# ECE - Certificate chain was invalid

**URL:** <https://discuss.elastic.co/t/ece-certificate-chain-was-invalid/217125>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Created:** [January 30, 2020, 8:21am UTC](https://discuss.elastic.co/t/ece-certificate-chain-was-invalid/217125 "2020-01-30T08:21:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ntran](https://avatars.discourse-cdn.com/v4/letter/n/73ab20/32.png) [@ntran](https://discuss.elastic.co/u/ntran)\
**Post date:** [January 30, 2020, 8:21am UTC](https://discuss.elastic.co/t/ece-certificate-chain-was-invalid/217125/1 "2020-01-30T08:21:39Z")

</div>

Hi all,

I am getting this error message when uploading my proxy certificate into ECE:  
`Certificate chain was invalid [Invalid Entry: expected X.509 Certificate`  
As I don't have certificates, I am unable to log into Kibana and Elasticsearch.

I am using openssl to generate a self signed certificate which has multiple wildcard common names.

1. Created ssl.conf file with the default common name + alt names
2. openssl genrsa -out private.key 4096
3. openssl req -new -sha256 -out private.csr -key private.key -config ssl.conf
4. openssl x509 -signkey private.key -in private.csr -req -days 365 -out private.crt

ssl.conf file

> [req]  
> default\_bits = 4096  
> distinguished\_name = req\_distinguished\_name  
> req\_extensions = req\_ext  
> [req\_distinguished\_name]  
> countryName = AE  
> countryName\_default = AE  
> stateOrProvinceName = Dubai  
> stateOrProvinceName\_default = Dubai  
> localityName = Dubai  
> localityName\_default = Dubai  
> organizationName = CompanyName  
> organizationName\_default = CompanyName  
> commonName = \*.text.example.com  
> commonName\_max = 64  
> commonName\_default = \*.text.example.com  
> [req\_ext]  
> subjectAltName = @alt\_names  
> [alt\_names]  
> DNS.1 = \*.text.example.com  
> DNS.2 = \*.text1.example.com  
> DNS.3 = \*.text2.example.com

Any help is greatly appreciated.  
Thank you,  
Nhung

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [January 30, 2020, 3:30pm UTC](https://discuss.elastic.co/t/ece-certificate-chain-was-invalid/217125/2 "2020-01-30T15:30:52Z")

</div>

Are the suggestions in this topic of any use?

> [@ECE 2.0.1 Unable to upload Letsencrypt TLS certificate](https://discuss.elastic.co/t/ece-2-0-1-unable-to-upload-letsencrypt-tls-certificate/158802/4):
>
> Despite its name, I'm not convinced fullchain.pem includes the CA cert, can you double check? If not, try converting/cating that in Otherwise you should be able to use openssl to verify the combined PEM is valid (or if not, what's wrong with it), eg: Let's assume the following values are set: SRV\_KEY=[path to server RSA key] SRV\_CERT=[path to server X509 cert] INTER\_CERT=[path to intermediate CA X509 cert] CA\_CERT=[path to CA X509 cert] CHAIN=[path to certificate chain, eg cat $SRV\_KEY $SRV\_C…

---

<div class="post-metadata">

**Author:** ![ntran](https://avatars.discourse-cdn.com/v4/letter/n/73ab20/32.png) [@ntran](https://discuss.elastic.co/u/ntran)\
**Post date:** [February 1, 2020, 3:53pm UTC](https://discuss.elastic.co/t/ece-certificate-chain-was-invalid/217125/3 "2020-02-01T15:53:18Z")

</div>

Hi @Alex_Piggott,

Thanks for this! It was helpful.

When i run, `openssl x509 -subject -issuer -noout -in /etc/ece/private.csr`, I get the following:

```
unable to load certificate
140619479984016:error:0906D06C:PEM routines:PEM_read_bio:no start line:pem_lib.c:707:Expecting: TRUSTED CERTIFICATE

```

Also, when I run,  
`openssl x509 -noout -modulus -in /etc/ece/private.crt | openssl sha256` and `openssl rsa -noout -modulus -in /etc/ece/private.key| openssl sha256`, I get two different outputs - indicating a key mismatch.

I was wondering in the steps I did, where did I go wrong? I used the private key generated to create the subsequent certificates. If I were to create new certificates, will this override the old ones? How can I ensure when I generate the new certificates, it will be fine?

Thanks,  
Nhung

---

<div class="post-metadata">

**Author:** ![Rob\_wylde](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rob_wylde/32/58231_2.png) [@Rob\_wylde](https://discuss.elastic.co/u/Rob_wylde)\
**Post date:** [February 3, 2020, 4:41pm UTC](https://discuss.elastic.co/t/ece-certificate-chain-was-invalid/217125/4 "2020-02-03T16:41:42Z")

</div>

I got pretty frustrated with this process myself and opt'd to just put nginx in front of ECE essentially terminating my SSL certs and proxying connection into ECE.

Now i have a lets encrypt wildcard being terminated by nginx and continue to use the self signed ECE provided certs.

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [February 3, 2020, 7:50pm UTC](https://discuss.elastic.co/t/ece-certificate-chain-was-invalid/217125/5 "2020-02-03T19:50:15Z")

</div>

From your OP, it looks like you your steps are slightly different to out steps here: [Manage security certificates | Elastic Cloud Enterprise Reference [3.6] | Elastic](https://www.elastic.co/guide/en/cloud-enterprise/current/ece-manage-certificates.html#ece-tls-generate)

> 1. Generate a certificate authority (CA) RSA key pair.
> 2. Create a self-signed CA certificate.
> 3. Generate a server RSA key pair.
> 4. Create a certificate signing request (CSR) for server certificate with the common name and the alternative name set.
> 5. Sign the server CSR with CA key pair.
> 6. Concatenate the PEM encode server RSA private key, the server certificate, and the CA certificate into a single file.

Vs your:

> 1. Created ssl.conf file with the default common name + alt names
> 2. openssl genrsa -out private.key 4096
> 3. openssl req -new -sha256 -out private.csr -key private.key -config ssl.conf
> 4. openssl x509 -signkey private.key -in private.csr -req -days 365 -out private.crt

Your steps 2 and 3 are our steps 3 and 4, and then you sign the CSR with the key from your step 2 (not the CA cert from our steps 1/2)?

The alternative suggestion of using `nginx` or `haproxy` can also work well (since you need a load balancer anyway, so might as well use a tool that also is designed to handle the horrors of SSL certificate more robustly!)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2020, 7:50pm UTC](https://discuss.elastic.co/t/ece-certificate-chain-was-invalid/217125/6 "2020-02-17T19:50:25Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
