# Elastic http securing: access denied ("java.io.FilePermission" "/etc/pki/tls/private" "read")

**URL:** <https://discuss.elastic.co/t/elastic-http-securing-access-denied-java-io-filepermission-etc-pki-tls-private-read/266202>\
**Category:** Elasticsearch\
**Created:** [March 4, 2021, 9:26am UTC](https://discuss.elastic.co/t/elastic-http-securing-access-denied-java-io-filepermission-etc-pki-tls-private-read/266202 "2021-03-04T09:26:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![raulk89](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@raulk89](https://discuss.elastic.co/u/raulk89)\
**Post date:** [March 4, 2021, 9:26am UTC](https://discuss.elastic.co/t/elastic-http-securing-access-denied-java-io-filepermission-etc-pki-tls-private-read/266202/1 "2021-03-04T09:26:54Z")

</div>

Hi

Elastic 7.11.1  
I am trying to secure http protcol.  
But I am getting

```
2021-03-04T11:15:13,050][ERROR][o.e.b.Bootstrap] [dev-dc2-rk] Exception
java.security.AccessControlException: access denied ("java.io.FilePermission" "/etc/pki/tls/private" "read")

```

Although permissions are fine (others have "r"):

> [root@dev-dc2-rk ~]# ls -lh / | grep etc  
> drwxr-xr-x. 101 root root 8.0K Mar 4 11:18 etc
> 
> [root@dev-dc2-rk ~]# ls -lh /etc/ | grep pki  
> drwxr-xr-x. 14 root root 4.0K Aug 13 2020 pki
> 
> [root@dev-dc2-rk ~]# ls -lh /etc/pki | grep tls  
> drwxr-xr-x. 5 root root 76 Dec 19 04:27 tls
> 
> [root@dev-dc2-rk ~]# ls -lh /etc/pki/tls | grep private  
> drwxr-xr-x. 2 root root 59 Mar 2 11:15 private
> 
> [root@dev-dc2-rk ~]# ls -lh /etc/pki/tls/private/  
> total 8.0K  
> -r--r--r-- 1 root elasticsearch 1.7K Apr 11 2019 priv.key

I also did try copying the key file to "/etc"

Then I get this:

```
2021-03-04T11:19:13,050][ERROR][o.e.b.Bootstrap] [dev-dc2-rk] Exception
java.security.AccessControlException: access denied ("java.io.FilePermission" "/etc" "read")

```

Also, this same error comes for all of these:

- xpack.security.http.ssl.key
- xpack.security.http.ssl.certificate
- xpack.security.http.ssl.certificate\_authorities

Help needed.

Regards  
Raul

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [March 4, 2021, 9:39am UTC](https://discuss.elastic.co/t/elastic-http-securing-access-denied-java-io-filepermission-etc-pki-tls-private-read/266202/2 "2021-03-04T09:39:59Z")

</div>

Elasticsearch only has permission to read config files from within its own config directory, which probably isn't `/etc/pki`. See [these docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-files.html) for more details:

> **IMPORTANT** : Any files that the security features use must be stored in the Elasticsearch configuration directory. Elasticsearch runs with restricted permissions and is only permitted to read from the locations configured in the directory layout for enhanced security.

and also [step 4 of these docs](https://www.elastic.co/guide/en/elasticsearch/reference/7.11/configuring-tls.html#node-certificates) which says to put the certs in the config directory.

---

<div class="post-metadata">

**Author:** ![raulk89](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@raulk89](https://discuss.elastic.co/u/raulk89)\
**Post date:** [March 4, 2021, 10:09am UTC](https://discuss.elastic.co/t/elastic-http-securing-access-denied-java-io-filepermission-etc-pki-tls-private-read/266202/3 "2021-03-04T10:09:41Z")

</div>

Ok, thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2021, 10:10am UTC](https://discuss.elastic.co/t/elastic-http-securing-access-denied-java-io-filepermission-etc-pki-tls-private-read/266202/4 "2021-04-01T10:10:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
