# Certificate error -javax.net.ssl.SSLHandshakeException: Received fatal alert: decrypt\_error

**URL:** https://discuss.elastic.co/t/certificate-error-javax-net-ssl-sslhandshakeexception-received-fatal-alert-decrypt-error/314524
**Category:** Elasticsearch
**Tags:** elastic-stack-security
**Created:** [September 15, 2022, 3:17pm UTC](https://discuss.elastic.co/t/certificate-error-javax-net-ssl-sslhandshakeexception-received-fatal-alert-decrypt-error/314524 "2022-09-15T15:17:53Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![elkstack1](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elkstack1](https://discuss.elastic.co/u/elkstack1)
#### Post date: [September 15, 2022, 3:17pm UTC](https://discuss.elastic.co/t/certificate-error-javax-net-ssl-sslhandshakeexception-received-fatal-alert-decrypt-error/314524/1 "2022-09-15T15:17:53Z")

</div>

```auto
Getting the below error while trying to access elasticsearch https://<server:name>/9200 and it says connection is not secure

DecoderException: javax.net.ssl.SSLHandshakeException: Received fatal alert: decrypt_error
        
Below is the elasticsearch.yml config

xpack.security.http.ssl.verification_mode: certificate
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.http.ssl.supported_protocols: TLSv1.2
xpack.security.transport.ssl.enabled: true
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.key: /opt/elastic/elasticsearch_7163/elasticsearch-7.16.3/config/certs/abc123.com.key
xpack.security.http.ssl.certificate: /opt/elastic/elasticsearch_7163/elasticsearch-7.16.3/config/certs/abc123.com_chain.crt
xpack.security.http.ssl.certificate_authorities: ["/opt/elastic/elasticsearch_7163/elasticsearch-7.16.3/config/certs/abc123.com_chain.crt"]
xpack.security.transport.ssl.key: /opt/elastic/elasticsearch_7163/elasticsearch-7.16.3/config/certs/abc123.com.key
xpack.security.transport.ssl.certificate: /opt/elastic/elasticsearch_7163/elasticsearch-7.16.3/config/certs/abc123.com_chain.crt
xpack.security.transport.ssl.certificate_authorities: ["/opt/elastic/elasticsearch_7163/elasticsearch-7.16.3/config/certs/abc123.com_chain.crt"]

I downloaded the certs from org and in the zip file - it had .crt, .key and pem file

```

---

<div class="post-metadata">

### Author: ![Justin\_Cranford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_cranford/32/85302_2.png) [@Justin\_Cranford](https://discuss.elastic.co/u/Justin_Cranford)
#### Post date: [September 19, 2022, 3:19pm UTC](https://discuss.elastic.co/t/certificate-error-javax-net-ssl-sslhandshakeexception-received-fatal-alert-decrypt-error/314524/2 "2022-09-19T15:19:13Z")

</div>

Can you try adding this setting?

```auto
xpack.security.enabled: true

```

The default was changed in 8.0.0 to true. Prior versions defaulted to false, and it looks like you may be using 7.16.3.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 17, 2022, 3:19pm UTC](https://discuss.elastic.co/t/certificate-error-javax-net-ssl-sslhandshakeexception-received-fatal-alert-decrypt-error/314524/3 "2022-10-17T15:19:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
