# Calling Elastic search from remote server via https

**URL:** <https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254>\
**Category:** Elasticsearch\
**Created:** [April 18, 2023, 9:52pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254 "2023-04-18T21:52:52Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [April 18, 2023, 9:52pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/1 "2023-04-18T21:52:52Z")

</div>

This works fine on local machine  
curl --cacert /etc/elasticsearch/certs/http\_ca.crt -u elastic: http **s** ://localhost:9200

This does not work remotely  
curl --cacert /etc/elasticsearch/certs/http\_ca.crt -u elastic: http **s** ://server.name.com:9200

The server won't start here is the configuration.

```auto
# ======================== Elasticsearch Configuration =========================
#
path.data: /var/lib/elasticsearch
#
path.logs: /var/log/elasticsearch
#
action.auto_create_index: ".ent-search-*-logs-*,-.ent-search-*,+*"
#
network.host: server.name.com
#
xpack.security.enabled: true
xpack.security.enrollment.enabled: true
xpack.security.authc.api_key.enabled: true
xpack.security.http.ssl.enabled: true
#
# Enable encryption for HTTP API client connections, such as Kibana, Logstash, and Agents
xpack.security.http.ssl:
 enabled: true
 keystore.path: /etc/elasticsearch/certs/http.p12
#
# Enable encryption and mutual authentication between cluster nodes
xpack.security.transport.ssl:
 enabled: true
 verification_mode: certificate
 keystore.path: /etc/elasticsearch/certs/transport.p12
 truststore.path: /etc/elasticsearch/certs/transport.p12
#
#----------------------- END SECURITY AUTO CONFIGURATION -------------------------

```

This is the error message.

```auto
[2023-04-18T16:26:04,842][INFO][o.e.p.PluginsService] [rofccs901a] loaded module [x-pack-text-structure]
[2023-04-18T16:26:04,842][INFO][o.e.p.PluginsService] [rofccs901a] loaded module [x-pack-voting-only-node]
[2023-04-18T16:26:04,842][INFO][o.e.p.PluginsService] [rofccs901a] loaded module [x-pack-watcher]
[2023-04-18T16:26:04,842][INFO][o.e.p.PluginsService] [rofccs901a] loaded module [x-pack-write-load-forecaster]
[2023-04-18T16:26:04,842][INFO][o.e.p.PluginsService] [rofccs901a] no plugins loaded
[2023-04-18T16:26:07,529][INFO][o.e.e.NodeEnvironment] [rofccs901a] using [1] data paths, mounts [[/var (/dev/mapper/vg_system-lv_var)]], net usable_space [6.5gb], net total_space [9.7gb], types [ext4]
[2023-04-18T16:26:07,529][INFO][o.e.e.NodeEnvironment] [rofccs901a] heap size [7.7gb], compressed ordinary object pointers [true]
[2023-04-18T16:26:07,693][INFO][o.e.n.Node] [rofccs901a] node name [rofccs901a], node ID [Hdt100ybQqeo8xCaJLjnOQ], cluster name [elasticsearch], roles [ingest, data_frozen, ml, data_hot, transform, data_content, data_warm, master, remote_cluster_client, data, data_cold]
[2023-04-18T16:26:10,794][INFO][o.e.x.s.Security] [rofccs901a] Security is enabled
[2023-04-18T16:26:11,030][INFO][o.e.x.s.a.s.FileRolesStore] [rofccs901a] parsed [0] roles from file [/etc/elasticsearch/roles.yml]
[2023-04-18T16:26:11,407][INFO][o.e.x.s.InitialNodeSecurityAutoConfiguration] [rofccs901a] Auto-configuration will not generate a password for the elastic built-in superuser, as we cannot determine if there is a terminal attached to the elasticsearch process. You can use the `bin/elasticsearch-reset-password` tool to set the password for the elastic user.
[2023-04-18T16:26:11,484][INFO][o.e.x.m.p.l.CppLogMessageHandler] [rofccs901a] [controller/28992] [Main.cc@123] controller (64 bit): Version 8.6.2 (Build 0d41528b670ce1) Copyright (c) 2023 Elasticsearch BV
[2023-04-18T16:26:12,057][INFO][o.e.t.n.NettyAllocator] [rofccs901a] creating NettyAllocator with the following configs: [name=elasticsearch_configured, chunk_size=1mb, suggested_max_allocation_size=1mb, factors={es.unsafe.use_netty_default_chunk_and_page_size=false, g1gc_enabled=true, g1gc_region_size=4mb}]
[2023-04-18T16:26:12,087][INFO][o.e.i.r.RecoverySettings] [rofccs901a] using rate limit [40mb] with [default=40mb, read=0b, write=0b, max=0b]
[2023-04-18T16:26:12,135][INFO][o.e.d.DiscoveryModule] [rofccs901a] using discovery type [multi-node] and seed hosts providers [settings]
[2023-04-18T16:26:13,456][INFO][o.e.n.Node] [rofccs901a] initialized
[2023-04-18T16:26:13,457][INFO][o.e.n.Node] [rofccs901a] starting ...
[2023-04-18T16:26:13,475][INFO][o.e.x.s.c.f.PersistentCache] [rofccs901a] persistent cache index loaded
[2023-04-18T16:26:13,476][INFO][o.e.x.d.l.DeprecationIndexingComponent] [rofccs901a] deprecation component started
[2023-04-18T16:26:13,562][INFO][o.e.t.TransportService] [rofccs901a] publish_address {rofccs901a.mayo.edu/10.146.73.221:9300}, bound_addresses {10.146.73.221:9300}
[2023-04-18T16:26:14,332][INFO][o.e.b.BootstrapChecks] [rofccs901a] bound or publishing to a non-loopback address, enforcing bootstrap checks
[2023-04-18T16:26:14,355][INFO][o.e.n.Node] [rofccs901a] stopping ...
[2023-04-18T16:26:14,406][INFO][o.e.n.Node] [rofccs901a] stopped
[2023-04-18T16:26:14,406][INFO][o.e.n.Node] [rofccs901a] closing ...
[2023-04-18T16:26:14,424][INFO][o.e.n.Node] [rofccs901a] closed
[2023-04-18T16:26:14,426][INFO][o.e.x.m.p.NativeController] [rofccs901a] Native controller process has stopped - no new native processes can be started

