# Elasticsearch 7.8.0 user authentication with X-Pack security fails

**URL:** <https://discuss.elastic.co/t/elasticsearch-7-8-0-user-authentication-with-x-pack-security-fails/249889>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 25, 2020, 2:17am UTC](https://discuss.elastic.co/t/elasticsearch-7-8-0-user-authentication-with-x-pack-security-fails/249889 "2020-09-25T02:17:15Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [September 29, 2020, 5:47pm UTC](https://discuss.elastic.co/t/elasticsearch-7-8-0-user-authentication-with-x-pack-security-fails/249889/10 "2020-09-29T17:47:55Z")

</div>

> [@dzyubanv](#):
>
> curl --cacert certs/elastic-certificates.p12

```auto
       --cacert <CA certificate>
              (TLS) Tells curl to use the specified certificate file to verify the peer. The file may contain multiple CA certificates. The certificate(s) must be in PEM format.

```

The curl option requires the cert in a PEM format but you're passing the cert in a PKCS12 format.

You can convert it with something similar to:

```auto
openssl pkcs12 -in certs/elastic-certificates.p12 -out certs/elastic-certificates.crt -nokeys

```

But be advised that, from my reading of the file names, you're passing in client certificates as certificate authorities.

Since the conversation strayed away from the original topic, maybe it's worth to open another thread, or better still find something that applies to your present situation, such as [Mutual tls/ssl on elasticsearch - #17 by SukeshGupta](https://discuss.elastic.co/t/mutual-tls-ssl-on-elasticsearch/197768/17) .

---

_[View the full topic](https://discuss.elastic.co/t/elasticsearch-7-8-0-user-authentication-with-x-pack-security-fails/249889)._
