 9:25pm UTC](https://discuss.elastic.co/t/azure-plugin-error-403-can-not-get-list-of-azure-nodes/17733 "2014-05-26T21:25:57Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikojiro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikojiro/32/1414_2.png) [@Nikojiro](https://discuss.elastic.co/u/Nikojiro)\
**Post date:** [May 26, 2014, 9:25pm UTC](https://discuss.elastic.co/t/azure-plugin-error-403-can-not-get-list-of-azure-nodes/17733/1 "2014-05-26T21:25:57Z")

</div>

Hi,

I've deployed a two nodes ElasticSearch cluster on Windows Azure. My setup  
is the following :

- I use OpenSSL 1.0.1c (as recommended on the plugin's GitHub pahe,  
other versions gave me trouble) to generate the SSH key, certificate and  
pkcs12 keystore
- the Azure plugin (2.2.0) is installed on both nodes and defined as  
mandatory in elasticsearch.yml
- the VMs run Ubuntu 12.04 (the exact image id is  
_b39f27a8b8c64d52b05eac6a62ebad85\_\_Ubuntu-12\_04\_4-LTS-amd64-server-20140514-en-us-30GB_  
)

When I start the cluster I have the split brain syndrome, each node elects  
itself as master and fails to see the other one. I configured the discovery  
log level to TRACE to get more detailed information, and there is the  
following error message :

[2014-05-26 17:46:21,285][WARN][cloud.azure] [elasticpoc1]  
can not get list of azure nodes: Server returned HTTP response code: 403  
for URL:  
[https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true](https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true)

This error appears 3 times in the log before the local node is elected as  
master.

I've attached the logs from both my nodes, as well as the  
_elasticsearch.yml_ config file (which only differs by setting a distinct  
node name between the 2 nodes).

I'm pretty clueless as to how I should proceed to get this right, so any  
help would be much appreciated.

Best regards,

Nicolas

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 27, 2014, 9:42am UTC](https://discuss.elastic.co/t/azure-plugin-error-403-can-not-get-list-of-azure-nodes/17733/2 "2014-05-27T09:42:05Z")

</div>

Hey Nicolas,

The 403 status code from azure basically means that your credentials are incorrects.  
It means to me that your certificate is either invalid in /home/elasticsearch/azurekeystore.pkcs12

You could try

curl --cert azure-cert.pem --key azure-pk.pem -H "x-ms-version: 2013-03-01" -H "Content-Type: application/json" "[https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true](https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true)"

And see if it works.

If not, I think

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 26 mai 2014 à 23:26:01, Nicolas Giraud ([nicosensei@gmail.com](mailto:nicosensei@gmail.com)) a écrit:

Hi,

I've deployed a two nodes ElasticSearch cluster on Windows Azure. My setup is the following :  
I use OpenSSL 1.0.1c (as recommended on the plugin's GitHub pahe, other versions gave me trouble) to generate the SSH key, certificate and pkcs12 keystore  
the Azure plugin (2.2.0) is installed on both nodes and defined as mandatory in elasticsearch.yml  
the VMs run Ubuntu 12.04 (the exact image id is b39f27a8b8c64d52b05eac6a62ebad85\_\_Ubuntu-12\_04\_4-LTS-amd64-server-20140514-en-us-30GB)  
When I start the cluster I have the split brain syndrome, each node elects itself as master and fails to see the other one. I configured the discovery log level to TRACE to get more detailed information, and there is the following error message :

[2014-05-26 17:46:21,285][WARN][cloud.azure] [elasticpoc1] can not get list of azure nodes: Server returned HTTP response code: 403 for URL: [https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true](https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true)

This error appears 3 times in the log before the local node is elected as master.

I've attached the logs from both my nodes, as well as the elasticsearch.yml config file (which only differs by setting a distinct node name between the 2 nodes).

I'm pretty clueless as to how I should proceed to get this right, so any help would be much appreciated.

Best regards,

## Nicolas

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.53845ded.275ac794.1e56%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.53845ded.275ac794.1e56%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Nikojiro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikojiro/32/1414_2.png) [@Nikojiro](https://discuss.elastic.co/u/Nikojiro)\
**Post date:** [May 27, 2014, 10:17am UTC](https://discuss.elastic.co/t/azure-plugin-error-403-can-not-get-list-of-azure-nodes/17733/3 "2014-05-27T10:17:12Z")

</div>

Ok, I'll try that as soon as I can. One (maybe dumb) question meanwhile, do  
the credentials provided when creating the certificate (I followed these  
steps :  
[http://azure.microsoft.com/en-us/documentation/articles/linux-use-ssh-key/](http://azure.microsoft.com/en-us/documentation/articles/linux-use-ssh-key/))  
need to match the Azure account credentials (email / password) ?

