# Can't start ES 7.3.0 with x-pack security enabled

**URL:** <https://discuss.elastic.co/t/cant-start-es-7-3-0-with-x-pack-security-enabled/195742>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 19, 2019, 12:46pm UTC](https://discuss.elastic.co/t/cant-start-es-7-3-0-with-x-pack-security-enabled/195742 "2019-08-19T12:46:03Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ludaca](https://avatars.discourse-cdn.com/v4/letter/l/ac8455/32.png) [@ludaca](https://discuss.elastic.co/u/ludaca)\
**Post date:** [August 19, 2019, 12:46pm UTC](https://discuss.elastic.co/t/cant-start-es-7-3-0-with-x-pack-security-enabled/195742/1 "2019-08-19T12:46:03Z")

</div>

Hello,  
I'm trying to enable xpack.security in ES 7.3.0 fresh install on k8s.  
X-pack license type: basic

My elasticsearch.yml  
\</\> cluster.name: "es7-sec"  
network.host: 0.0.0.0  
path.logs: /var/log  
discovery.seed\_hosts:  
- es-master-0  
- es-master-1  
.........  
- es-data1-2  
cluster.initial\_master\_nodes:  
- es-master-0  
- es-master-1  
- es-master-2  
xpack.security.enabled: true  
xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12  
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12  
\</\>

elastic-certificates.p12 generated using docker-compose with ES image 7.3.0 by command":  
bin/elasticsearch-certutil cert --silent --pass xxxxx -out elastic-certificates.p12  
and mounted on all nodes in ES cluster under /usr/share/elasticsearch/config with permissions:  
600 elasticsearch:root elastic-certificates.p12

Containers crashed with such messages in ES log:  
\</\> "Caused by: java.lang.IllegalStateException: failed to load plugin class [org.elasticsearch.xpack.core.XPackPlugin]",  
"Caused by: java.lang.reflect.InvocationTargetException",  
"Caused by: org.elasticsearch.ElasticsearchException: failed to initialize a TrustManagerFactory",  
"Caused by: java.io.IOException: keystore password was incorrect",  
"Caused by: java.security.UnrecoverableKeyException: failed to decrypt safe contents entry: javax.crypto.BadPaddingException: Given final block not properly padded. Such issues can arise if a bad key is used during decryption."  
\</\>

Any help will be appreciated.  
Thanks in advance  
Luda

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 19, 2019, 12:54pm UTC](https://discuss.elastic.co/t/cant-start-es-7-3-0-with-x-pack-security-enabled/195742/2 "2019-08-19T12:54:06Z")

</div>

The problem is that you are setting a password for your `PKCS#12` file by passing `--pass` parameter, but then you're not providing that password to Elasticsearch for it to be able to decrypt and read your `elastic-certificates.p12`

If you want/need to use a password protected keystore/truststore, then you need to set also

```auto
xpack.security.transport.ssl.keystore.password: 
xpack.security.transport.ssl.truststore.password: 

```

so that Elasticsearch can read your `elastic-certificates.p12`

---

<div class="post-metadata">

**Author:** ![ludaca](https://avatars.discourse-cdn.com/v4/letter/l/ac8455/32.png) [@ludaca](https://discuss.elastic.co/u/ludaca)\
**Post date:** [August 19, 2019, 2:00pm UTC](https://discuss.elastic.co/t/cant-start-es-7-3-0-with-x-pack-security-enabled/195742/3 "2019-08-19T14:00:01Z")

</div>

Thank you, the masters started now, but in ES logs there is:  
\</\> "message": "[xpack.security.transport.ssl.truststore.password] setting was deprecated in Elasticsearch and will be removed in a future release! See the breaking changes documentation for the next major version." } \</\>  
Is there a possibility to create p12 cert without password?

---

<div class="post-metadata">

**Author:** ![crickes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crickes/32/18009_2.png) [@crickes](https://discuss.elastic.co/u/crickes)\
**Post date:** [August 19, 2019, 2:28pm UTC](https://discuss.elastic.co/t/cant-start-es-7-3-0-with-x-pack-security-enabled/195742/5 "2019-08-19T14:28:30Z")

</div>

The parameter names has been changed.  
Its now called: xpack.security.transport.ssl.truststore.secure\_password

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 19, 2019, 3:49pm UTC](https://discuss.elastic.co/t/cant-start-es-7-3-0-with-x-pack-security-enabled/195742/6 "2019-08-19T15:49:16Z")

</div>

> [@ludaca](#):
>
> Is there a possibility to create p12 cert without password?

Unfortunately you can't create a PKCS12 store without setting a password, you can only set an empty password, see the documentation for `--pass` parameter in [elasticsearch-certutil | Reference](https://www.elastic.co/guide/en/elasticsearch/reference/current/certutil.html).

##### Possible solution 1

[Editing this to keep everything in place for future reference]  
As @TimV mentioned in the [post below](https://discuss.elastic.co/t/cant-start-es-7-3-0-with-x-pack-security-enabled/195742/7) correcting me:

> [@TimV](#):
>
> We assume that the password is blank if it is not specified. Simply create a PKCS#12 file with a blank password, and leave the `.password` (and `.secure_password` ) unset.

##### Possible solution 2

As @crickes mentioned, you can either use the equivalent secure settings:

```auto
xpack.security.transport.ssl.keystore.secure_password:
xpack.security.transport.ssl.truststore.secure_password:

```

that need to be set in the [secure settings](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/secure-settings.html)

To be precise, these have not been changed but `password` has been deprecated in favor of `secure_password`.

##### Possible solution 3

If you can't/don't want to use secure settings, then you alternatively use elasticsearch-certutil to create a PEM formatted key and certificate that do not need to be password protected, using the `--pem` parameter

i.e.

```auto
bin/elasticsearch-certutil cert --silent --pem -out elastic-certificates-pem.zip

```

and unzipping this you will get 3 files

- ca/ca.crt
- instance/instance.crt
- instance/instance.key

Then you can configure your nodes with

```auto
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate 
xpack.security.transport.ssl.key: instance.key
xpack.security.transport.ssl.certificate:instance.crt 
xpack.security.transport.ssl.certificate_authorities: ["ca.crt"] 

```

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 20, 2019, 2:23am UTC](https://discuss.elastic.co/t/cant-start-es-7-3-0-with-x-pack-security-enabled/195742/7 "2019-08-20T02:23:59Z")

</div>

> [@ikakavas](#):
>
> If you want/need to use a password protected keystore/truststore, then you need to set also
> 
> ```auto
> xpack.security.transport.ssl.keystore.password: 
> xpack.security.transport.ssl.truststore.password: 
> 
> ```

This should not be necessary. We assume that the password is blank if it is not specified. Simply create a PKCS#12 file with a blank password, and leave the `.password` (and `.secure_password`) unset.

---

<div class="post-metadata">

**Author:** ![ludaca](https://avatars.discourse-cdn.com/v4/letter/l/ac8455/32.png) [@ludaca](https://discuss.elastic.co/u/ludaca)\
**Post date:** [August 20, 2019, 5:54am UTC](https://discuss.elastic.co/t/cant-start-es-7-3-0-with-x-pack-security-enabled/195742/8 "2019-08-20T05:54:03Z")

</div>

Thanks so much to everyone for the detailed answers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 17, 2019, 5:54am UTC](https://discuss.elastic.co/t/cant-start-es-7-3-0-with-x-pack-security-enabled/195742/9 "2019-09-17T05:54:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
