# Could not create SSL/TLS secure channel

**URL:** <https://discuss.elastic.co/t/could-not-create-ssl-tls-secure-channel/218668>\
**Category:** Elasticsearch\
**Created:** [February 10, 2020, 8:40pm UTC](https://discuss.elastic.co/t/could-not-create-ssl-tls-secure-channel/218668 "2020-02-10T20:40:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![steevegldev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steevegldev/32/62222_2.png) [@steevegldev](https://discuss.elastic.co/u/steevegldev)\
**Post date:** [February 10, 2020, 8:40pm UTC](https://discuss.elastic.co/t/could-not-create-ssl-tls-secure-channel/218668/1 "2020-02-10T20:40:48Z")

</div>

I'm trying to post index by using ApiKey and .NET library, but I got an error.

```
Dim auth = New ApiKeyAuthenticationCredentials("ApiKeyID", "ApiKey" )
Dim settings = New ConnectionConfiguration("CloudID", auth)
Dim client = New ElasticLowLevelClient(settings)
esResponse = client.Index(Of BytesResponse)(AxesConfig.Current.ElasticsearchIndexTransaction + "-" + NoSit, "1", PostData.Serializable(jObj))

```

Return

```
Unsuccessful () low level call on PUT: /transaction-00116/_doc/1
# Audit trail of this API call:
 - [1] BadResponse: Node: https://***.eastus2.azure.elastic-cloud.com:9243/ Took: 00:00:00.8145147
# OriginalException: Elasticsearch.Net.ElasticsearchClientException: The request was aborted: Could not create SSL/TLS secure channel.. Call: Status code unknown from: PUT /transaction-00116/_doc/1 ---> System.Net.WebException: The request was aborted: Could not create SSL/TLS secure channel.
   at System.Net.HttpWebRequest.GetResponse()
   at Elasticsearch.Net.HttpWebRequestConnection.Request[TResponse](RequestData requestData)
   --- End of inner exception stack trace ---
# Request:
<Request stream not captured or already read to completion by serializer. Set DisableDirectStreaming() on ConnectionSettings to force it to be set on the response.>
# Response:

```

Any ideal?

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [February 11, 2020, 2:01am UTC](https://discuss.elastic.co/t/could-not-create-ssl-tls-secure-channel/218668/2 "2020-02-11T02:01:35Z")

</div>

> [@steevegldev](#):
>
> Could not create SSL/TLS secure channel.

This indicates a problem with establishing a HTTPS connection. Based on the stacktrace provided, it looks like you're targeting an older version .NET Framework that uses the older `System.Net.HttpWebRequest` type for HTTP.

My _suspicion_ is that the version of .NET Framework is not configured to support the version of TLS that Elasticsearch Service on Cloud is using; If I recall correctly, the service uses TLS 1.2, which [**older .NET Framework versions** may not be configured by default to support](https://docs.microsoft.com/en-us/dotnet/framework/network-programming/tls).

A couple of different options that I would recommend

1. Update to a newer .NET Framework version that supports TLS 1.2 by default

2. Configure [`ServicePointManager.SecurityProtocol`](https://docs.microsoft.com/en-us/dotnet/api/system.net.servicepointmanager.securityprotocol?view=netframework-4.8#System_Net_ServicePointManager_SecurityProtocol) to use TLS 1.2. If patches have been applied that default the OS to use TLS 1.2, then setting `ServicePointManager.SecurityProtocol` to `SecurityProtocolType.SystemDefault` will work. Otherwise, it can be set to `SecurityProtocolType.Tls12` or the int value `3072`

---

<div class="post-metadata">

**Author:** ![steevegldev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steevegldev/32/62222_2.png) [@steevegldev](https://discuss.elastic.co/u/steevegldev)\
**Post date:** [February 11, 2020, 4:47pm UTC](https://discuss.elastic.co/t/could-not-create-ssl-tls-secure-channel/218668/3 "2020-02-11T16:47:32Z")

</div>

Thanks for that complete answer. I'm still trying to figure out how to force the TLS version in [VB.NET](http://VB.NET) 4.6.1.

But the question I have is why APM work without issue?

---

<div class="post-metadata">

**Author:** ![steevegldev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steevegldev/32/62222_2.png) [@steevegldev](https://discuss.elastic.co/u/steevegldev)\
**Post date:** [February 11, 2020, 9:17pm UTC](https://discuss.elastic.co/t/could-not-create-ssl-tls-secure-channel/218668/4 "2020-02-11T21:17:16Z")

</div>

I fixed it with `ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12` just before `client.Index`

I don't know if it's the best solution, but it's working.

I tried the following without succeed:

```auto
  <runtime>
    <AppContextSwitchOverrides value="Switch.System.Net.DontEnableSystemDefaultTlsVersions=false"/>
  </runtime>

```

Thanks

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [February 12, 2020, 12:33am UTC](https://discuss.elastic.co/t/could-not-create-ssl-tls-secure-channel/218668/5 "2020-02-12T00:33:07Z")

</div>

> [@steevegldev](#):
>
> I fixed it with `ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12` just before `client.Index`

Happy it works for you! Note, you only need to call this once for the lifetime of the application and before any call is made, so somewhere in application startup is best.

> [@steevegldev](#):
>
> But the question I have is why APM work without issue?

I think it may be because all of .NET APM agent's HTTP calls are based on `System.Net.Http.HttpClient` and not `System.Net.HttpWebRequest`.

> [@steevegldev](#):
>
> I tried the following without succeed:
> 
> ```auto
> <runtime>
> <AppContextSwitchOverrides value="Switch.System.Net.DontEnableSystemDefaultTlsVersions=false"/>
> </runtime>
> 
> ```

This implies to me that the OS may not be patched to support TLS 1.2 by default. You can check the Windows registry for [`SystemDefaultTlsVersions`](https://docs.microsoft.com/en-us/dotnet/framework/network-programming/tls#systemdefaulttlsversions).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 11, 2020, 12:33am UTC](https://discuss.elastic.co/t/could-not-create-ssl-tls-secure-channel/218668/6 "2020-03-11T00:33:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
