# Elastic 8.7\_\_enrollement-token\_\_"failed to establish trust with server "

**URL:** <https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856>\
**Category:** Kibana\
**Created:** [April 26, 2023, 2:25pm UTC](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856 "2023-04-26T14:25:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [April 26, 2023, 2:25pm UTC](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856/1 "2023-04-26T14:25:35Z")

</div>

Hi ,

I have a kibana server and an elastic server with differents IP address .

When I want to create a token for kibana with command :

` sudo bin/elasticsearch-create-enrollement-token -s kibana`

OR

`sudo bin/elasticsearch-create-enrollement-token -s kibana --url "https://@ELASTIC IP ADDRESS:9200`

I have an error : "Failed to establish trust with server at @ELASTIC IP ADDRESS"

I have a default config with `network.host : @ELASTIC IP ADDRESS` and http.port: 9200  
It's a new install

Any idea ?

Thanks

---

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [May 2, 2023, 11:51am UTC](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856/2 "2023-05-02T11:51:53Z")

</div>

Any idea ?

---

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [May 2, 2023, 12:55pm UTC](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856/3 "2023-05-02T12:55:13Z")

</div>

my log :

`sudo bin/elasticsearch-create-enrollment-token -s kibana`

```auto
> 14:45:55.875 [main] WARN org.elasticsearch.common.ssl.DiagnosticTrustManager - failed to establish trust with server at [192.168.200.141]; the server provided a certificate with subject name [CN=elastic], fingerprint [982d15d1bd187a3a62f19ff63cca807045bda55d], no keyUsage and extendedKeyUsage [serverAuth]; the certificate is valid between [2023-04-25T14:36:14Z] and [2025-04-24T14:36:14Z] (current time is [2023-05-02T12:45:55.872722204Z], certificate dates are valid); the session uses cipher suite [TLS_AES_256_GCM_SHA384] and protocol [TLSv1.3]; the certificate has subject alternative names [DNS:localhost,IP:127.0.0.1,IP:192.168.99.162,DNS:elastic]; the certificate is issued by [CN=Elasticsearch security auto-configuration HTTP CA]; the certificate is signed by (subject [CN=Elasticsearch security auto-configuration HTTP CA] fingerprint [0f92f1fc6d9c035d3aca7311b1c7febd113f0d5c] {trusted issuer}) which is self-issued; the [CN=Elasticsearch security auto-configuration HTTP CA] certificate is trusted in this ssl context ([xpack.security.http.ssl (with trust configuration: Composite-Trust{JDK-trusted-certs,StoreTrustConfig{path=/etc/elasticsearch/certs/http.p12, password=<non-empty>, type=PKCS12, algorithm=PKIX}})])
> java.security.cert.CertificateException: No subject alternative names matching IP address 192.168.200.141 found
> at sun.security.util.HostnameChecker.matchIP(HostnameChecker.java:164) ~[?:?]
> at sun.security.util.HostnameChecker.match(HostnameChecker.java:101) ~[?:?]
> at sun.security.ssl.X509TrustManagerImpl.checkIdentity(X509TrustManagerImpl.java:458) ~[?:?]
> at sun.security.ssl.X509TrustManagerImpl.checkIdentity(X509TrustManagerImpl.java:432) ~[?:?]
> at sun.security.ssl.X509TrustManagerImpl.checkTrusted(X509TrustManagerImpl.java:238) ~[?:?]
> at sun.security.ssl.X509TrustManagerImpl.checkServerTrusted(X509TrustManagerImpl.java:132) ~[?:?]
> at org.elasticsearch.common.ssl.DiagnosticTrustManager.checkServerTrusted(DiagnosticTrustManager.java:80) ~[?:?]
> at sun.security.ssl.CertificateMessage$T13CertificateConsumer.checkServerCerts(CertificateMessage.java:1335) ~[?:?]
> at sun.security.ssl.CertificateMessage$T13CertificateConsumer.onConsumeCertificate(CertificateMessage.java:1226) ~[?:?]
> at sun.security.ssl.CertificateMessage$T13CertificateConsumer.consume(CertificateMessage.java:1169) ~[?:?]
> at sun.security.ssl.SSLHandshake.consume(SSLHandshake.java:396) ~[?:?]
> at sun.security.ssl.HandshakeContext.dispatch(HandshakeContext.java:480) ~[?:?]
> at sun.security.ssl.HandshakeContext.dispatch(HandshakeContext.java:458) ~[?:?]
> at sun.security.ssl.TransportContext.dispatch(TransportContext.java:201) ~[?:?]
> at sun.security.ssl.SSLTransport.decode(SSLTransport.java:172) ~[?:?]
> at sun.security.ssl.SSLSocketImpl.decode(SSLSocketImpl.java:1510) ~[?:?]
> at sun.security.ssl.SSLSocketImpl.readHandshakeRecord(SSLSocketImpl.java:1425) ~[?:?]
> at sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:455) ~[?:?]
> at sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:426) ~[?:?]
> at sun.net.www.protocol.https.HttpsClient.afterConnect(HttpsClient.java:578) ~[?:?]
> at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:187) ~[?:?]
> at sun.net.www.protocol.https.HttpsURLConnectionImpl.connect(HttpsURLConnectionImpl.java:142) ~[?:?]
> at org.elasticsearch.xpack.core.common.socket.SocketAccess.lambda$doPrivileged$0(SocketAccess.java:42) ~[?:?]
> at java.security.AccessController.doPrivileged(AccessController.java:569) ~[?:?]
> at org.elasticsearch.xpack.core.common.socket.SocketAccess.doPrivileged(SocketAccess.java:41) ~[?:?]
> at org.elasticsearch.xpack.core.security.CommandLineHttpClient.execute(CommandLineHttpClient.java:178) ~[?:?]
> at org.elasticsearch.xpack.core.security.CommandLineHttpClient.execute(CommandLineHttpClient.java:112) ~[?:?]
> at org.elasticsearch.xpack.security.tool.BaseRunAsSuperuserCommand.checkClusterHealthWithRetries(BaseRunAsSuperuserCommand.java:214) ~[?:?]
> at org.elasticsearch.xpack.security.tool.BaseRunAsSuperuserCommand.execute(BaseRunAsSuperuserCommand.java:127) ~[?:?]
> at org.elasticsearch.common.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:54) ~[elasticsearch-8.7.0.jar:8.7.0]
> at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:85) ~[elasticsearch-cli-8.7.0.jar:8.7.0]
> at org.elasticsearch.cli.Command.main(Command.java:50) ~[elasticsearch-cli-8.7.0.jar:8.7.0]
> at org.elasticsearch.launcher.CliToolLauncher.main(CliToolLauncher.java:64) ~[cli-launcher-8.7.0.jar:8.7.0]
> 
> ERROR: Failed to determine the health of the cluster.

