# Enterprise Search

**URL:** <https://discuss.elastic.co/t/enterprise-search/262523>\
**Category:** Elastic Search\
**Created:** [January 28, 2021, 3:10pm UTC](https://discuss.elastic.co/t/enterprise-search/262523 "2021-01-28T15:10:55Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![vikram\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikram_singh/32/66490_2.png) [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Post date:** [January 28, 2021, 3:10pm UTC](https://discuss.elastic.co/t/enterprise-search/262523/1 "2021-01-28T15:10:55Z")

</div>

Hi,  
I setup a 3 node elasticsearch cluster on docker and enable xpack trial licence. Also setup enterprisesearch.  
Enterprisesearch showing running in log side but in browser side it is not opening and showing `This site can’t provide a secure connection`

After running enterprisesearch getting below details:

```auto

es_enterprise | [2021-01-28T14:49:08.823+00:00][1][2580][app-server][INFO]: Done running task: KeepFilebeatAlive
es_enterprise | [2021-01-28T14:49:08.854+00:00][1][2582][app-server][INFO]: Done running task: RefreshFritoPieContentSources
es_enterprise | [2021-01-28T14:49:08.855+00:00][1][2580][app-server][INFO]: Running task: RequeueStaleJobs
es_enterprise | [2021-01-28T14:49:08.902+00:00][1][2580][cron-Work::Cron::RequeueStaleJobs][INFO]: Performing task: RequeueStaleJobs
es_enterprise | [2021-01-28T14:49:08.934+00:00][1][2580][worker][INFO]: Updated 0 stale items from queue(s): ["connectors", "document_destroyer", "engine_destroyer", "index_adder", "indexed_doc_remover", "mailer", "refresh_document_counts", "reindexer", "schema_updater", "seed_sample_engine", "workplace_search"]
es_enterprise | [2021-01-28T14:49:08.935+00:00][1][2580][cron-Work::Cron::RequeueStaleJobs][INFO]: Done performing task: RequeueStaleJobs
es_enterprise | [2021-01-28T14:49:08.980+00:00][1][2580][app-server][INFO]: Done running task: RequeueStaleJobs
es_enterprise | [2021-01-28T14:54:08.638+00:00][1][2580][app-server][INFO]: Running task: RefreshElasticsearchLicense
es_enterprise | [2021-01-28T14:54:08.699+00:00][1][2580][cron-Work::Cron::RefreshElasticsearchLicense][INFO]: Performing task: RefreshElasticsearchLicense
es_enterprise | [2021-01-28T14:54:08.719+00:00][1][2580][cron-Work::Cron::RefreshElasticsearchLicense][INFO]: Done performing task: RefreshElasticsearchLicense
es_enterprise | [2021-01-28T14:54:08.745+00:00][1][2580][app-server][INFO]: Done running task: RefreshElasticsearchLicense
es_enterprise | [2021-01-28T14:54:08.825+00:00][1][2580][app-server][INFO]: Running task: KeepFilebeatAlive
es_enterprise | [2021-01-28T14:54:08.887+00:00][1][2580][cron-Work::Cron::KeepFilebeatAlive][INFO]: Performing task: KeepFilebeatAlive
es_enterprise | [2021-01-28T14:54:08.888+00:00][1][2580][cron-Work::Cron::KeepFilebeatAlive][INFO]: Done performing task: KeepFilebeatAlive
es_enterprise | [2021-01-28T14:54:08.933+00:00][1][2580][app-server][INFO]: Done running task: KeepFilebeatAlive
es_enterprise | [2021-01-28T14:55:08.747+00:00][1][2580][app-server][INFO]: Running task: UpdateCustomSourcesConfig
es_enterprise | [2021-01-28T14:55:08.793+00:00][1][2580][cron-Work::Cron::UpdateCustomSourcesConfig][INFO]: Performing task: UpdateCustomSourcesConfig
es_enterprise | [2021-01-28T14:55:08.797+00:00][1][2580][cron-Work::Cron::UpdateCustomSourcesConfig][INFO]: Done performing task: UpdateCustomSourcesConfig
es_enterprise | [2021-01-28T14:55:08.839+00:00][1][2580][app-server][INFO]: Done running task: UpdateCustomSourcesConfig
es_enterprise | [2021-01-28T14:55:08.856+00:00][1][2580][app-server][INFO]: Running task: RefreshFritoPieContentSources
es_enterprise | [2021-01-28T14:55:08.887+00:00][1][2580][cron-Work::Cron::RefreshFritoPieContentSources][INFO]: Performing task: RefreshFritoPieContentSources
es_enterprise | [2021-01-28T14:55:08.891+00:00][1][2580][cron-Work::Cron::RefreshFritoPieContentSources][INFO]: Done performing task: RefreshFritoPieContentSources
es_enterprise | [2021-01-28T14:55:08.917+00:00][1][2580][app-server][INFO]: Done running task: RefreshFritoPieContentSources
es_enterprise | [2021-01-28T14:55:08.982+00:00][1][2580][app-server][INFO]: Running task: RequeueStaleJobs
es_enterprise | [2021-01-28T14:55:09.027+00:00][1][2580][cron-Work::Cron::RequeueStaleJobs][INFO]: Performing task: RequeueStaleJobs
es_enterprise | [2021-01-28T14:55:09.035+00:00][1][2580][worker][INFO]: Updated 0 stale items from queue(s): ["connectors", "document_destroyer", "engine_destroyer", "index_adder", "indexed_doc_remover", "mailer", "refresh_document_counts", "reindexer", "schema_updater", "seed_sample_engine", "workplace_search"]
es_enterprise | [2021-01-28T14:55:09.035+00:00][1][2580][cron-Work::Cron::RequeueStaleJobs][INFO]: Done performing task: RequeueStaleJobs
es_enterprise | [2021-01-28T14:55:09.059+00:00][1][2580][app-server][INFO]: Done running task: RequeueStaleJobs

