# Elastic wont start - java.io.IOException: keystore password was incorrect

**URL:** <https://discuss.elastic.co/t/elastic-wont-start-java-io-ioexception-keystore-password-was-incorrect/204819>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 23, 2019, 8:21am UTC](https://discuss.elastic.co/t/elastic-wont-start-java-io-ioexception-keystore-password-was-incorrect/204819 "2019-10-23T08:21:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sidharth\_Sinha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidharth_sinha/32/46287_2.png) [@Sidharth\_Sinha](https://discuss.elastic.co/u/Sidharth_Sinha)\
**Post date:** [October 23, 2019, 8:21am UTC](https://discuss.elastic.co/t/elastic-wont-start-java-io-ioexception-keystore-password-was-incorrect/204819/1 "2019-10-23T08:21:31Z")

</div>

I configured elastic to do x-pack security.  
Followed the documentation to create pkcs12 certs using the certutil, configured the password, and also added keystore entry to match the password.

When I start elastic, I get the follwing:

> Caused by: org.elasticsearch.ElasticsearchException: failed to initialize SSL TrustManager  
> at org.elasticsearch.xpack.core.ssl.StoreTrustConfig.createTrustManager(StoreTrustConfig.java:74) ~[?:?]  
> at org.elasticsearch.xpack.core.ssl.SSLService.createSslContext(SSLService.java:384) ~[?:?]  
> at jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) ~[?:?]  
> at jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62) ~[?:?]  
> at jdk.internal.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45) ~[?:?]  
> at java.lang.reflect.Constructor.newInstanceWithCaller(Constructor.java:500) ~[?:?]  
> at java.lang.reflect.Constructor.newInstance(Constructor.java:481) ~[?:?]  
> at org.elasticsearch.plugins.PluginsService.loadPlugin(PluginsService.java:605) ~[elasticsearch-7.4.0.jar:7.4.0]  
> at org.elasticsearch.plugins.PluginsService.loadBundle(PluginsService.java:556) ~[elasticsearch-7.4.0.jar:7.4.0]  
> at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:349) ~[elasticsearch-7.4.0.jar:7.4.0]  
> at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:159) ~[elasticsearch-7.4.0.jar:7.4.0]  
> ... 6 more  
> Caused by: java.io.IOException: keystore password was incorrect  
> at sun.security.pkcs12.PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2118) ~[?:?]  
> at sun.security.util.KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:222) ~[?:?]  
> at java.security.KeyStore.load(KeyStore.java:1472) ~[?:?]  
> at org.elasticsearch.xpack.core.ssl.TrustConfig.getStore(TrustConfig.java:97) ~[?:?]  
> at org.elasticsearch.xpack.core.ssl.StoreTrustConfig.createTrustManager(StoreTrustConfig.java:65) ~[?:?]  
> at org.elasticsearch.xpack.core.ssl.SSLService.createSslContext(SSLService.java:384) ~[?:?]  
> at java.util.HashMap.computeIfAbsent(HashMap.java:1138) ~[?:?]  
> at org.elasticsearch.xpack.core.ssl.SSLService.loadConfiguration(SSLService.java:446) ~[?:?]  
> at org.elasticsearch.xpack.core.ssl.SSLService.lambda$loadSSLConfigurations$2(SSLService.java:426) ~[?:?]  
> at java.util.HashMap.forEach(HashMap.java:1338) ~[?:?]  
> at jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62) ~[?:?]  
> at jdk.internal.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45) ~[?:?]  
> at java.lang.reflect.Constructor.newInstanceWithCaller(Constructor.java:500) ~[?:?]  
> at java.lang.reflect.Constructor.newInstance(Constructor.java:481) ~[?:?]  
> at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:159) ~[elasticsearch-7.4.0.jar:7.4.0]  
> ... 6 more  
> Caused by: java.security.UnrecoverableKeyException: failed to decrypt safe contents entry: javax.crypto.BadPaddingException: Given final block not properly padded. Such issues can arise if a bad key is used during decryption.  
> at sun.security.pkcs12.PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2118) ~[?:?]  
> at sun.security.util.KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:222) ~[?:?]  
> at java.security.KeyStore.load(KeyStore.java:1472) ~[?:?]  
> at org.elasticsearch.xpack.core.ssl.TrustConfig.getStore(TrustConfig.java:97) ~[?:?]  
> at org.elasticsearch.xpack.core.ssl.StoreTrustConfig.createTrustManager(StoreTrustConfig.java:65) ~[?:?]  
> at java.util.HashMap.forEach(HashMap.java:1338) ~[?:?]  
> at org.elasticsearch.xpack.core.ssl.SSLService.loadSSLConfigurations(SSLService.java:426) ~[?:?]  
> at org.elasticsearch.xpack.core.ssl.SSLService.(SSLService.java:121) ~[?:?]  
> at org.elasticsearch.xpack.core.XPackPlugin.(XPackPlugin.java:142) ~[?:?]  
> at jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) ~[?:?]  
> at jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62) ~[?:?]  
> at jdk.internal.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45) ~[?:?]  
> at java.lang.reflect.Constructor.newInstanceWithCaller(Constructor.java:500) ~[?:?]  
> at java.lang.reflect.Constructor.newInstance(Constructor.java:481) ~[?:?]  
> at org.elasticsearch.plugins.PluginsService.loadPlugin(PluginsService.java:605) ~[elasticsearch-7.4.0.jar:7.4.0]  
> at org.elasticsearch.plugins.PluginsService.loadBundle(PluginsService.java:556) ~[elasticsearch-7.4.0.jar:7.4.0]  
> at org.elasticsearch.plugins.PluginsService.loadBundles(PluginsService.java:471) ~[elasticsearch-7.4.0.jar:7.4.0]  
> at org.elasticsearch.plugins.PluginsService.(PluginsService.java:163) ~[elasticsearch-7.4.0.jar:7.4.0]  
> at org.elasticsearch.node.Node.(Node.java:311) ~[elasticsearch-7.4.0.jar:7.4.0]  
> at org.elasticsearch.node.Node.(Node.java:255) ~[elasticsearch-7.4.0.jar:7.4.0]  
> at org.elasticsearch.bootstrap.Bootstrap$5.(Bootstrap.java:221) ~[elasticsearch-7.4.0.jar:7.4.0]  
> at org.elasticsearch.bootstrap.Bootstrap.setup(Bootstrap.java:221) ~[elasticsearch-7.4.0.jar:7.4.0]  
> at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:349) ~[elasticsearch-7.4.0.jar:7.4.0]  
> at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:159) ~[elasticsearch-7.4.0.jar:7.4.0]  
> ... 6 more