On Tuesday, May 27, 2014 11:42:13 AM UTC+2, David Pilato wrote:

> Hey Nicolas,
> 
> The 403 status code from azure basically means that your credentials are  
> incorrects.  
> It means to me that your certificate is either invalid  
> in /home/elasticsearch/azurekeystore.pkcs12
> 
> You could try
> 
> curl --cert azure-cert.pem --key azure-pk.pem -H "x-ms-version:  
> 2013-03-01" -H "Content-Type: application/json" "  
> [https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true](https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true)  
> "
> 
> And see if it works.
> 
> If not, I think
> 
> --  
> _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)
> 
> Le 26 mai 2014 à 23:26:01, Nicolas Giraud ([nicos...@gmail.com](mailto:nicos...@gmail.com)\<javascript:\>)  
> a écrit:
> 
> Hi,
> 
> I've deployed a two nodes Elasticsearch cluster on Windows Azure. My setup  
> is the following :
> 
> - I use OpenSSL 1.0.1c (as recommended on the plugin's GitHub pahe,  
> other versions gave me trouble) to generate the SSH key, certificate and  
> pkcs12 keystore
> - the Azure plugin (2.2.0) is installed on both nodes and defined as  
> mandatory in elasticsearch.yml
> - the VMs run Ubuntu 12.04 (the exact image id is  
> _b39f27a8b8c64d52b05eac6a62ebad85\_\_Ubuntu-12\_04\_4-LTS-amd64-server-20140514-en-us-30GB_  
> )
> 
> When I start the cluster I have the split brain syndrome, each node  
> elects itself as master and fails to see the other one. I configured the  
> discovery log level to TRACE to get more detailed information, and there is  
> the following error message :
> 
> [2014-05-26 17:46:21,285][WARN][cloud.azure] [elasticpoc1]  
> can not get list of azure nodes: Server returned HTTP response code: 403  
> for URL:  
> [https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true](https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true)
> 
> This error appears 3 times in the log before the local node is elected as  
> master.
> 
> I've attached the logs from both my nodes, as well as the  
> _elasticsearch.yml_ config file (which only differs by setting a distinct  
> node name between the 2 nodes).
> 
> I'm pretty clueless as to how I should proceed to get this right, so any  
> help would be much appreciated.
> 
> Best regards,
> 
> ## Nicolas
> 
> ## You received this message because you are subscribed to the Google Groups "elasticsearch" group. To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>. To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com?utm_medium=email&utm_source=footer) . For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b6fe8613-6929-4b01-a9d2-cc6bb921f587%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b6fe8613-6929-4b01-a9d2-cc6bb921f587%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 27, 2014, 12:01pm UTC](https://discuss.elastic.co/t/azure-plugin-error-403-can-not-get-list-of-azure-nodes/17733/4 "2014-05-27T12:01:05Z")

</div>

No they don't have to match.  
The certificate have to be uploaded to Azure platform and that's all. Whatever your email address is.

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 27 mai 2014 à 12:17:16, Nicolas Giraud ([nicosensei@gmail.com](mailto:nicosensei@gmail.com)) a écrit:

Ok, I'll try that as soon as I can. One (maybe dumb) question meanwhile, do the credentials provided when creating the certificate (I followed these steps : [http://azure.microsoft.com/en-us/documentation/articles/linux-use-ssh-key/](http://azure.microsoft.com/en-us/documentation/articles/linux-use-ssh-key/)) need to match the Azure account credentials (email / password) ?

On Tuesday, May 27, 2014 11:42:13 AM UTC+2, David Pilato wrote:  
Hey Nicolas,

The 403 status code from azure basically means that your credentials are incorrects.  
It means to me that your certificate is either invalid in /home/elasticsearch/azurekeystore.pkcs12

You could try

curl --cert azure-cert.pem --key azure-pk.pem -H "x-ms-version: 2013-03-01" -H "Content-Type: application/json" "[https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true](https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true)"

And see if it works.

