# Configure X-Pack.Security on ELK V6.2.4

**URL:** <https://discuss.elastic.co/t/configure-x-pack-security-on-elk-v6-2-4/139502>\
**Category:** Elasticsearch\
**Created:** [July 11, 2018, 7:59am UTC](https://discuss.elastic.co/t/configure-x-pack-security-on-elk-v6-2-4/139502 "2018-07-11T07:59:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sreejiths](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@sreejiths](https://discuss.elastic.co/u/sreejiths)\
**Post date:** [July 11, 2018, 7:59am UTC](https://discuss.elastic.co/t/configure-x-pack-security-on-elk-v6-2-4/139502/1 "2018-07-11T07:59:34Z")

</div>

As part of testing X-Pack.Security on Elasticsearch V6.2.4 in our UAT infra , Was trting to set passwords for build in users i am getting below error .

Can anyone please help/advise on this issue

[root@elasticsearch-uat-1 elasticsearch]# bin/x-pack/setup-passwords interactive  
15:46:35.441 [main] ERROR org.elasticsearch.xpack.core.ssl.SSLService - unsupported ciphers [[TLS\_ECDHE\_RSA\_WITH\_AES\_256\_CBC\_SHA384, TLS\_ECDHE\_ECDSA\_WITH\_AES\_256\_CBC\_SHA384, TLS\_ECDHE\_ECDSA\_WITH\_AES\_256\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_256\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA]] were requested but cannot be used in this JVM, however there are supported ciphers that will be used [[TLS\_RSA\_WITH\_AES\_256\_CBC\_SHA256, TLS\_RSA\_WITH\_AES\_256\_CBC\_SHA, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA]]. If you are trying to use ciphers with a key length greater than 128 bits on an Oracle JVM, you will need to install the unlimited strength JCE policy files.  
Exception in thread "main" ElasticsearchException[failed to initialize a TrustManagerFactory]; nested: IOException[keystore password was incorrect]; nested: UnrecoverableKeyException[failed to decrypt safe contents entry: javax.crypto.BadPaddingException: Given final block not properly padded];  
at org.elasticsearch.xpack.core.ssl.StoreTrustConfig.createTrustManager(StoreTrustConfig.java:72)  
at org.elasticsearch.xpack.core.ssl.SSLService.createSslContext(SSLService.java:419)  
at java.util.HashMap.computeIfAbsent(HashMap.java:1118)  
at org.elasticsearch.xpack.core.ssl.SSLService.lambda$loadSSLConfigurations$0(SSLService.java:465)  
at java.util.ArrayList.forEach(ArrayList.java:1249)  
at org.elasticsearch.xpack.core.ssl.SSLService.loadSSLConfigurations(SSLService.java:464)  
at org.elasticsearch.xpack.core.ssl.SSLService.(SSLService.java:91)  
at org.elasticsearch.xpack.security.authc.esnative.tool.CommandLineHttpClient.postURL(CommandLineHttpClient.java:92)  
at org.elasticsearch.xpack.security.authc.esnative.tool.SetupPasswordTool$SetupCommand.checkElasticKeystorePasswordValid(SetupPasswordTool.java:278)  
at org.elasticsearch.xpack.security.authc.esnative.tool.SetupPasswordTool$InteractiveSetup.execute(SetupPasswordTool.java:172)  
at org.elasticsearch.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:86)  
at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:124)  
at org.elasticsearch.cli.MultiCommand.execute(MultiCommand.java:75)  
at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:124)  
at org.elasticsearch.cli.Command.main(Command.java:90)  
at org.elasticsearch.xpack.security.authc.esnative.tool.SetupPasswordTool.main(SetupPasswordTool.java:105)  
Caused by: java.io.IOException: keystore password was incorrect  
at sun.security.pkcs12.PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2015)  
at java.security.KeyStore.load(KeyStore.java:1445)  
at org.elasticsearch.xpack.core.ssl.CertUtils.readKeyStore(CertUtils.java:276)  
at org.elasticsearch.xpack.core.ssl.CertUtils.trustManager(CertUtils.java:267)  
at org.elasticsearch.xpack.core.ssl.StoreTrustConfig.createTrustManager(StoreTrustConfig.java:70)  
... 15 more  
Caused by: java.security.UnrecoverableKeyException: failed to decrypt safe contents entry: javax.crypto.BadPaddingException: Given final block not properly padded  
... 20 more  
[root@elasticsearch-uat-1 elasticsearch]# pwd  
/usr/share/elasticsearch  
[root@elasticsearch-uat-1 elasticsearch]#

---

<div class="post-metadata">

**Author:** ![sreejiths](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@sreejiths](https://discuss.elastic.co/u/sreejiths)\
**Post date:** [July 11, 2018, 8:14am UTC](https://discuss.elastic.co/t/configure-x-pack-security-on-elk-v6-2-4/139502/2 "2018-07-11T08:14:57Z")

</div>

As the error showed "keystore password was incorrect" i tried adding "xpack.ssl.keystore.password" in elasticsearch.yml , BUT that also does not help

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 12, 2018, 1:07am UTC](https://discuss.elastic.co/t/configure-x-pack-security-on-elk-v6-2-4/139502/3 "2018-07-12T01:07:28Z")

</div>

It's hard to give you specific advice without understanding your configuration, but the general cause of the problem is this:

- You have configured a `truststore` (or perhaps `keystore`, but from the error message, I think it's more likely to be a `truststore`) somewhere in your `elasticsearch.yml`
- You pust the password for that truststore into the elasticsearch keystore with the `elasticsearch-keystore` tool

In the version you are running (6.2), the `setup-passwords` tool is unable to read SSL passwords from the elasticsearch keystore. It needs them to be in the `elasticsearch.yml` file.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2018, 1:14am UTC](https://discuss.elastic.co/t/configure-x-pack-security-on-elk-v6-2-4/139502/4 "2018-08-09T01:14:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
