# Calling Elasticsearch/X-Pack API from node js application

**URL:** <https://discuss.elastic.co/t/calling-elasticsearch-x-pack-api-from-node-js-application/154343>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 28, 2018, 1:25pm UTC](https://discuss.elastic.co/t/calling-elasticsearch-x-pack-api-from-node-js-application/154343 "2018-10-28T13:25:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vigneshr35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vigneshr35/32/32636_2.png) [@vigneshr35](https://discuss.elastic.co/u/vigneshr35)\
**Post date:** [October 28, 2018, 1:25pm UTC](https://discuss.elastic.co/t/calling-elasticsearch-x-pack-api-from-node-js-application/154343/1 "2018-10-28T13:25:23Z")

</div>

Hi Team,

I have developed a node js service that will call Elasticsearch APIs to perform various operations like creating roles, creating users, establish user-role mapping etc. The Elasticsearch instance has been configured so as to enable HTTPS to access Elasticsearch APIs.

When my application calls the API, the below shown error message is seen

> { Error: unable to verify the first certificate  
> at TLSSocket. (\_tls\_wrap.js:1103:38)  
> at emitNone (events.js:106:13)  
> at TLSSocket.emit (events.js:208:7)  
> at TLSSocket.\_finishInit (\_tls\_wrap.js:637:8)  
> at TLSWrap.ssl.onhandshakedone (\_tls\_wrap.js:467:38) code: 'UNABLE\_TO\_VERIFY\_LEAF\_SIGNATURE' }  
> { Error: socket hang up  
> at createHangUpError (\_http\_client.js:331:15)

Here are the request options for the API call from my node application.  
Please let me know if key, cert and ca are the only required options to be added ?

> var optionspost = {  
> host: utilities.elastic.host,  
> path: utilities.elasticAPIS.createUserRole+roleName,  
> port: utilities.elastic.port,  
> method: 'PUT',  
> key: \<path\_to\_elasticsearch\_client\_key\>, encoding),  
> cert: \<path\_to\_elasticsearch\_client\_cert\>, encoding),  
> ca: HPECAs.All\_HPE\_CAs,  
> headers: postheaders  
> };

The SSL configurations in elasticsearch.yml are as follows:

> xpack.ssl.certificate: \<path\_to\_elasticsearch\>/config/certificates/server.crt  
> xpack.ssl.key: \<path\_to\_elasticsearch\>/config/certificates/server.key  
> xpack.ssl.certificate\_authorities: ["\<path\_to\_elasticsearch\>/elasticsearch/config/certificates/ca1.cer","\<path\_to\_elasticsearch\>/elasticsearch/config/certificates/ca2.cer"]

Please confirm if-

1. The value of 'key' in my application's request options should be the path for the same server key that is configured in xpack.ssl.key ?
2. The value of 'cert' in my application's request options should be the path for the same server cert that is configured in xpack.ssl.certificate ?
3. The value of 'ca' in my application's request options should be the path for the ca's configured in xpack.ssl.certificate\_authorities ?

Thank you,  
Vignesh Ravi

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [October 29, 2018, 1:37am UTC](https://discuss.elastic.co/t/calling-elasticsearch-x-pack-api-from-node-js-application/154343/2 "2018-10-29T01:37:25Z")

</div>

> [@vigneshr35](#):
>
> { Error: unable to verify the first certificate

It looks like your node client does not trust the certificate provided by the Elasticsearch HTTP service.

> [@](#):
>
> ```auto
> var optionspost = {
> ... 
> }
> 
> ```

And what are you doing with these options? What client library are you using, and what API are you passing the options to?

> ```
> ca: HPECAs.All_HPE_CAs
> 
> ```

Is that the same set of CAs as you use in your elasticsearch config?

> [@](#):
>
> ```auto
> xpack.ssl.certificate_authorities: ["<path_to_elasticsearch>/elasticsearch/config/certificates/ca1.cer","<path_to_elasticsearch>/elasticsearch/config/certificates/ca2.cer"]
> 
> ```

> [@vigneshr35](#):
>
> Please confirm if-

I can't really answer these without knowing what you are doing with the request options, but...

> [@vigneshr35](#):
>
> The value of 'key' in my application's request options should be the path for the same server key that is configured in xpack.ssl.key ?  
> The value of 'cert' in my application's request options should be the path for the same server cert that is configured in xpack.ssl.certificate ?

No, almost certainly not.  
You only want to provide a certificate and key in your client if your cluster is enforcing client certificates for the Rest interface (which is typically not the case).  
If it is, then you want each client to have its own certificate and key, you shouldn't reuse the servers certificate for client authentication.  
Otherwise, just don't configure a client certificate/key.

> [@vigneshr35](#):
>
> The value of 'ca' in my application's request options should be the path for the ca's configured in xpack.ssl.certificate\_authorities ?

It should be the path to local copies of those same files.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2018, 1:42am UTC](https://discuss.elastic.co/t/calling-elasticsearch-x-pack-api-from-node-js-application/154343/3 "2018-11-26T01:42:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