If not, I think

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 26 mai 2014 à 23:26:01, Nicolas Giraud ([nicos...@gmail.com](mailto:nicos...@gmail.com)) a écrit:

Hi,

I've deployed a two nodes ElasticSearch cluster on Windows Azure. My setup is the following :  
I use OpenSSL 1.0.1c (as recommended on the plugin's GitHub pahe, other versions gave me trouble) to generate the SSH key, certificate and pkcs12 keystore  
the Azure plugin (2.2.0) is installed on both nodes and defined as mandatory in elasticsearch.yml  
the VMs run Ubuntu 12.04 (the exact image id is b39f27a8b8c64d52b05eac6a62ebad85\_\_Ubuntu-12\_04\_4-LTS-amd64-server-20140514-en-us-30GB)  
When I start the cluster I have the split brain syndrome, each node elects itself as master and fails to see the other one. I configured the discovery log level to TRACE to get more detailed information, and there is the following error message :

[2014-05-26 17:46:21,285][WARN][cloud.azure] [elasticpoc1] can not get list of azure nodes: Server returned HTTP response code: 403 for URL: [https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true](https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true)

This error appears 3 times in the log before the local node is elected as master.

I've attached the logs from both my nodes, as well as the elasticsearch.yml config file (which only differs by setting a distinct node name between the 2 nodes).

I'm pretty clueless as to how I should proceed to get this right, so any help would be much appreciated.

Best regards,

## Nicolas

## You received this message because you are subscribed to the Google Groups "elasticsearch" group. To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com). To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com). For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b6fe8613-6929-4b01-a9d2-cc6bb921f587%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b6fe8613-6929-4b01-a9d2-cc6bb921f587%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.53847e81.1f48eaa1.1e56%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.53847e81.1f48eaa1.1e56%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Nikojiro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikojiro/32/1414_2.png) [@Nikojiro](https://discuss.elastic.co/u/Nikojiro)\
**Post date:** [May 27, 2014, 12:19pm UTC](https://discuss.elastic.co/t/azure-plugin-error-403-can-not-get-list-of-azure-nodes/17733/5 "2014-05-27T12:19:57Z")

</div>

I tried as you suggested :

curl --cert azure-certificate.pem --key azure-pk.pem -H "x-ms-version:  
2013-03-01" -H "Content-Type: application/json"  
"[https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true](https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true)"

and got the same error as with ES :

`ForbiddenError`The  
server failed to authenticate the request. Verify that the certificate is  
valid and is associated with this subscription.

I'm using the Linux azure-cli and bash shells to deploy my cluster. I built  
OpenSSL 1.0.1c from source, and here are the commands I use to generate the  
certificate, private key and Java keystore (pretty much copy pasted from  
the blog article) :

OPENSSL\_BIN=/usr/local/ssl/bin/openssl  
$OPENSSL\_BIN req -x509 -nodes -days 365 -newkey rsa:2048 -keyout $PRIVKEY  
-out $CERT  
chmod 600 $PRIVKEY  
$OPENSSL\_BIN x509 -outform der -in $CERT -out $CERT\_DER

# Generate Java keystore

$OPENSSL\_BIN pkcs8 -topk8 -nocrypt -in $PRIVKEY -inform PEM -out  
azure-pk.pem -outform PEM  
cat $CERT azure-pk.pem \> azure.pem.txt  
$OPENSSL\_BIN pkcs12 -export -in azure.pem.txt -out $KEYSTORE -name azure  
-noiter -nomaciter

The certificate has been uploaded when I created the initial VM and the  
cloud service was subsequently created:

CERT=azure-certificate.pem  
SERVICE=elasticpoc  
[HOST=$SERVICE.cloudapp.net](http://HOST=$SERVICE.cloudapp.net)  
USER=elasticsearch  
VM\_PWD=esAzure1!!  
IMG=ubuntu-java7-elasticsearch  
VM\_SIZE=extralarge  
OS\_IMAGE=b39f27a8b8c64d52b05eac6a62ebad85\_\_Ubuntu-12\_04\_4-LTS-amd64-server-20140514-en-us-30GB

azure vm create $HOST $OS\_IMAGE   
--vm-name $IMG   
--location "West Europe"   
--vm-size $VM\_SIZE   
--ssh 22   
--ssh-cert ssl/$CERT   
$USER $VM\_PWD

VM\_PWD is the same as the certificate password.

The keystore is copied over SSH to the final VMs once the ne above has been  
set up and captured.

I don't understand what's happening here ...