```

---

<div class="post-metadata">

**Author:** ![JLeysens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jleysens/32/67404_2.png) [@JLeysens](https://discuss.elastic.co/u/JLeysens)\
**Post date:** [May 9, 2023, 10:16am UTC](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856/4 "2023-05-09T10:16:29Z")

</div>

Hi @Julien069 ! The issue is the machine you are trying to create the enrollment token from does not have the ability to establish a connection over SSL (`https`). This is an issue with the certificate not including your Elasticsearch node's address, how did you generate the SSL certificate? It should include a SAN (Subject Alternative Name) entry for your IP address see:

> **[Set up basic security for the Elastic Stack plus secured HTTPS traffic |...](https://www.elastic.co/guide/en/elasticsearch/reference/master/security-basic-setup-https.html#encrypt-http-communication)**
>
> ELSER is a learned sparse ranking model trained by Elastic.

The alternative is to just not connect over SSL (`xpack.security.http.ssl.enabled: false`), but I'm not sure whether that is an option for you?

---

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [May 9, 2023, 12:30pm UTC](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856/5 "2023-05-09T12:30:37Z")

</div>

Hi Jean-louis ( French ? )

In fact , the problem comes from the change of the IP address .  
I tried to generate a new CA but it doesn't work .

I don't understand somethings , what it's the difference between :

` xpack.security.http.ssl`

and

` xpack.security.transport.ssl`

For me ,`http.ssl` is for the webconsole and `transport` for the exchange between Elastic and Kibana ...

---

<div class="post-metadata">

**Author:** ![JLeysens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jleysens/32/67404_2.png) [@JLeysens](https://discuss.elastic.co/u/JLeysens)\
**Post date:** [May 9, 2023, 12:55pm UTC](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856/6 "2023-05-09T12:55:07Z")

</div>

I see, it seems your ES node's public IP address changed.

Again, to get a new certificate from your Elasticsearch central CA follow the link from the previous message and use the `./bin/elasticsearch-certutil http` (from where you have ES installed) and follow the prompts.

> [@Julien069](#):
>
> For me ,`http.ssl` is for the webconsole and `transport` for the exchange between Elastic and Kibana ...

`http` is for any traffic coming to your cluster over the Internet, this includes Kibana. `transport` is for internode communication - traffic that flows between your ES nodes.

---

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [May 10, 2023, 12:06pm UTC](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856/7 "2023-05-10T12:06:09Z")

</div>

> [@JLeysens](#):
>
> `http` is for any traffic coming to your cluster over the Internet, this includes Kibana. `transport` is for internode communication - traffic that flows between your ES nodes.

Thanks you very much for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2023, 12:06pm UTC](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856/8 "2023-06-07T12:06:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
