# Creation/error of a x.509 certificate

**URL:** <https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 21, 2022, 1:07pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201 "2022-10-21T13:07:26Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![EExisT](https://avatars.discourse-cdn.com/v4/letter/e/35a633/32.png) [@EExisT](https://discuss.elastic.co/u/EExisT)\
**Post date:** [October 21, 2022, 1:07pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/1 "2022-10-21T13:07:26Z")

</div>

Hello,

I'm trying to produce x.509 crt and key for 4 instances that I have saved in a .yml file(Elastic, Kibana, Winlogbeat and Metricbeat)

I was trying to ro run the command `/usr/share/elasticsearch/bin/elasticsearch-certutil cert --ca --pem --in instances.yml --out certs.zip` to produce a ca.crt for the authority and a .crt and a .key for each instance.

When I try to run this command and the system prompt to me to insert a pwd for the ca I receive the error:

```auto
Exception in thread "main" java.nio.file.NoSuchFileException: --pem
	at java.base/sun.nio.fs.UnixException.translateToIOException(UnixException.java:92)
	at java.base/sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:106)
	at java.base/sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:111)
	at java.base/sun.nio.fs.UnixFileSystemProvider.newByteChannel(UnixFileSystemProvider.java:218)
	at java.base/java.nio.file.Files.newByteChannel(Files.java:380)
	at java.base/java.nio.file.Files.newByteChannel(Files.java:432)
	at java.base/java.nio.file.spi.FileSystemProvider.newInputStream(FileSystemProvider.java:422)
	at java.base/java.nio.file.Files.newInputStream(Files.java:160)
	at org.elasticsearch.common.ssl.KeyStoreUtil.readKeyStore(KeyStoreUtil.java:71)
	at org.elasticsearch.xpack.core.ssl.CertParsingUtils.readKeyPairsFromKeystore(CertParsingUtils.java:105)
	at org.elasticsearch.xpack.core.ssl.CertParsingUtils.readPkcs12KeyPairs(CertParsingUtils.java:96)
	at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.lambda$loadPkcs12CA$1(CertificateTool.java:366)
	at org.elasticsearch.xpack.security.cli.CertificateTool.withPassword(CertificateTool.java:1027)
	at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.loadPkcs12CA(CertificateTool.java:361)
	at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.getCAInfo(CertificateTool.java:347)
	at org.elasticsearch.xpack.security.cli.CertificateTool$GenerateCertificateCommand.getCAInfo(CertificateTool.java:759)
	at org.elasticsearch.xpack.security.cli.CertificateTool$GenerateCertificateCommand.execute(CertificateTool.java:701)
	at org.elasticsearch.common.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:54)
	at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:85)
	at org.elasticsearch.cli.MultiCommand.execute(MultiCommand.java:94)
	at org.elasticsearch.xpack.security.cli.CertificateTool.execute(CertificateTool.java:160)
	at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:85)
	at org.elasticsearch.cli.Command.main(Command.java:50)
	at org.elasticsearch.launcher.CliToolLauncher.main(CliToolLauncher.java:64)

```

I tried to modify the command but it doesn't work.

Could u help me?  
Thank u

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 21, 2022, 2:28pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/2 "2022-10-21T14:28:24Z")

</div>

Hi @EExisT  
The Command is expecting the path to the CA file that you should have created in your first step

`bin/elasticsearch-certutil ca`

That would create the CA which you would pass in on the next command that you're trying to run

> --ca \<file\_path\>  
> Specifies the path to an existing CA key pair (in PKCS#12 format). This parameter cannot be used with the ca or csr parameters.

