# Elasticsearch 7.4 unable to read truststore file

**URL:** <https://discuss.elastic.co/t/elasticsearch-7-4-unable-to-read-truststore-file/236504>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 10, 2020, 12:03pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-unable-to-read-truststore-file/236504 "2020-06-10T12:03:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bytemedwb](https://avatars.discourse-cdn.com/v4/letter/b/7bcc69/32.png) [@bytemedwb](https://discuss.elastic.co/u/bytemedwb)\
**Post date:** [June 10, 2020, 12:03pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-unable-to-read-truststore-file/236504/1 "2020-06-10T12:03:09Z")

</div>

All:  
I am having the same error as described in this post:

> [@Trying to figure out how to enable x-pack](https://discuss.elastic.co/t/trying-to-figure-out-how-to-enable-x-pack/213367):
>
> I have been repeatedly failing to figure out how to properly enable x-pack. There's a lot of guides out there, but I still feel like I'm missing something. I built a new test machine to try to simplify this but am still running into trouble, so I turn to here for assistance. I'll reference this guide for example. [https://www.elastic.co/blog/getting-started-with-elasticsearch-security](https://www.elastic.co/blog/getting-started-with-elasticsearch-security) Firstly, my environment characteristics. Mine is a bit different than the guide, as I'm using CentOS 7. I'm tes…

In my log file I get the following:  
`Caused by: org.elasticsearch.ElasticsearchException: failed to initialize SSL TrustManager - access to read truststore file [/etc/pki/java/truststore.jks] is blocked; SSL resources should be placed in the [/etc/elasticsearch/dspc] directory`

Followed by:  
`Caused by: java.security.AccessControlException: access denied ("java.io.FilePermission" "/etc/pki/java/truststore.jks" "read")`

However the elasticsearch user should have permissions to the file as shown below:  
`[root@dspcnode04 dspc]# ls -alt /etc/pki/java total 60 drwxr-xr-x+ 15 root root 195 May 28 15:48 .. drwxr-xr-x. 2 root root 83 May 28 15:48 . -rw-r--r-- 1 root root 2467 May 28 15:48 keystore.jks -rw-r--r-- 1 root root 3992 May 28 15:48 keystore.p12 -rw-r--r-- 1 root root 53152 May 28 15:39 truststore.jks lrwxrwxrwx. 1 root root 40 May 25 20:39 cacerts -> /etc/pki/ca-trust/extracted/java/cacerts`

Add to this I can run the command:

`su elasticsearch -c 'cat /etc/pki/java/truststore.jks'`

And see the file. The other posts I have found similar offer no help.  
I am installing this ES on an existing cluster and need to use the existing certificates and trust/key stores.

I have looked through the tutorial and not found anything helpful.  
Any idea on how to even approach debugging this?

UPDATE:  
I have just tried the following:

1. Linking the jks files in /etc/pki/java to /etc/elasticsearch/dspc and changing the elasticsearch.yml file to point to /etc/elasticsearch/dspc. ----- That did not work.

2. I copied the jks files to /etc/elasticsearch/dspc , left the ownership and permissions (root, 644) the same and had the elasticsearch.yml file point to them. ---- That did work.

So now my updated question:  
Why does Elasticsearch 7.4 require the files to be in the configuration directory??

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [June 10, 2020, 12:36pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-unable-to-read-truststore-file/236504/2 "2020-06-10T12:36:54Z")

</div>

> [@bytemedwb](#):
>
> Why does Elasticsearch 7.4 require the files to be in the configuration directory??

This is not 7.4 specifically, all versions have this requirement.

---

<div class="post-metadata">

**Author:** ![bytemedwb](https://avatars.discourse-cdn.com/v4/letter/b/7bcc69/32.png) [@bytemedwb](https://discuss.elastic.co/u/bytemedwb)\
**Post date:** [June 10, 2020, 1:05pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-unable-to-read-truststore-file/236504/3 "2020-06-10T13:05:58Z")

</div>

Thanks, but this really make managing common certificates and key/trust stores in a large cluster difficult.

Was someone just trying to implement extra security?

I have multiple applications and tools that need to share common certs and keys. This is all managed through thousands of lines of puppet code.  
At least provide me a variable to override the fixed location.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [June 11, 2020, 3:17pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-unable-to-read-truststore-file/236504/4 "2020-06-11T15:17:15Z")

</div>

> [@bytemedwb](#):
>
> Was someone just trying to implement extra security?

Spot on, that would certainly be us.

We grant ( via a SecurityManager policy ) the permission to read files _only_ from within the configuration directory.

> [@bytemedwb](#):
>
> At least provide me a variable to override the fixed location.

I think you are looking for [`ES_PATH_CONF`](https://www.elastic.co/guide/en/elasticsearch/reference/current/settings.html#config-files-location), we don't have an override setting path only for key/certificate material

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2020, 3:17pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-unable-to-read-truststore-file/236504/5 "2020-07-09T15:17:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