```

my configuration setting is:

```auto
 enterprisesearch:
    image: docker.elastic.co/enterprise-search/enterprise-search:$ELK_VERSION
    container_name: es_enterprise
    environment:
      - cluster.name=es-docker-cluster
      - node.name=enterprisesearch
      - elasticsearch.host=https://es01:9200
      - ent_search.auth.source=standard
      - elasticsearch.username=myelasticuser
      - elasticsearch.password=$ELASTIC_PASSWORD
      - allow_es_settings_modification=true
      - ent_search.external_url=https://myservername.com:3002
      - secret_management.encryption_keys=[q2cs0f128f730y3148fa137e6cc06f3617d20e170c93a11146f448e9w97fa0cf]
      - ENT_SEARCH_DEFAULT_PASSWORD=$ELASTIC_PASSWORD
      - elasticsearch.ssl.enabled=true
      - elasticsearch.ssl.verify=false
      - "JAVA_OPTS=-Xms2g -Xmx2g"
    ports:
      - "3002:3002"
    links:
      - es01
    depends_on:
      - es01
    networks:
      - elastic

```

---

<div class="post-metadata">

**Author:** ![Sean\_Story](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean_story/32/69987_2.png) [@Sean\_Story](https://discuss.elastic.co/u/Sean_Story)\
**Post date:** [January 28, 2021, 8:34pm UTC](https://discuss.elastic.co/t/enterprise-search/262523/2 "2021-01-28T20:34:37Z")

</div>

Hi @vikram_singh

I think the issue is that you've configured your `ent_search.external_url` to use SSL (`https://`), but you have not set the relevant configurations to enable SSL: [https://www.elastic.co/guide/en/enterprise-search/current/configure-ssl-tls.html](https://www.elastic.co/guide/en/enterprise-search/current/configure-ssl-tls.html)

You can either:

1. change to `http` from `https` like:

```auto
 - ent_search.external_url=http://myservername.com:3002

```

1. enable SSL with:

```auto
ent_search.ssl.enabled: true
ent_search.ssl.keystore.path: "/path/to/keystore.jks" # modify this for the right path
ent_search.ssl.keystore.password: "changeme" # modify this for the right password
ent_search.ssl.keystore.key_password: "changeme" # modify this for the right password

```

Let us know if you run into other issues!

---

<div class="post-metadata">

**Author:** ![vikram\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikram_singh/32/66490_2.png) [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Post date:** [January 29, 2021, 12:20pm UTC](https://discuss.elastic.co/t/enterprise-search/262523/3 "2021-01-29T12:20:49Z")

</div>

Hi,

I choose 2nd option and generate keystore.jks file by command:  
`keytool -genkey -alias server-alias -keyalg RSA -storepass changeme -keypass changeme -keystore keystore.jks -dname 'CN=localhost, OU=Unknown, O=Unknown, L=Unknown, ST=Unknown, C=Unknown'`  
from elasticsearch guide book  
`https://www.elastic.co/guide/en/enterprise-search/current/configure-ssl-tls.html`