You're not providing a file, so the next option is it's looking at the dash `--pem` thinking it's a file Just as the error suggests

---

<div class="post-metadata">

**Author:** ![EExisT](https://avatars.discourse-cdn.com/v4/letter/e/35a633/32.png) [@EExisT](https://discuss.elastic.co/u/EExisT)\
**Post date:** [October 21, 2022, 2:41pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/3 "2022-10-21T14:41:20Z")

</div>

Hi @stephenb,

when I try to pass the path of the CA I receive the following error:

Command

```auto
/usr/share/elasticsearch/bin/elasticsearch-certutil cert --ca ./ca.crt --pem --in instances.yml --out certs.zip

```

Error

```auto
Exception in thread "main" java.nio.file.NoSuchFileException: ca.key
	at java.base/sun.nio.fs.UnixException.translateToIOException(UnixException.java:92)
	at java.base/sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:106)
	at java.base/sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:111)
	at java.base/sun.nio.fs.UnixFileSystemProvider.newByteChannel(UnixFileSystemProvider.java:218)
	at java.base/java.nio.file.Files.newByteChannel(Files.java:380)
	at java.base/java.nio.file.Files.newByteChannel(Files.java:432)
	at java.base/java.nio.file.spi.FileSystemProvider.newInputStream(FileSystemProvider.java:422)
	at java.base/java.nio.file.Files.newInputStream(Files.java:160)
	at org.elasticsearch.common.ssl.KeyStoreUtil.readKeyStore(KeyStoreUtil.java:71)
	at org.elasticsearch.xpack.core.ssl.CertParsingUtils.readKeyPairsFromKeystore(CertParsingUtils.java:105)
	at org.elasticsearch.xpack.core.ssl.CertParsingUtils.readPkcs12KeyPairs(CertParsingUtils.java:96)
	at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.lambda$loadPkcs12CA$1(CertificateTool.java:366)
	at org.elasticsearch.xpack.security.cli.CertificateTool.withPassword(CertificateTool.java:1027)
	at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.loadPkcs12CA(CertificateTool.java:361)
	at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.getCAInfo(CertificateTool.java:347)
	at org.elasticsearch.xpack.security.cli.CertificateTool$GenerateCertificateCommand.getCAInfo(CertificateTool.java:759)
	at org.elasticsearch.xpack.security.cli.CertificateTool$GenerateCertificateCommand.execute(CertificateTool.java:701)
	at org.elasticsearch.common.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:54)
	at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:85)
	at org.elasticsearch.cli.MultiCommand.execute(MultiCommand.java:94)
	at org.elasticsearch.xpack.security.cli.CertificateTool.execute(CertificateTool.java:160)
	at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:85)
	at org.elasticsearch.cli.Command.main(Command.java:50)
	at org.elasticsearch.launcher.CliToolLauncher.main(CliToolLauncher.java:64)

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 21, 2022, 2:52pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/4 "2022-10-21T14:52:04Z")

</div>

Please share the command you used to create the CA... if you did .pem style you have to provide the private key as well and use this format as shown in the [docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/certutil.html#certutil)

(cert ([--ca \<file\_path\>] | **[--ca-cert \<file\_path\> --ca-key \<file\_path\>]**

The Flow for creating certs is

Create a CA  
Then use that CA to generate certificates.

---

<div class="post-metadata">

**Author:** ![EExisT](https://avatars.discourse-cdn.com/v4/letter/e/35a633/32.png) [@EExisT](https://discuss.elastic.co/u/EExisT)\
**Post date:** [October 21, 2022, 3:00pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/5 "2022-10-21T15:00:21Z")

</div>

I gave the following command:

```auto
/usr/share/elasticsearch/bin/elasticsearch-certutil cert --ca ./ca.crt --pem --in instances.yml --out certs.zip

```

So, I must give now also the .key path.  
I will give this command:

```auto
/usr/share/elasticsearch/bin/elasticsearch-certutil cert --ca-cert ./ca.crt --ca-key ./ca.key --pem --in instances.yml --out certs.zip

```

Is it right?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 21, 2022, 4:11pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/6 "2022-10-21T16:11:42Z")

</div>

Please show the command you used to generate the CA it would look like but yes perhaps... I don't know because you did not show me the command that create

There are 2 steps to generate certs see [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup.html#generate-certificates)

Step1 : Create a CA (need to show me this or Perhaps you did not run that)  
Step2 : Use The CA to create the certs, this seem to be what you are trying to do.

We can help much better if you show all your steps...

---

<div class="post-metadata">

**Author:** ![EExisT](https://avatars.discourse-cdn.com/v4/letter/e/35a633/32.png) [@EExisT](https://discuss.elastic.co/u/EExisT)\
**Post date:** [October 21, 2022, 4:30pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/7 "2022-10-21T16:30:23Z")

</div>

Sorry @stephenb I misunderstood.

To produce the CA I gave this