On Tuesday, May 27, 2014 2:01:13 PM UTC+2, David Pilato wrote:

> No they don't have to match.  
> The certificate have to be uploaded to Azure platform and that's all.  
> Whatever your email address is.
> 
> --  
> _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)
> 
> Le 27 mai 2014 à 12:17:16, Nicolas Giraud ([nicos...@gmail.com](mailto:nicos...@gmail.com)\<javascript:\>)  
> a écrit:
> 
> Ok, I'll try that as soon as I can. One (maybe dumb) question meanwhile,  
> do the credentials provided when creating the certificate (I followed these  
> steps :  
> [http://azure.microsoft.com/en-us/documentation/articles/linux-use-ssh-key/](http://azure.microsoft.com/en-us/documentation/articles/linux-use-ssh-key/))  
> need to match the Azure account credentials (email / password) ?
> 
> On Tuesday, May 27, 2014 11:42:13 AM UTC+2, David Pilato wrote:
> 
> > Hey Nicolas,
> > 
> > The 403 status code from azure basically means that your credentials are  
> > incorrects.  
> > It means to me that your certificate is either invalid  
> > in /home/elasticsearch/azurekeystore.pkcs12
> > 
> > You could try
> > 
> > curl --cert azure-cert.pem --key azure-pk.pem -H "x-ms-version:  
> > 2013-03-01" -H "Content-Type: application/json" "  
> > [https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true](https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true)  
> > "
> > 
> > And see if it works.
> > 
> > If not, I think
> > 
> > ```
> > -- 
> > 
> > ```
> > 
> > _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> > @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)
> > 
> > Le 26 mai 2014 à 23:26:01, Nicolas Giraud ([nicos...@gmail.com](mailto:nicos...@gmail.com)) a écrit:
> > 
> > Hi,
> > 
> > I've deployed a two nodes Elasticsearch cluster on Windows Azure. My  
> > setup is the following :
> > 
> > - I use OpenSSL 1.0.1c (as recommended on the plugin's GitHub pahe,  
> > other versions gave me trouble) to generate the SSH key, certificate and  
> > pkcs12 keystore
> > - the Azure plugin (2.2.0) is installed on both nodes and defined as  
> > mandatory in elasticsearch.yml
> > - the VMs run Ubuntu 12.04 (the exact image id is  
> > _b39f27a8b8c64d52b05eac6a62ebad85\_\_Ubuntu-12\_04\_4-LTS-amd64-server-20140514-en-us-30GB_  
> > )
> > 
> > When I start the cluster I have the split brain syndrome, each node  
> > elects itself as master and fails to see the other one. I configured the  
> > discovery log level to TRACE to get more detailed information, and there is  
> > the following error message :
> > 
> > [2014-05-26 17:46:21,285][WARN][cloud.azure] [elasticpoc1]  
> > can not get list of azure nodes: Server returned HTTP response code: 403  
> > for URL:  
> > [https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true](https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true)
> > 
> > This error appears 3 times in the log before the local node is elected as  
> > master.
> > 
> > I've attached the logs from both my nodes, as well as the  
> > _elasticsearch.yml_ config file (which only differs by setting a  
> > distinct node name between the 2 nodes).
> > 
> > I'm pretty clueless as to how I should proceed to get this right, so any  
> > help would be much appreciated.
> > 
> > Best regards,
> > 
> > ## Nicolas
> > 
> > ## You received this message because you are subscribed to the Google Groups "elasticsearch" group. To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com). To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/39ed88e3-c30c-428a-a65f-c76cfbf99ec2%40googlegroups.com?utm_medium=email&utm_source=footer) . For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/b6fe8613-6929-4b01-a9d2-cc6bb921f587%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b6fe8613-6929-4b01-a9d2-cc6bb921f587%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/b6fe8613-6929-4b01-a9d2-cc6bb921f587%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/b6fe8613-6929-4b01-a9d2-cc6bb921f587%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/3cadf1d6-54cc-4293-a578-0d4424de6bd0%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3cadf1d6-54cc-4293-a578-0d4424de6bd0%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Nikojiro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikojiro/32/1414_2.png) [@Nikojiro](https://discuss.elastic.co/u/Nikojiro)\
**Post date:** [May 27, 2014, 9:15pm UTC](https://discuss.elastic.co/t/azure-plugin-error-403-can-not-get-list-of-azure-nodes/17733/6 "2014-05-27T21:15:10Z")

</div>

I found some relevant info  
here: [How to deploy to Azure with powershell? - Stack Overflow](http://stackoverflow.com/questions/14069593/how-to-deploy-to-azure-with-powershell)

The curl command now works. I'm currently redeploying my service, fingers  
crossed!

