# Connect Enterprise Search to elasticsearch via SSL

**URL:** https://discuss.elastic.co/t/connect-enterprise-search-to-elasticsearch-via-ssl/271466
**Category:** Elastic Search
**Tags:** elastic-app-search
**Created:** [April 28, 2021, 6:02am UTC](https://discuss.elastic.co/t/connect-enterprise-search-to-elasticsearch-via-ssl/271466 "2021-04-28T06:02:24Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![rabi82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabi82/32/87817_2.png) [@rabi82](https://discuss.elastic.co/u/rabi82)
#### Post date: [April 28, 2021, 6:02am UTC](https://discuss.elastic.co/t/connect-enterprise-search-to-elasticsearch-via-ssl/271466/1 "2021-04-28T06:02:24Z")

</div>

Hi,  
i have the Elasticsearch up and running with SSL  
the command curl --insecure -X GET '[https://localhost:9200?pretty](https://localhost:9200?pretty)' works perfectly  
now after installing the Enterprise Search, the yml looks like below ::

elasticsearch.host: [https://localhost:9200](https://localhost:9200)

allow\_es\_settings\_modification: true

secret\_management.encryption\_keys: [z%C\*F-Ja]

ent\_search.ssl.enabled: true  
ent\_search.ssl.keystore.path: "/keys/keystore.jks"  
ent\_search.ssl.keystore.password: "changeme"  
ent\_search.ssl.keystore.key\_password: "changeme"  
ent\_search.external\_url: [https://localhost:3002](https://localhost:3002)

but the connection failed  
any idea ?

---

<div class="post-metadata">

### Author: ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)
#### Post date: [April 28, 2021, 11:23pm UTC](https://discuss.elastic.co/t/connect-enterprise-search-to-elasticsearch-via-ssl/271466/2 "2021-04-28T23:23:40Z")

</div>

Are you using self signed certs? If so the. The enterprise search server probably isn't set up to trust the elasticsearch server certificate.

---

<div class="post-metadata">

### Author: ![rabi82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabi82/32/87817_2.png) [@rabi82](https://discuss.elastic.co/u/rabi82)
#### Post date: [April 29, 2021, 12:51am UTC](https://discuss.elastic.co/t/connect-enterprise-search-to-elasticsearch-via-ssl/271466/3 "2021-04-29T00:51:11Z")

</div>

hi Alex  
the request curl --insecure -X GET '[https://localhost:9200?pretty](https://localhost:9200?pretty)' works fine  
so I assume the SSL configuration is ok in the elasticsearch

the lasticsearch.yml looks like below ::  
network.host: 0.0.0.0  
cluster.initial\_master\_nodes: ["node-1"]

xpack.security.enabled: true  
xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: none  
xpack.security.transport.ssl.keystore.path: certs/elastic-certificates.p12  
xpack.security.transport.ssl.truststore.path: certs/elastic-certificates.p12

xpack.security.http.ssl.enabled: true  
xpack.security.http.ssl.keystore.path: certs/elastic-certificates.p12  
xpack.security.http.ssl.truststore.path: certs/elastic-certificates.p12  
xpack.security.http.ssl.client\_authentication: none

http.host: 0.0.0.0  
http.cors.enabled : true  
http.cors.allow-origin : "\*"  
http.cors.allow-methods : OPTIONS, HEAD, GET, POST, PUT, DELETE  
http.cors.allow-headers : X-Requested-With,X-Auth-Token,Content-Type, Content-Length

xpack.security.authc.api\_key.enabled: true  
xpack.security.authc:  
anonymous:  
roles: superuser  
authz\_exception: true

I am new to SSL and how it should work, so maybe I am missing something  
please help

---

<div class="post-metadata">

### Author: ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)
#### Post date: [April 29, 2021, 1:08am UTC](https://discuss.elastic.co/t/connect-enterprise-search-to-elasticsearch-via-ssl/271466/4 "2021-04-29T01:08:51Z")

</div>

I wasn't saying that the SSL wasn't setup properly in elasticsearch, but SSL is based off of trust. I trust the issuer so I trust you. If the enterprise search server isn't set to trust the certificates that are on the elasticsearch server then the requests will fail. The reason the curl commands are working is because you're using the `--insecure`, try without and you'll see the error I'm referring to.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 27, 2021, 1:09am UTC](https://discuss.elastic.co/t/connect-enterprise-search-to-elasticsearch-via-ssl/271466/5 "2021-05-27T01:09:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
