# cURL request not working with CA certificate on Windows

**URL:** <https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 13, 2022, 12:58pm UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566 "2022-03-13T12:58:32Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andy0708](https://avatars.discourse-cdn.com/v4/letter/a/df705f/32.png) [@Andy0708](https://discuss.elastic.co/u/Andy0708)\
**Post date:** [March 13, 2022, 12:58pm UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566/1 "2022-03-13T12:58:32Z")

</div>

Hi,

The following command works fine on macOS, but I am unable to get it to work on Windows 10.

`curl --cacert config\certs\http_ca.crt -u elastic https://localhost:9200`

This happens after starting up a fresh cluster on version 8.1.0 (extracted from the zip file).

The command fails with the following error.

```auto
C:\Users\myuser\Desktop\elasticsearch-8.1.0>curl --cacert config\certs\http_ca.crt -u elastic https://localhost:9200
curl: (60) schannel: CertGetCertificateChain trust error CERT_TRUST_REVOCATION_STATUS_UNKNOWN
More details here: https://curl.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the web page mentioned above.

```

Using either `--insecure` or `-k` works, but that is not the ideal approach.

I followed [the instructions within the documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/zip-windows.html#_check_that_elasticsearch_is_running_2), so I presume that this approach should work. I am not very proficient with TLS certificates, so perhaps I am missing something?

Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 13, 2022, 3:54pm UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566/2 "2022-03-13T15:54:08Z")

</div>

Take a look at this post there may be a typo in the docs.

Perhaps try this depending on where you're running the command from, but the service are not in the config directory. They're in the certs directory.

```auto
curl --cacert certs\http_ca.crt -u elastic https://localhost:9200

```

> [@Newbie to Linux/elastic. I'm having trouble setting up elasticsearch](https://discuss.elastic.co/t/newbie-to-linux-elastic-im-having-trouble-setting-up-elasticsearch/298687/15):
>
> @epheria , @elasticscrub it seems this is just a docs error in curl --cacert /etc/elasticsearch/config/certs/http\_ca.crt -u elastic https://localhost:9200 should be curl --cacert /etc/elasticsearch/certs/http\_ca.crt -u elastic https://localhost:9200 Apologies for missing this above. We will adjust the docs, thanks for bringing this up !

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 13, 2022, 4:37pm UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566/3 "2022-03-13T16:37:22Z")

</div>

The typo is about something else(deb/rpm installation instructions) it doesn’t apply in this case. Also, the docs have been already fixed by now !

@Andy0708 the problem here is that your windows installation has no internet connectivity and curl can’t look up CRLs . Try curl with `—ssl-no-revoke`

---

<div class="post-metadata">

**Author:** ![Andy0708](https://avatars.discourse-cdn.com/v4/letter/a/df705f/32.png) [@Andy0708](https://discuss.elastic.co/u/Andy0708)\
**Post date:** [March 13, 2022, 5:15pm UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566/4 "2022-03-13T17:15:11Z")

</div>

@stephenb Thanks! The path is actually correct when using a zip file setup. 🙂

@ikakavas Hmm, I tried both on a separate physical Windows machine (and got the above error) and on a Parallels VM (on Mac). The latter gives me the following error.

```auto
curl: (77) schannel: next InitializeSecurityContext failed: SEC_E_UNTRUSTED_ROOT (0x80090325) - The certificate chain was issued by an authority that is not trusted.

```

Both have Internet access in general (including through curl). I also tried disabling the Windows firewall, but it made no difference.

I couldn't find any trace of that option anywhere (including in the man page). Maybe it has been replace by `--insecure` and `-k`? Otherwise I must be missing something. 🙂

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 13, 2022, 5:38pm UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566/5 "2022-03-13T17:38:32Z")

</div>

I thought this was a windows curl option 😕 maybe I’m mistaken. Can you try `--ssl-revoke-best-effort`? this should be available in recent curl versions

---

<div class="post-metadata">

**Author:** ![Andy0708](https://avatars.discourse-cdn.com/v4/letter/a/df705f/32.png) [@Andy0708](https://discuss.elastic.co/u/Andy0708)\
**Post date:** [March 13, 2022, 5:58pm UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566/6 "2022-03-13T17:58:08Z")

</div>

Turns out `ssl-no-revoke` was there after all. Sorry, my bad. Using it does produce the error in my previous post, though.

Anyway, I am not actually going to use Elasticsearch on Windows since I am a Mac user. I am just producing some YouTube content and wanted to cover Windows as well. So if the command should work in general and this is somehow related to my particular setup, I am fine with leaving it at that. 😉

---

<div class="post-metadata">

**Author:** ![Obinna\_Igwe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/obinna_igwe/32/103315_2.png) [@Obinna\_Igwe](https://discuss.elastic.co/u/Obinna_Igwe)\
**Post date:** [March 21, 2022, 4:52pm UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566/7 "2022-03-21T16:52:40Z")

</div>

Some of us actually need this to work on Windows.

I tried this on Mac and it worked perfectly. But when I tried it on Windows, I got the following errors:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b9c9d3bcf7a4c3d15cbfb7db012146efbf7ce7b3.png)

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 21, 2022, 9:41pm UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566/8 "2022-03-21T21:41:57Z")

</div>

Please don't paste screenshots of text.

They are not searchable, they are not accessible by vision impaired readers, they are hard to read on mobile devices and ultimately they make it far less likely that anyone will be able to provide you with the assistance you are after.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 21, 2022, 10:07pm UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566/9 "2022-03-21T22:07:30Z")

</div>

It looks like your first attempt connected correctly and you just entered the incorrect password for the `elastic` user.  
Try it again, and double check the password.

---

<div class="post-metadata">

**Author:** ![dardar4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dardar4/32/96937_2.png) [@dardar4](https://discuss.elastic.co/u/dardar4)\
**Post date:** [March 31, 2022, 8:52am UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566/11 "2022-03-31T08:52:49Z")

</div>

Same problem here

curl --cacert config/certs/http\_ca.crt -X GET [https://localhost:9200](https://localhost:9200)  
returns the error:

curl: (60) schannel: CertGetCertificateChain trust error CERT\_TRUST\_REVOCATION\_STATUS\_UNKNOWN  
More details here: [curl - SSL CA Certificates](https://curl.se/docs/sslcerts.html)

curl failed to verify the legitimacy of the server and therefore could not  
establish a secure connection to it. To learn more about this situation and  
how to fix it, please visit the web page mentioned above.

if we use --insecure it ignores the problem and I can get a valid results

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2022, 8:52am UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566/12 "2022-04-28T08:52:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