```auto
/usr/share/elasticsearch/bin/elasticsearch-certutil ca --pem 

```

This produce a zip that I unzipped and that I quote above.  
Thank u:)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 21, 2022, 4:37pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/8 "2022-10-21T16:37:29Z")

</div>

So yes use

`/usr/share/elasticsearch/bin/elasticsearch-certutil cert --ca-cert ./ca.crt --ca-key ./ca.key --pem --in instances.yml --out certs.zip`

assuming all the paths are correct.

when you create .pem there are always to parts the cert and the key

---

<div class="post-metadata">

**Author:** ![EExisT](https://avatars.discourse-cdn.com/v4/letter/e/35a633/32.png) [@EExisT](https://discuss.elastic.co/u/EExisT)\
**Post date:** [October 21, 2022, 5:45pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/9 "2022-10-21T17:45:12Z")

</div>

So now I gave the command `/usr/share/elasticsearch/bin/elasticsearch-certutil cert --ca-cert ./ca.crt --ca-key ./ca.key --pem --in instances.yml --out certs.zip`, being in the CA directory, where the are both ca files(crt and key) but I get this...

```auto
Exception in thread "main" java.nio.file.NoSuchFileException: ca.crt
	at java.base/sun.nio.fs.UnixException.translateToIOException(UnixException.java:92)
	at java.base/sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:106)
	at java.base/sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:111)
	at java.base/sun.nio.fs.UnixFileSystemProvider.newByteChannel(UnixFileSystemProvider.java:218)
	at java.base/java.nio.file.Files.newByteChannel(Files.java:380)
	at java.base/java.nio.file.Files.newByteChannel(Files.java:432)
	at java.base/java.nio.file.spi.FileSystemProvider.newInputStream(FileSystemProvider.java:422)
	at java.base/java.nio.file.Files.newInputStream(Files.java:160)
	at org.elasticsearch.common.ssl.PemUtils.readCertificates(PemUtils.java:689)
	at org.elasticsearch.xpack.core.ssl.CertParsingUtils.readX509Certificate(CertParsingUtils.java:53)
	at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.loadPemCA(CertificateTool.java:386)
	at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.getCAInfo(CertificateTool.java:349)
	at org.elasticsearch.xpack.security.cli.CertificateTool$GenerateCertificateCommand.getCAInfo(CertificateTool.java:759)
	at org.elasticsearch.xpack.security.cli.CertificateTool$GenerateCertificateCommand.execute(CertificateTool.java:701)
	at org.elasticsearch.common.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:54)
	at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:85)
	at org.elasticsearch.cli.MultiCommand.execute(MultiCommand.java:94)
	at org.elasticsearch.xpack.security.cli.CertificateTool.execute(CertificateTool.java:160)
	at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:85)
	at org.elasticsearch.cli.Command.main(Command.java:50)
	at org.elasticsearch.launcher.CliToolLauncher.main(CliToolLauncher.java:64)

```

that it seems to be the same previous one error

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 21, 2022, 5:58pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/10 "2022-10-21T17:58:39Z")

</div>

> [@EExisT](#):
>
> `Exception in thread "main" java.nio.file.NoSuchFileException: ca.crt`

It's says it can't find the files .... where are the files, provide full paths to the files

`/usr/share/elasticsearch/bin/elasticsearch-certutil cert --ca-cert /full/path/to/file/ca.crt --ca-key /full/path/to/file/ca.key --pem --in /full/path/to/file/instances.yml --out /full/path/to/file/certs.zip`,

Try running from