And update my configuration

```auto
 enterprisesearch:
    image: docker.elastic.co/enterprise-search/enterprise-search:$ELK_VERSION
    container_name: es_enterprise
    environment:
      - cluster.name=es-docker-cluster
      - node.name=enterprisesearch
      - elasticsearch.host=https://es01:9200
      - ent_search.auth.source=standard
      - elasticsearch.username=elastic
      - elasticsearch.password=$ELASTIC_PASSWORD
      - allow_es_settings_modification=true
      - ent_search.external_url=https://myservername.com:3002
      - secret_management.encryption_keys=[q2cs0f128f730y3148fa137e6cc06f3617d20e170c93a11146f448e9w97fa0cf]
      - ENT_SEARCH_DEFAULT_PASSWORD=$ELASTIC_PASSWORD
      - elasticsearch.ssl.enabled=true
      - elasticsearch.ssl.verify=false
      - "JAVA_OPTS=-Xms2g -Xmx2g"
	  - ent_search.ssl.enabled=true
      - ent_search.ssl.keystore.path=keystore.jks
      - ent_search.ssl.keystore.password=changeme
      - ent_search.ssl.keystore.key_password=changeme
    ports:
      - "3002:3002"
    links:
      - es01
    depends_on:
      - es01
    networks:
      - elastic

```

but getting `keystore.jks` file error:

```auto
es01 is up-to-date
Recreating es_enterprise ... done
Attaching to es_enterprise
es_enterprise | Found java executable in PATH
es_enterprise | Java version detected: 1.8.0_252 (major version: 8)
es_enterprise | Enterprise Search is starting...
es_enterprise | *** [DEPRECATION WARNING] The setting '#/ent_search/auth/source' is deprecated and will be removed in version '8.0.0'. Please use the new auth config format ent_search.auth.<auth_name>.source.
es_enterprise |
es_enterprise | --------------------------------------------------------------------------------
es_enterprise |
es_enterprise | Invalid config file (/usr/share/enterprise-search/config/enterprise-search.yml):
es_enterprise | The setting '#/ent_search/ssl/keystore/path' is not valid: error reading file 'keystore.jks'
es_enterprise |
es_enterprise | --------------------------------------------------------------------------------
es_enterprise |
es_enterprise exited with code 1

```

---

<div class="post-metadata">

**Author:** ![Sean\_Story](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean_story/32/69987_2.png) [@Sean\_Story](https://discuss.elastic.co/u/Sean_Story)\
**Post date:** [January 29, 2021, 4:56pm UTC](https://discuss.elastic.co/t/enterprise-search/262523/4 "2021-01-29T16:56:14Z")

</div>

@vikram_singh can you ssh into that docker container and check that the `keystore.jks` file is there? I don't see that you've done anything to add a volume to your container.

If it is there, verify that the right user has read permissions for it? And if the permissions are sufficient, try using an absolute path, instead of a relative one?

---

<div class="post-metadata">

**Author:** ![vikram\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikram_singh/32/66490_2.png) [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Post date:** [January 29, 2021, 5:36pm UTC](https://discuss.elastic.co/t/enterprise-search/262523/5 "2021-01-29T17:36:53Z")

</div>

Hi Sean,  
After running this command  
`keytool -genkey -alias server-alias -keyalg RSA -storepass changeme -keypass changeme -keystore keystore.jks -dname 'CN=localhost, OU=Unknown, O=Unknown, L=Unknown, ST=Unknown, C=Unknown`  
A file name `keystore.jks` is created and I give it's path in configuration file (name is `elastic-docker-tls.yml`).

For file permission, current user is `elasticuser`. Below screen `keystore.jks` file is present and my configuration file is `elastic-docker-tls.yml`. I think file permission is correct.

```auto
[elasticuser@elasticsearch-centos docker-elk-masterxpack]$ ls -l
-rw-rw-r--. 1 elasticuser elasticuser 589 Jan 19 10:11 create-certs.yml
-rw-rw-r--. 1 elasticuser elasticuser 6313 Jan 29 12:12 elastic-docker-tls.yml
drwxrwxr-x. 5 elasticuser elasticuser 69 Jan 19 09:37 elasticsearch
-rw-rw-r--. 1 elasticuser elasticuser 2611 Jan 29 12:06 keystore.jks
drwxrwxr-x. 3 elasticuser elasticuser 38 Jan 28 10:55 kibana
[elasticuser@elasticsearch-centos docker-elk-masterxpack]$

```

---

<div class="post-metadata">

**Author:** ![vikram\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikram_singh/32/66490_2.png) [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Post date:** [January 29, 2021, 5:50pm UTC](https://discuss.elastic.co/t/enterprise-search/262523/6 "2021-01-29T17:50:57Z")

</div>

Hi Sean,  
For absolute path, I also tried it but getting same error.

