# Cross Cluster Search on ECK - how to set ca cert

**URL:** <https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [October 3, 2019, 8:24am UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113 "2019-10-03T08:24:26Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![iremmats](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iremmats/32/55316_2.png) [@iremmats](https://discuss.elastic.co/u/iremmats)\
**Post date:** [October 3, 2019, 8:24am UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/1 "2019-10-03T08:24:26Z")

</div>

Hi,

So we are playing around with ECK on multiple clusters in different region. We want to establish cross cluster search from one central cluster.

How can we set the ca-cert for our clusters during creation?  
We followed the instructions here to set the http certificate but how do we set the CA cert?

[https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-custom-http-certificate.html](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-custom-http-certificate.html)

This is the error we get right now.  
{  
"error": {  
"root\_cause": [  
{  
"type": "transport\_exception",  
"reason": "handshake failed because connection reset"  
}  
],  
"type": "connect\_transport\_exception",  
"reason": "[100.102.0.8:9300] general node connection failure",  
"caused\_by": {  
"type": "transport\_exception",  
"reason": "handshake failed because connection reset"  
}  
},  
"status": 500  
}

---

<div class="post-metadata">

**Author:** ![glennslaven](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glennslaven/32/56068_2.png) [@glennslaven](https://discuss.elastic.co/u/glennslaven)\
**Post date:** [October 16, 2019, 11:54pm UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/2 "2019-10-16T23:54:04Z")

</div>

Did you ever get this resolved?

---

<div class="post-metadata">

**Author:** ![iremmats](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iremmats/32/55316_2.png) [@iremmats](https://discuss.elastic.co/u/iremmats)\
**Post date:** [October 17, 2019, 5:54am UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/3 "2019-10-17T05:54:38Z")

</div>

Hi,

We ended up creating new clusters with the same CA. Instructions here are pretty good. It works fine now.

> **[elastic/helm-charts](https://github.com/elastic/helm-charts/tree/master/elasticsearch/examples/security)**
>
> You know, for Kubernetes. Contribute to elastic/helm-charts development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![glennslaven](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glennslaven/32/56068_2.png) [@glennslaven](https://discuss.elastic.co/u/glennslaven)\
**Post date:** [October 17, 2019, 7:32pm UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/4 "2019-10-17T19:32:42Z")

</div>

So you're not using the operator any more?

---

<div class="post-metadata">

**Author:** ![iremmats](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iremmats/32/55316_2.png) [@iremmats](https://discuss.elastic.co/u/iremmats)\
**Post date:** [October 17, 2019, 8:21pm UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/5 "2019-10-17T20:21:12Z")

</div>

No, we gave up on it. I like the idea but its not fully there yet.

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [October 18, 2019, 8:24am UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/6 "2019-10-18T08:24:13Z")

</div>

Sorry for the late reply.

To configure additional CA certificates you can just use the `xpack.security.transport.ssl.certificate_authorities` key as described in the [Elasticsearch documentation,](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/configuring-tls.html#tls-transport) there is nothing ECK specific here to keep in mind other than mounting the CA certificates into the pod.

An example Elasticsearch manifest for ECK could then look like this:

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1beta1
kind: Elasticsearch
metadata:
  name: cluster-one
spec:
  version: 7.4.0
  nodeSets:
  - name: default
    count: 1
    config:
      xpack.security.transport.ssl.certificate_authorities:
      - /usr/share/elasticsearch/config/remote/ca.crt
    podTemplate:
      spec:
        containers:
        - name: elasticsearch
          volumeMounts:
          - name: remote-certs
            mountPath: /usr/share/elasticsearch/config/remote
        volumes:
        - name: remote-certs
          secret:
            secretName: cluster-two-es-transport-certs-public

```

This assumes that a secret called `cluster-two-es-transport-certs-public` exists containing the CA certs of the other cluster you want to connect to. You will also have to configure the CA of this cluster on the other side to establish mutual trust.

---

<div class="post-metadata">

**Author:** ![iremmats](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iremmats/32/55316_2.png) [@iremmats](https://discuss.elastic.co/u/iremmats)\
**Post date:** [October 18, 2019, 9:01am UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/7 "2019-10-18T09:01:48Z")

</div>

Thanks!  
Put that into the documentation too and next time I have some spare time I will implement that. 🙂

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [October 18, 2019, 5:53pm UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/8 "2019-10-18T17:53:14Z")

</div>

It is maybe worth pointing out (for others reading this) that setting up the CAs is in itself not sufficient to configure remote clusters across different regions/k8s clusters. You also would have to make sure that all nodes in the remote cluster are reachable from the other cluster eg. via some form of router (all depending on your setup so hard to make a specific recommendation)

---

<div class="post-metadata">

**Author:** ![iremmats](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iremmats/32/55316_2.png) [@iremmats](https://discuss.elastic.co/u/iremmats)\
**Post date:** [October 20, 2019, 6:39pm UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/9 "2019-10-20T18:39:05Z")

</div>

We had to dig deep to find the proxy setting for cross cluster search to work with Kubernetes.

cluster.remote.euwest1.proxy: "k8s-node-ip:32500"  
cluster.remote.euwest1.seeds: "elastic-master.logging:9300"  
cluster.remote.euwest1.skip\_unavailable: true

We still have the issue of having to specify one Kubernetes node as proxy. Haven't gotten any working TCP load balancing. Amazon is our cloud right now.

---

<div class="post-metadata">

**Author:** ![glennslaven](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glennslaven/32/56068_2.png) [@glennslaven](https://discuss.elastic.co/u/glennslaven)\
**Post date:** [October 20, 2019, 10:38pm UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/10 "2019-10-20T22:38:04Z")

</div>

So I've got the CA cert now being used by both clusters with the  
`xpack.security.transport.ssl.certificate_authorities` config value.

However I'm still getting `org.elasticsearch.transport.TransportException: handshake failed because connection reset` as an error when trying to connect to the remote cluster.

I've just taken the CA cert from the remote cluster's secret and put it in the `certificate_authorities` for the other cluster.

---

<div class="post-metadata">

**Author:** ![glennslaven](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glennslaven/32/56068_2.png) [@glennslaven](https://discuss.elastic.co/u/glennslaven)\
**Post date:** [October 20, 2019, 11:57pm UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/11 "2019-10-20T23:57:19Z")

</div>

Over on the remote cluster when the error occurs I see this error in the ES logs:

```
PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
```

---

<div class="post-metadata">

**Author:** ![iremmats](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iremmats/32/55316_2.png) [@iremmats](https://discuss.elastic.co/u/iremmats)\
**Post date:** [October 21, 2019, 6:03am UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/12 "2019-10-21T06:03:57Z")

</div>

How is the config for the two clusters? Somehow you messed up the certificates or the proxy thingy. Running in Kubernetes or on vms?

---

<div class="post-metadata">

**Author:** ![glennslaven](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glennslaven/32/56068_2.png) [@glennslaven](https://discuss.elastic.co/u/glennslaven)\
**Post date:** [October 21, 2019, 9:10am UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/13 "2019-10-21T09:10:48Z")

</div>

Ok, I got it figured out.

It was my mistake in mis-reading the docs. I thought it was only the querying cluster that needed the CA cert of the remote cluster added, but you need the CA of each added to the other.

@iremmats, thank you for the `proxy` hint, that bit me as well!

---

<div class="post-metadata">

**Author:** ![glennslaven](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glennslaven/32/56068_2.png) [@glennslaven](https://discuss.elastic.co/u/glennslaven)\
**Post date:** [October 21, 2019, 9:11am UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/14 "2019-10-21T09:11:55Z")

</div>

Is there a way to "prime" the cluster with a pre-generated CA cert for transport, so that when the cluster comes up it uses a well-known CA to generate the cert secrets so I don't need to look it up after the cluster starts?

---

<div class="post-metadata">

**Author:** ![eedugon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eedugon/32/45404_2.png) [@eedugon](https://discuss.elastic.co/u/eedugon)\
**Post date:** [October 23, 2019, 8:48am UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/15 "2019-10-23T08:48:50Z")

</div>

@glennslaven, for **transport** protocol we don't support user configured certificates. At least not at the moment with 1.0.

But even for **HTTP** , there's no way to put just **only** the CA (and key) and make the operator to sign the certificates with that CA. If custom certificates are used (for http) we expect the users to give all three: CA, cert and private key.

---

<div class="post-metadata">

**Author:** ![frankdirosaiv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankdirosaiv/32/56647_2.png) [@frankdirosaiv](https://discuss.elastic.co/u/frankdirosaiv)\
**Post date:** [October 25, 2019, 6:48pm UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/16 "2019-10-25T18:48:57Z")

</div>

@pebrc can you elaborate on the router you are talking about?

I am attempting cross cluster replication where my leader exposes a k8s LB service on port 9300. However, I still cannot connect.

```auto
unexpected remote node {leader-es-default-1}

```

Scaling down Leader to 1 node will allow follower to connect to leader, but then I get the following error when I try to replicate an index.

```auto
No route to host: <leader cluster IP>/<leader cluster ip>:9300",

```

---

<div class="post-metadata">

**Author:** ![zcthompson](https://avatars.discourse-cdn.com/v4/letter/z/278dde/32.png) [@zcthompson](https://discuss.elastic.co/u/zcthompson)\
**Post date:** [November 12, 2019, 9:40pm UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/17 "2019-11-12T21:40:53Z")

</div>

Is there any plans to have this by GA. We are looking at this for OpenShift and ECK without the ability to pass these to secrets to allow CCS and CCR seems like a deal breaker for many that don't use AWS, GCE, etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:27am UTC](https://discuss.elastic.co/t/cross-cluster-search-on-eck-how-to-set-ca-cert/202113/18 "2022-11-04T07:27:52Z")

</div>


