# Elasticsearch 7.4.2 : Problem with SSL configuration

**URL:** <https://discuss.elastic.co/t/elasticsearch-7-4-2-problem-with-ssl-configuration/208101>\
**Category:** Elasticsearch\
**Created:** [November 15, 2019, 3:50pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-2-problem-with-ssl-configuration/208101 "2019-11-15T15:50:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michael\_Oullion](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_oullion/32/46106_2.png) [@Michael\_Oullion](https://discuss.elastic.co/u/Michael_Oullion)\
**Post date:** [November 15, 2019, 3:50pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-2-problem-with-ssl-configuration/208101/1 "2019-11-15T15:50:27Z")

</div>

Hi,

I try to configure **https** on my Elasticsearch and I have some trouble to do it.

I start with a **pfx certificate** provide by my Ops team.  
I try to use this type of configuration :

```auto
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.key: E:\example\elasticsearch-7.4.2\config\cert.key
xpack.security.http.ssl.key_passphrase: test
xpack.security.http.ssl.certificate: E:\example\elasticsearch-7.4.2\config\cert.crt

```

I know I can use :

```auto
xpack.security.http.ssl.keystore.type: PKCS12
xpack.security.http.ssl.keystore.path: E:\example\elasticsearch-7.4.2\config\wildcard.recette.corp.lan.pfx
xpack.security.http.ssl.keystore.password: blablablabla

```

and it's works but for some reasons, I would used the first config.

To do that, I must transform my pfx in 2 files :  
**Key**

```auto
openssl pkcs12 -in wildcard.recette.corp.lan.pfx -nocerts -out cert.key

```

**Certificat**

```auto
openssl pkcs12 -in wildcard.recette.corp.lan.pfx -nokeys -out cert.crt

```

With this config, I have this error :

```auto
Caused by: java.io.IOException: **ObjectIdentifier() -- data isn't an object ID** (tag = 48)
         at sun.security.util.ObjectIdentifier.<init>(ObjectIdentifier.java:253) ~[?:?]
         at sun.security.util.DerInputStream.getOID(DerInputStream.java:281) ~[?:?]
         at com.sun.crypto.provider.PBES2Parameters.engineInit(PBES2Parameters.java:267) ~[sunjce_provider.jar:1.8.0_20]
         at java.security.AlgorithmParameters.init(AlgorithmParameters.java:293) ~[?:1.8.0_25]
         at sun.security.x509.AlgorithmId.decodeParams(AlgorithmId.java:132) ~[?:?]
         at sun.security.x509.AlgorithmId.<init>(AlgorithmId.java:114) ~[?:?]
         at sun.security.x509.AlgorithmId.parse(AlgorithmId.java:372) ~[?:?]

```

After a little Google search, I find [this](https://github.com/elastic/elasticsearch/issues/32021)  
So, I try the pkcs8 solution :

```auto
openssl pkcs8 -topk8 -v1 PBE-SHA1-RC4-128 -in cert.key -out cert8.key

```

The Elasticsearch Server now start !  
.... but failed to start an https channel

```auto
java.lang.IllegalArgumentException: did not find an SSLContext for [SSLConfiguration{keyConfig=[keyPath=[E:\example\elasticsearch
-7.4.2\config\cert8.key], certPaths=[E:\example\elasticsearch-7.4.2\config\cert.crt]], trustConfig=Combining Trust Config{JDK tru
sted certs, keyPath=[E:\example\elasticsearch-7.4.2\config\cert8.key], certPaths=[E:\example\elasticsearch-7.4.2\confi
g\cert.crt]}], cipherSuites=[[TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_256_C
BC_SHA384, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_
WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA256, TLS_RSA_WITH_AES_128_CBC_SHA256, TLS_RSA_WITH_AES
_256_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA]], supportedProtocols=[[TLSv1.2, TLSv1.1]], sslClientAuth=[NONE], verificationMode=[FULL]}]
        at org.elasticsearch.xpack.core.ssl.SSLService.sslContextHolder(SSLService.java:306) ~[x-pack-core-7.4.2.jar:7.4.2]
        at org.elasticsearch.xpack.core.ssl.SSLService.sslContext(SSLService.java:294) ~[x-pack-core-7.4.2.jar:7.4.2]
        at org.elasticsearch.xpack.core.ssl.SSLService.createSSLEngine(SSLService.java:250) ~[x-pack-core-7.4.2.jar:7.4.2]
        at org.elasticsearch.xpack.security.transport.netty4.SecurityNetty4HttpServerTransport$HttpSslChannelHandler.initChannel...

```

I don't really understand this error and so, I don't know how to resolve it.

I try with

```auto
openssl pkcs12 -in wildcard.recette.corp.lan.pfx -nocerts -out cert.key -nodes

```

and it's work but I want a passphrase on my private key.

Any ideas?

_Info :_  
_Windows Server 2012 R2_  
_Java Oracle jdk 1.8.0\_25_  
_Elasticsearch 7.4.2_

Regards,  
Mike

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2019, 3:50pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-2-problem-with-ssl-configuration/208101/2 "2019-12-13T15:50:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