Heres my config:

> xpack.security.enabled: true  
> xpack.monitoring.enabled: true
> 
> discovery.type: single-node
> 
> xpack.ssl.keystore.password:   
> xpack.security.transport.ssl.enabled: true  
> xpack.security.transport.ssl.verification\_mode: certificate  
> xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/elastic-certificates.p12  
> xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/elastic-certificates.p12
> 
> xpack.security.http.ssl.enabled: true  
> xpack.security.http.ssl.keystore.path: /etc/elasticsearch/certs/elastic-certificates.p12  
> xpack.security.http.ssl.truststore.path: /etc/elasticsearch/certs/elastic-certificates.p12  
> xpack.security.http.ssl.client\_authentication: optional

I cant get elastic to start. Am I missing anything?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 23, 2019, 2:21pm UTC](https://discuss.elastic.co/t/elastic-wont-start-java-io-ioexception-keystore-password-was-incorrect/204819/2 "2019-10-23T14:21:02Z")

</div>

You have password protected your `elastic-certificates.p12` and you don't have this set anywhere in your configuration so elasticsearch fails to read this. You need to add the relevant settings

---

<div class="post-metadata">

**Author:** ![Sidharth\_Sinha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidharth_sinha/32/46287_2.png) [@Sidharth\_Sinha](https://discuss.elastic.co/u/Sidharth_Sinha)\
**Post date:** [October 24, 2019, 4:33am UTC](https://discuss.elastic.co/t/elastic-wont-start-java-io-ioexception-keystore-password-was-incorrect/204819/3 "2019-10-24T04:33:54Z")

</div>

Hi Ioannis,

Thanks. Isnt this the password that is mentioned under. I already did the below for both keystore and truststore:

> xpack.ssl.keystore.password

I have also added the password using :

> ./elasticsearch-keystore add xpack.ssl.keystore.secure\_password

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 24, 2019, 4:54am UTC](https://discuss.elastic.co/t/elastic-wont-start-java-io-ioexception-keystore-password-was-incorrect/204819/5 "2019-10-24T04:54:59Z")

</div>

This is not the correct configuration parameter. `xpack.ssl.*` default settings were removed in version 7 and even before these wouldn't apply to passwords. see [https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html).

Since you define the keystore in the following for configuration settings

```auto
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/elastic-certificates.p12
xpack.security.http.ssl.keystore.path: /etc/elasticsearch/certs/elastic-certificates.p12
xpack.security.http.ssl.truststore.path: /etc/elasticsearch/certs/elastic-certificates.p12

```

you either need

```auto
xpack.security.transport.ssl.keystore.password: <your_password_here>
xpack.security.transport.ssl.truststore.password: <your_password_here>
xpack.security.http.ssl.keystore.password: <your_password_here>
xpack.security.http.ssl.truststore.password: <your_password_here>

```

or alternatively add them to the secure settings with

```auto
./elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure_password
./elasticsearch-keystore add xpack.security.transport.ssl.truststore.secure_password
./elasticsearch-keystore add xpack.security.http.ssl.keystore.secure_password
./elasticsearch-keystore add xpack.security.http.ssl.truststore.secure_password

```

---

<div class="post-metadata">

**Author:** ![Sidharth\_Sinha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidharth_sinha/32/46287_2.png) [@Sidharth\_Sinha](https://discuss.elastic.co/u/Sidharth_Sinha)\
**Post date:** [October 24, 2019, 4:56am UTC](https://discuss.elastic.co/t/elastic-wont-start-java-io-ioexception-keystore-password-was-incorrect/204819/6 "2019-10-24T04:56:29Z")

</div>

Thanks a lot Ioannis! That helped.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2019, 4:56am UTC](https://discuss.elastic.co/t/elastic-wont-start-java-io-ioexception-keystore-password-was-incorrect/204819/7 "2019-11-21T04:56:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