Error:

```auto
[elasticuser@elasticsearch-centos docker-elk-masterxpack]$ docker-compose -f elastic-docker-tls.yml up enterprisesearch
es01 is up-to-date
Recreating es_enterprise ... done
Attaching to es_enterprise
es_enterprise | Found java executable in PATH
es_enterprise | Java version detected: 1.8.0_252 (major version: 8)
es_enterprise | Enterprise Search is starting...
es_enterprise | *** [DEPRECATION WARNING] The setting '#/ent_search/auth/source' is deprecated and will be removed in version '8.0.0'. Please use the new auth config format ent_search.auth.<auth_name>.source.
es_enterprise |
es_enterprise | --------------------------------------------------------------------------------
es_enterprise |
es_enterprise | Invalid config file (/usr/share/enterprise-search/config/enterprise-search.yml):
es_enterprise | The setting '#/ent_search/ssl/keystore/path' is not valid: error reading file '/home/elasticuser/mytest/docker-elk-masterxpack/keystore.jks'
es_enterprise |
es_enterprise | --------------------------------------------------------------------------------
es_enterprise |
es_enterprise exited with code 1
[elasticuser@elasticsearch-centos docker-elk-masterxpack]$

```

And configuration is:

```auto
environment:
      - cluster.name=es-docker-cluster
      - node.name=enterprisesearch
      - elasticsearch.host=https://es01:9200
      - ent_search.auth.source=standard
      - elasticsearch.username=elastic
      - elasticsearch.password=$ELASTIC_PASSWORD
      - allow_es_settings_modification=true
      - ent_search.external_url=https://myservername.com:3002
      - secret_management.encryption_keys=[q2cs0f128f730y3148fa137e6cc06f3617d20e170c93a11146f448e9w97fa0cf]
      - ENT_SEARCH_DEFAULT_PASSWORD=$ELASTIC_PASSWORD
      - elasticsearch.ssl.enabled=true
      - elasticsearch.ssl.verify=false
      - "JAVA_OPTS=-Xms2g -Xmx2g"
	  - ent_search.ssl.enabled=true
      - ent_search.ssl.keystore.path=/home/elasticuser/mytest/docker-elk-masterxpack/keystore.jks
      - ent_search.ssl.keystore.password=changeme
      - ent_search.ssl.keystore.key_password=changeme
    ports:
      - "3002:3002"
    links:
      - es01
    depends_on:
      - es01
    networks:
      - elastic

```

---

<div class="post-metadata">

**Author:** ![Sean\_Story](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean_story/32/69987_2.png) [@Sean\_Story](https://discuss.elastic.co/u/Sean_Story)\
**Post date:** [January 29, 2021, 9:30pm UTC](https://discuss.elastic.co/t/enterprise-search/262523/7 "2021-01-29T21:30:23Z")

</div>

Hi @vikram_singh ,

I think that the issue is that that file isn't on the docker container, it's in the working directory where your docker compose file is. The docker container doesn't automatically share a filesystem with the system that docker is mounted on. Some posts that might help explain this:

- [Use volumes | Docker Documentation](https://docs.docker.com/storage/volumes/)
- [How to access files outside a Docker container](https://flaviocopes.com/docker-access-files-outside-container/)

I'm not a docker expert, and am not as familiar with using `docker compose`. But when I've used `docker run` to add a volume, it's been like:

```auto
docker run -p 3002:3002 --name=workplace \
-e elasticsearch.host='http://host.docker.internal:9200' \
-e elasticsearch.username=elastic \
-e elasticsearch.password=changeme \
-e allow_es_settings_modification=true \
-e secret_management.encryption_keys='[4a2cd3f81d39bf28738c10db0ca782095ffac07279561809eecc722e0c20eb09]' \
-e ENT_SEARCH_DEFAULT_PASSWORD=changeme \
-e ent_search.listen_port=3002 \
-e ent_search.external_url='http://localhost:3002' \
-e ent_search.ssl.enabled=true \
-e ent_search.ssl.keystore.path=/usr/share/enterprise-search/keystore.jks \
-e ent_search.ssl.keystore.password=changeme \
-e ent_search.ssl.keystore.key_password=changeme \
-v /home/elasticuser/mytest/docker-elk-masterxpack:/usr/share/enterprise-search \
docker.elastic.co/enterprise-search/enterprise-search:7.10.2