```

```auto

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 18, 2023, 10:25pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/2 "2023-04-18T22:25:00Z")

</div>

> [@neil.maffitt](#):
>
> This is the error message.
> 
> ```auto
> 
> ```

There is no error there, and from what I can see Elasticsearch is starting up and running fine until something asks it to shutdown.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 18, 2023, 10:42pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/3 "2023-04-18T22:42:53Z")

</div>

> [@warkolm](#):
>
> from what I can see Elasticsearch is starting up and running fine

Actually I don't think so. The http REST layer does not start. Only the Transport Layer started:

```auto
publish_address {rofccs901a.mayo.edu/10.146.73.221:9300}, bound_addresses {10.146.73.221:9300}

```

But indeed there is no error message which looks wrong...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 18, 2023, 10:45pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/4 "2023-04-18T22:45:09Z")

</div>

Yep you're right, I missed that part. But it's still starting up before it's asked to shutdown.

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [April 18, 2023, 10:45pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/5 "2023-04-18T22:45:17Z")

</div>

Is there anything in the configuration missing?  
Also role.yml is empty should there be something in there?

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [April 18, 2023, 10:46pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/6 "2023-04-18T22:46:27Z")

</div>

What could possible ask it to shut down? Permissions issue?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 18, 2023, 10:50pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/7 "2023-04-18T22:50:44Z")

</div>

There's no errors in your logs, so no.

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [April 18, 2023, 10:53pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/8 "2023-04-18T22:53:23Z")

</div>

From systemd journal

```auto
-- Subject: Unit elasticsearch.service has begun start-up
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
--
-- Unit elasticsearch.service has begun starting up.
Apr 18 17:48:26 rofccs901a systemd-entrypoint[116624]: bootstrap check failure [1] of [1]: the default discovery settings are unsuitable for production use; at least one of [discovery.see
Apr 18 17:48:26 rofccs901a systemd-entrypoint[116624]: ERROR: Elasticsearch did not exit normally - check the logs at /var/log/elasticsearch/elasticsearch.log
Apr 18 17:48:28 rofccs901a systemd-entrypoint[116624]: ERROR: [1] bootstrap checks failed. You must address the points described in the following [1] lines before starting Elasticsearch.
Apr 18 17:48:28 rofccs901a systemd[1]: elasticsearch.service: main process exited, code=exited, status=78/n/a
Apr 18 17:48:28 rofccs901a systemd[1]: Failed to start Elasticsearch.
-- Subject: Unit elasticsearch.service has failed
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
--
-- Unit elasticsearch.service has failed.
--
-- The result is failed.

```

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [April 18, 2023, 10:56pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/9 "2023-04-18T22:56:16Z")

</div>

If I remove this from the elastic.yml file then Elasticsearch starts fine but then I can't do a remote curl.

```auto
network.host: server.name.com

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 18, 2023, 11:12pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/10 "2023-04-18T23:12:38Z")

</div>

Could you try with the ip address instead of the name?

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [April 19, 2023, 1:50pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/11 "2023-04-19T13:50:56Z")

</div>

ok, I did change it to IP address and get then same error message. But this time I noticed this error message

```auto
systemd-entrypoint[72712]: bootstrap check failure [1] of [1]: the default discovery settings are unsuitable for production use; at least one of [discovery.seed_hosts, discovery.seed_providers, cluster.initial_master_nodes] must be configured

```

This is the first time I am starting Elastic search with the network.host set. This is a single instance of Elastic Search and I am not setting up a cluster.  
Is this my issue? What yml settings should I add? Thanks

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [April 19, 2023, 8:45pm UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/12 "2023-04-19T20:45:10Z")

</div>

Is there verbose logging that could be done.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 22, 2023, 10:48am UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/13 "2023-04-22T10:48:37Z")

</div>

It sounds like you want to set the node into single-node discovery:

> **[Bootstrap Checks | Elasticsearch Guide \[8.7\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/bootstrap-checks.html#single-node-discovery)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2023, 10:49am UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254/14 "2023-05-20T10:49:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
