# Elastisearch Start : java.nio.file.AccessDeniedException: /etc/elasticsearch/elasticsearch.keystore

**URL:** <https://discuss.elastic.co/t/elastisearch-start-java-nio-file-accessdeniedexception-etc-elasticsearch-elasticsearch-keystore/380864>\
**Category:** Elasticsearch\
**Tags:** runtime-fields\
**Created:** [August 7, 2025, 11:02am UTC](https://discuss.elastic.co/t/elastisearch-start-java-nio-file-accessdeniedexception-etc-elasticsearch-elasticsearch-keystore/380864 "2025-08-07T11:02:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Elasticisti](https://avatars.discourse-cdn.com/v4/letter/e/51bf81/32.png) [@Elasticisti](https://discuss.elastic.co/u/Elasticisti)\
**Post date:** [August 7, 2025, 11:02am UTC](https://discuss.elastic.co/t/elastisearch-start-java-nio-file-accessdeniedexception-etc-elasticsearch-elasticsearch-keystore/380864/1 "2025-08-07T11:02:45Z")

</div>

Just now I am resinstalling ELk with this

> **[Installation of ELK Stack (Kibana, Elastic search and Logstash) on Alma Linux](https://medium.com/@derricklwaga/installation-of-elk-stack-kibana-elastic-search-and-logstash-on-alma-linux-a5c9d96f2dfe)**
>
> Article 2: SECURITY OPERATIONS CENTER (SOC)

If I would like to start Elasticsearch, I receives the follwing error:

```auto
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: java.nio.file.AccessDeniedException: /etc/elasticsearch/elasticsearch.keystore
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at java.base/sun.nio.fs.UnixException.translateToIOException(UnixException.java:90)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at java.base/sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:106)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at java.base/sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:111)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at java.base/sun.nio.fs.UnixFileSystemProvider.newFileChannel(UnixFileSystemProvider.java:213)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at java.base/java.nio.channels.FileChannel.open(FileChannel.java:301)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at java.base/java.nio.channels.FileChannel.open(FileChannel.java:353)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at org.apache.lucene.store.NIOFSDirectory.openInput(NIOFSDirectory.java:78)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at org.apache.lucene.store.Directory.openChecksumInput(Directory.java:156)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at org.elasticsearch.common.settings.KeyStoreWrapper.load(KeyStoreWrapper.java:253)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at org.elasticsearch.server.cli.KeyStoreLoader.load(KeyStoreLoader.java:27)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at org.elasticsearch.server.cli.ServerCli.execute(ServerCli.java:87)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at org.elasticsearch.common.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:55)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:101)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at org.elasticsearch.cli.Command.main(Command.java:54)
Aug 07 12:34:26 ESXELX1300 systemd-entrypoint[6090]: at org.elasticsearch.launcher.CliToolLauncher.main(CliToolLauncher.java:65)
Aug 07 12:34:26 ESXELX1300 systemd[1]: elasticsearch.service: Main process exited, code=exited, status=74/IOERR

```

“Root” is owner on elasticsearch.keystore

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/7/87d44e29fd8f84d4fd6df835df03bdf9e591634b.png)

Java is installed:

```auto
[root@ESXELX1300 lib]# java -version
Picked up JAVA_TOOL_OPTIONS: -Djavax.net.ssl.trustStore=/etc/javacas/cacerts
java version "21.0.8" 2025-07-15 LTS
Java(TM) SE Runtime Environment (build 21.0.8+12-LTS-250)
Java HotSpot(TM) 64-Bit Server VM (build 21.0.8+12-LTS-250, mixed mode, sharing)

```

JAVA\_HOME is set:

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/7/27f156a62dff03178b40a5be716b3033df86dae2.png)

Do you have any idea, whet the problem can be?

EI

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [August 7, 2025, 11:56am UTC](https://discuss.elastic.co/t/elastisearch-start-java-nio-file-accessdeniedexception-etc-elasticsearch-elasticsearch-keystore/380864/2 "2025-08-07T11:56:47Z")

</div>

> [@Elasticisti](#):
>
> Do you have any idea, whet the problem can be?

The problem is incorrect file ownership/permissions. On a RHEL-like (rpm) system you should have:

```auto
$ id elasticsearch
uid=986(elasticsearch) gid=987(elasticsearch) groups=987(elasticsearch)

$ sudo ls -l /etc/elasticsearch/elasticsearch.keystore
-rw-rw----. 1 root elasticsearch 536 Jul 14 09:24 /etc/elasticsearch/elasticsearch.keystore

```

i.e. an elasticsearch user and elasticsearch group, and that specific file should be group-owned by that elasticsearch group. Your file seems group-owned by “901” which likely means something went wrong or a step was missed. But you are following a (random) 3rd party (medium) guide. I’ve nothing against that guide’s author, but a quick glance and he starts by installing a JDK:

“We will need to install Java JDK version 21, the most recent version stable release, which is required by the ELK components.”

He does not appear to notice that the JDK that elasticsearch later uses in the one that came bundled with elasticsearch itself, **not** the one he installed. That's actually not that important, not relevant to your current issue, but does show the guide is at least a little suboptimal. I’m not motivated enough to spend further time on finding where his guide _might_ be leading you astray.

IMHO you should use the official documentation. Especially if you are starting on your journey. If I were you, I'd start over, use a fresh VM, follow the official documentation. eg [here](https://www.elastic.co/docs/deploy-manage/deploy/self-managed/install-elasticsearch-with-rpm)