On Monday, May 26, 2014 11:25:58 PM UTC+2, Nicolas Giraud wrote:

> Hi,
> 
> I've deployed a two nodes Elasticsearch cluster on Windows Azure. My setup  
> is the following :
> 
> - I use OpenSSL 1.0.1c (as recommended on the plugin's GitHub pahe,  
> other versions gave me trouble) to generate the SSH key, certificate and  
> pkcs12 keystore
> - the Azure plugin (2.2.0) is installed on both nodes and defined as  
> mandatory in elasticsearch.yml
> - the VMs run Ubuntu 12.04 (the exact image id is  
> _b39f27a8b8c64d52b05eac6a62ebad85\_\_Ubuntu-12\_04\_4-LTS-amd64-server-20140514-en-us-30GB_  
> )
> 
> When I start the cluster I have the split brain syndrome, each node  
> elects itself as master and fails to see the other one. I configured the  
> discovery log level to TRACE to get more detailed information, and there is  
> the following error message :
> 
> [2014-05-26 17:46:21,285][WARN][cloud.azure] [elasticpoc1]  
> can not get list of azure nodes: Server returned HTTP response code: 403  
> for URL:  
> [https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true](https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true)
> 
> This error appears 3 times in the log before the local node is elected as  
> master.
> 
> I've attached the logs from both my nodes, as well as the  
> _elasticsearch.yml_ config file (which only differs by setting a distinct  
> node name between the 2 nodes).
> 
> I'm pretty clueless as to how I should proceed to get this right, so any  
> help would be much appreciated.
> 
> Best regards,
> 
> Nicolas

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/bdc6277a-b81f-4556-902d-832c3032ba3a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/bdc6277a-b81f-4556-902d-832c3032ba3a%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Nikojiro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikojiro/32/1414_2.png) [@Nikojiro](https://discuss.elastic.co/u/Nikojiro)\
**Post date:** [May 27, 2014, 10:20pm UTC](https://discuss.elastic.co/t/azure-plugin-error-403-can-not-get-list-of-azure-nodes/17733/7 "2014-05-27T22:20:08Z")

</div>

I confirm that this works. I simply needed to upload my PEM certificate to  
Azure under Settings/Management Certificates.

Simply uploading it with the cloud service is not enough ... dumb mistake  
in the end 😉

On Tuesday, May 27, 2014 11:15:10 PM UTC+2, Nicolas Giraud wrote:

> I found some relevant info here:  
> [How to deploy to Azure with powershell? - Stack Overflow](http://stackoverflow.com/questions/14069593/how-to-deploy-to-azure-with-powershell)
> 
> The curl command now works. I'm currently redeploying my service, fingers  
> crossed!
> 
> On Monday, May 26, 2014 11:25:58 PM UTC+2, Nicolas Giraud wrote:
> 
> > Hi,
> > 
> > I've deployed a two nodes Elasticsearch cluster on Windows Azure. My  
> > setup is the following :
> > 
> > - I use OpenSSL 1.0.1c (as recommended on the plugin's GitHub pahe,  
> > other versions gave me trouble) to generate the SSH key, certificate and  
> > pkcs12 keystore
> > - the Azure plugin (2.2.0) is installed on both nodes and defined as  
> > mandatory in elasticsearch.yml
> > - the VMs run Ubuntu 12.04 (the exact image id is  
> > _b39f27a8b8c64d52b05eac6a62ebad85\_\_Ubuntu-12\_04\_4-LTS-amd64-server-20140514-en-us-30GB_  
> > )
> > 
> > When I start the cluster I have the split brain syndrome, each node  
> > elects itself as master and fails to see the other one. I configured the  
> > discovery log level to TRACE to get more detailed information, and there is  
> > the following error message :
> > 
> > [2014-05-26 17:46:21,285][WARN][cloud.azure] [elasticpoc1]  
> > can not get list of azure nodes: Server returned HTTP response code: 403  
> > for URL:  
> > [https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true](https://management.core.windows.net/1d4c95fb-d9f1-4594-af6b-bfd3941f1c64/services/hostedservices/elasticpoc?embed-detail=true)
> > 
> > This error appears 3 times in the log before the local node is elected as  
> > master.
> > 
> > I've attached the logs from both my nodes, as well as the  
> > _elasticsearch.yml_ config file (which only differs by setting a  
> > distinct node name between the 2 nodes).
> > 
> > I'm pretty clueless as to how I should proceed to get this right, so any  
> > help would be much appreciated.
> > 
> > Best regards,
> > 
> > Nicolas

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/9ef6c2bd-30a1-450b-ad41-0330a5815180%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/9ef6c2bd-30a1-450b-ad41-0330a5815180%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:26am UTC](https://discuss.elastic.co/t/azure-plugin-error-403-can-not-get-list-of-azure-nodes/17733/8 "2017-07-06T01:26:31Z")

</div>