```auto
cd /usr/share/elasticsearch
./bin/elasticsearch-certutil cert --ca-cert ./ca.crt --ca-key ./ca.key --pem --in instances.yml --out certs.zip

```

or provide full path to the files or where ever you ran the command from before... this is just it can't find the files.

---

<div class="post-metadata">

**Author:** ![EExisT](https://avatars.discourse-cdn.com/v4/letter/e/35a633/32.png) [@EExisT](https://discuss.elastic.co/u/EExisT)\
**Post date:** [October 22, 2022, 12:38pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/11 "2022-10-22T12:38:29Z")

</div>

Hi @stephenb

```auto
/usr/share/elasticsearch/bin/elasticsearch-certutil cert --ca-cert ./usr/share/elasticsearch/ca/ca.crt --ca-key ./usr/share/elasticsearch/ca/ca.key --pem --in instances.yml --out certs2.zip

```

This is the command with the full path of the ca.

```auto
Exception in thread "main" java.nio.file.NoSuchFileException: usr/share/elasticsearch/ca/ca.crt
	at java.base/sun.nio.fs.UnixException.translateToIOException(UnixException.java:92)
	at java.base/sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:106)
	at java.base/sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:111)
	at java.base/sun.nio.fs.UnixFileSystemProvider.newByteChannel(UnixFileSystemProvider.java:218)
	at java.base/java.nio.file.Files.newByteChannel(Files.java:380)
	at java.base/java.nio.file.Files.newByteChannel(Files.java:432)
	at java.base/java.nio.file.spi.FileSystemProvider.newInputStream(FileSystemProvider.java:422)
	at java.base/java.nio.file.Files.newInputStream(Files.java:160)
	at org.elasticsearch.common.ssl.PemUtils.readCertificates(PemUtils.java:689)
	at org.elasticsearch.xpack.core.ssl.CertParsingUtils.readX509Certificate(CertParsingUtils.java:53)
	at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.loadPemCA(CertificateTool.java:386)
	at org.elasticsearch.xpack.security.cli.CertificateTool$CertificateCommand.getCAInfo(CertificateTool.java:349)
	at org.elasticsearch.xpack.security.cli.CertificateTool$GenerateCertificateCommand.getCAInfo(CertificateTool.java:759)
	at org.elasticsearch.xpack.security.cli.CertificateTool$GenerateCertificateCommand.execute(CertificateTool.java:701)
	at org.elasticsearch.common.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:54)
	at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:85)
	at org.elasticsearch.cli.MultiCommand.execute(MultiCommand.java:94)
	at org.elasticsearch.xpack.security.cli.CertificateTool.execute(CertificateTool.java:160)
	at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:85)
	at org.elasticsearch.cli.Command.main(Command.java:50)
	at org.elasticsearch.launcher.CliToolLauncher.main(CliToolLauncher.java:64)

```

How can you see the path is correct.

```auto
root@ubuntu-linux-22-04-desktop:/usr/share/elasticsearch/ca# pwd
/usr/share/elasticsearch/ca
root@ubuntu-linux-22-04-desktop:/usr/share/elasticsearch/ca# ls -l
totale 8
-rw-r--r-- 1 root root 1200 ott 21 16:32 ca.crt
-rw-r--r-- 1 root root 1679 ott 21 16:32 ca.key

```

---

<div class="post-metadata">

**Author:** ![EExisT](https://avatars.discourse-cdn.com/v4/letter/e/35a633/32.png) [@EExisT](https://discuss.elastic.co/u/EExisT)\
**Post date:** [October 22, 2022, 1:35pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/12 "2022-10-22T13:35:43Z")

</div>

It WORKS!

I gave all full path for the ca.crt, ca.key, input e outfit files and it produced the certificates...I don't know why cause the files were all in the path where I was placed...however thanks for the support @stephenb

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2022, 1:35pm UTC](https://discuss.elastic.co/t/creation-error-of-a-x-509-certificate/317201/13 "2022-11-19T13:35:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
