# Elastic user not able to authenticate after full cluster restart

**URL:** <https://discuss.elastic.co/t/elastic-user-not-able-to-authenticate-after-full-cluster-restart/168684>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 16, 2019, 1:16pm UTC](https://discuss.elastic.co/t/elastic-user-not-able-to-authenticate-after-full-cluster-restart/168684 "2019-02-16T13:16:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![prabhakar\_talari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhakar_talari/32/46469_2.png) [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Post date:** [February 16, 2019, 1:16pm UTC](https://discuss.elastic.co/t/elastic-user-not-able-to-authenticate-after-full-cluster-restart/168684/1 "2019-02-16T13:16:26Z")

</div>

All,

We have enabled TLS and restarted full cluster. but elastic user is not able to authenticate with cluster getting below error

{  
"error" : {  
"root\_cause" : [  
{  
"type" : "security\_exception",  
"reason" : "failed to authenticate user [elastic]",  
"header" : {  
"WWW-Authenticate" : "Basic realm="security" charset="UTF-8""  
}  
}  
],  
"type" : "security\_exception",  
"reason" : "failed to authenticate user [elastic]",  
"header" : {  
"WWW-Authenticate" : "Basic realm="security" charset="UTF-8""  
}  
},  
"status" : 401  
}

could any one suggest please

Regards

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [February 18, 2019, 7:23am UTC](https://discuss.elastic.co/t/elastic-user-not-able-to-authenticate-after-full-cluster-restart/168684/2 "2019-02-18T07:23:33Z")

</div>

Please look at the relevant part of your Elasticsearch logs for the time you attempt to authenticate, there will be helpful details there. If the issue doesn't become obvious, please share the logs here ( **Do** format them using the `</>` button and checking the preview window) and we can take a look

---

<div class="post-metadata">

**Author:** ![prabhakar\_talari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhakar_talari/32/46469_2.png) [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Post date:** [February 18, 2019, 8:28am UTC](https://discuss.elastic.co/t/elastic-user-not-able-to-authenticate-after-full-cluster-restart/168684/3 "2019-02-18T08:28:52Z")

</div>

Thank you for the help. The issue has been resolved by adding below parameter

`xpack.ssl.verification_mode: certificate`

While generating the certificate we have not mentioned dns option.

Thans

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2019, 8:28am UTC](https://discuss.elastic.co/t/elastic-user-not-able-to-authenticate-after-full-cluster-restart/168684/4 "2019-03-18T08:28:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
