# ElasticSearch Certificate issue

**URL:** <https://discuss.elastic.co/t/elasticsearch-certificate-issue/362682>\
**Category:** Elasticsearch\
**Created:** [July 8, 2024, 8:51am UTC](https://discuss.elastic.co/t/elasticsearch-certificate-issue/362682 "2024-07-08T08:51:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rash4ford](https://avatars.discourse-cdn.com/v4/letter/r/b4bc9f/32.png) [@rash4ford](https://discuss.elastic.co/u/rash4ford)\
**Post date:** [July 8, 2024, 8:51am UTC](https://discuss.elastic.co/t/elasticsearch-certificate-issue/362682/1 "2024-07-08T08:51:59Z")

</div>

Hi Team,

Our Elastis is complaining about certificate - I have checked all the cerficate assigned to elastic none of them are expired.

Please advise any help is greatly appreciated

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate  
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:499) ~[?:?]  
at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:290) ~[?:?]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:444) ~[?:?]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:420) ~[?:?]  
at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:412) ~[?:?]  
at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1410) ~[?:?]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:440) ~[?:?]  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:420) ~[?:?]  
at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:919) ~[?:?]  
at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:166) ~[?:?]  
at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:788) ~[?:?]  
at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:689) ~[?:?]  
at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:652) ~[?:?]  
at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:562) ~[?:?]  
at io.netty.util.concurrent.SingleThreadEventExecutor$4.run(SingleThreadEventExecutor.java:997) ~[?:?]  
at io.netty.util.internal.ThreadExecutorMap$2.run(ThreadExecutorMap.java:74) ~[?:?]  
at java.lang.Thread.run(Thread.java:1570) ~[?:?]  
Caused by: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate  
at sun.security.ssl.Alert.createSSLException(Alert.java:130) ~[?:?]  
at sun.security.ssl.Alert.createSSLException(Alert.java:117) ~[?:?]  
at sun.security.ssl.TransportContext.fatal(TransportContext.java:365) ~[?:?]  
at sun.security.ssl.Alert$AlertConsumer.consume(Alert.java:287) ~[?:?]  
at sun.security.ssl.TransportContext.dispatch(TransportContext.java:204) ~[?:?]  
at sun.security.ssl.SSLTransport.decode(SSLTransport.java:172) ~[?:?]  
at sun.security.ssl.SSLEngineImpl.decode(SSLEngineImpl.java:736) ~[?:?]  
at sun.security.ssl.SSLEngineImpl.readRecord(SSLEngineImpl.java:691) ~[?:?]  
at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:506) ~[?:?]  
at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:482) ~[?:?]  
at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:679) ~[?:?]  
at io.netty.handler.ssl.SslHandler$SslEngineType$3.unwrap(SslHandler.java:310) ~[?:?]  
at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1445) ~[?:?]  
at io.netty.handler.ssl.SslHandler.decodeJdkCompatible(SslHandler.java:1338) ~[?:?]  
at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:1387) ~[?:?]  
at io.netty.handler.codec.ByteToMessageDecoder.decodeRemovalReentryProtection(ByteToMessageDecoder.java:529) ~[?:?]  
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:468) ~[?:?]

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/d/add3b7ecac486d8713b7721f54ef10fd77a3b834.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/a/6abbf43f4b61890131b1c873a8f31bea111f43b2.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/3/6386c75a7353ede43c8a937d1ac29ea80271ed4b.png)

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 9, 2024, 4:05am UTC](https://discuss.elastic.co/t/elasticsearch-certificate-issue/362682/2 "2024-07-09T04:05:41Z")

</div>

Please take the time to copy and paste the full log message as text. You've left off the first line from the log message, which is the most important part.

Also, please do not paste screenshots of text. It is hard to read (particularly on mobile devices), inaccessible for people with vision impairments, and impossible to search. If you would like us to provide our time to help you, then please take the time to copy and paste the relevant information as text.

One of your HTTP clients is not configured to trust your `ca.crt`. If you look in the log it will tell you the address of that client which may help you to track it down.  
There is nothing you can do on the server to fix this, other than possibly switching to a different set of certificate (from a different CA) that are already trusted by your expected clients.

---

<div class="post-metadata">

**Author:** ![rash4ford](https://avatars.discourse-cdn.com/v4/letter/r/b4bc9f/32.png) [@rash4ford](https://discuss.elastic.co/u/rash4ford)\
**Post date:** [July 9, 2024, 1:39pm UTC](https://discuss.elastic.co/t/elasticsearch-certificate-issue/362682/3 "2024-07-09T13:39:38Z")

</div>

Thank you so much I will check it
