# Elasticsearch crashes with "Certificate chain is not valid" exception

**URL:** <https://discuss.elastic.co/t/elasticsearch-crashes-with-certificate-chain-is-not-valid-exception/212611>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 20, 2019, 6:59am UTC](https://discuss.elastic.co/t/elasticsearch-crashes-with-certificate-chain-is-not-valid-exception/212611 "2019-12-20T06:59:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fetch](https://avatars.discourse-cdn.com/v4/letter/f/dbc845/32.png) [@fetch](https://discuss.elastic.co/u/fetch)\
**Post date:** [December 20, 2019, 6:59am UTC](https://discuss.elastic.co/t/elasticsearch-crashes-with-certificate-chain-is-not-valid-exception/212611/1 "2019-12-20T06:59:44Z")

</div>

Hello,

I have a cluster of 3 servers with ELK 6.8.6 stack.

I'm trying to setup the 3rd server of the cluster, but it behaves somehow different.

I specify the following configuration for ssl:

```auto
xpack.security.enabled: true
xpack.monitoring.collection.enabled: true

xpack.security.http.ssl.enabled: false
#xpack.security.http.ssl.verification_mode: certificate
#xpack.security.http.ssl.key: my.key
#xpack.security.http.ssl.certificate: my.pem
#xpack.security.http.ssl.certificate_authorities: ["my.ca"]

xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate

xpack.security.transport.ssl.keystore.type: PKCS12
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.keystore.password: "pass"

xpack.security.transport.ssl.truststore.type: PKCS12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.password: "pass"

```

With this configuration elasticsearch starts and works fine. However, as soon as I uncomment `xpack.security.http*` options elasticsearch crashes at boot with the following traceback: [https://pastebin.com/sKA7KUhg](https://pastebin.com/sKA7KUhg)

It happens even with the options:

```auto
xpack.security.http.ssl.enabled: false
xpack.security.http.ssl.verification_mode: none

```

I've checked the certificate with the openssl and it seems fine:

```auto
openssl verify -verbose -CAfile my.ca my.pem
my.pem: OK

```

Another weird part of this situation that I have exactly the same `my.key`, `my.pem`, `my.ca` on two other servers and elasticsearch works fine with them.

Any ideas how to fix it?

---

<div class="post-metadata">

**Author:** ![fetch](https://avatars.discourse-cdn.com/v4/letter/f/dbc845/32.png) [@fetch](https://discuss.elastic.co/u/fetch)\
**Post date:** [December 20, 2019, 10:43am UTC](https://discuss.elastic.co/t/elasticsearch-crashes-with-certificate-chain-is-not-valid-exception/212611/2 "2019-12-20T10:43:48Z")

</div>

3 days of trials and errors finally gave some results...

Two servers are using Oracle JDK that doesn't care about the pem with the certificates chain.

But the third server has OpenJDK and turns out that it will fail chain validation if the certificates placed in the wrong order. So the solution was to reorder the `my.pem` file in the way that the next certificate has the subject equal to the issuer of the pevious certificate.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2020, 10:43am UTC](https://discuss.elastic.co/t/elasticsearch-crashes-with-certificate-chain-is-not-valid-exception/212611/3 "2020-01-17T10:43:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