```

notice in particular here the `/usr/share/enterprise-search` is where Enterprise Search is installed on the docker container's filesystem. So:

```auto
-e ent_search.ssl.keystore.path=/usr/share/enterprise-search/keystore.jks \

```

is a path to a file on the container (not on the host machine's filesystem), and

```auto
-v /home/elasticuser/mytest/docker-elk-masterxpack:/usr/share/enterprise-search \

```

tells docker that the volume should map the local `/home/elasticuser/mytest/docker-elk-masterxpack` to the container `/usr/share/enterprise-search`.  
Note that I don't know what files you have in `/home/elasticuser/mytest/docker-elk-masterxpack` other than the java keystore file, so you might want to give it its own directory if you don't want to mount a ton of other files.

Give those articles a read, and let me know if you're still having issues. We're going to get this working for you, I'm confident. 🙂

---

<div class="post-metadata">

**Author:** ![vikram\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikram_singh/32/66490_2.png) [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Post date:** [February 1, 2021, 9:17am UTC](https://discuss.elastic.co/t/enterprise-search/262523/8 "2021-02-01T09:17:46Z")

</div>

Hi Sean,  
Thanks it's working.

I change my configuration file for keystore path  
`- ent_search.ssl.keystore.path=/usr/share/enterprisesearch/keystore.jks`

and add volumes line  
`volumes: - /home/elasticuser/mytest/docker-elk-masterxpack:/usr/share/enterprisesearch`

Before doing above settings I copy keystore file from my docker-elk-masterxpack folder to /usr/share/enterprisesearch by  
` cp keystore.kjs /usr/share/enterprisesearch`

Now my configuration is:

```auto
environment:
      - cluster.name=es-docker-cluster
      - node.name=enterprisesearch
      - elasticsearch.host=https://es01:9200
      - ent_search.auth.source=standard
      - elasticsearch.username=elastic
      - elasticsearch.password=$ELASTIC_PASSWORD
      - allow_es_settings_modification=true
      - ent_search.external_url=https://myservername.com:3002
      - secret_management.encryption_keys=[q2cs0f128f730y3148fa137e6cc06f3617d20e170c93a11146f448e9w97fa0cf]
      - ENT_SEARCH_DEFAULT_PASSWORD=$ELASTIC_PASSWORD
      - elasticsearch.ssl.enabled=true
      - elasticsearch.ssl.verify=false
      - "JAVA_OPTS=-Xms2g -Xmx2g"
	  - ent_search.ssl.enabled=true
      - ent_search.ssl.keystore.path=/usr/share/enterprisesearch/keystore.jks
      - ent_search.ssl.keystore.password=changeme
      - ent_search.ssl.keystore.key_password=changeme
    ports:
      - "3002:3002"
    volumes:
      - /home/elasticuser/mytest/docker-elk-masterxpack:/usr/share/enterprisesearch
    links:
      - es01
    depends_on:
      - es01
    networks:
      - elastic

```

Now I am configuring kibana for enterprise search.  
I update my configuration  
from  
`- ent_search.auth.source=standard` to  
`- ent_search.auth.source=elasticsearch-native`

and also update my kibana.yml for `enterpriseSearch.host`

Below is kibana.yml settings

```auto
#
server.name: localhost
server.host: 0.0.0.0
elasticsearch.hosts: ["https://es01:9200"]
#monitoring.ui.container.elasticsearch.enabled: true

# For disable sandbox error
xpack.reporting.capture.browser.chromium.disableSandbox: false

# For enterprisesearch
enterpriseSearch.host: 'https://localhost:3002'

## X-Pack security credentials
#
elasticsearch.username: elastic
elasticsearch.password: $ELASTIC_PASSWORD

```

But now, when I open kibana it is showing  
`Unable to connect`  
`We can’t establish a connection to Enterprise Search at the host URL: https://localhost:3002`

I also tried with `enterpriseSearch.host: 'https://myservername.com:3002'`  
But no change in error.

---

<div class="post-metadata">

**Author:** ![Sean\_Story](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean_story/32/69987_2.png) [@Sean\_Story](https://discuss.elastic.co/u/Sean_Story)\
**Post date:** [February 2, 2021, 6:56pm UTC](https://discuss.elastic.co/t/enterprise-search/262523/9 "2021-02-02T18:56:49Z")

</div>

Docker is weird about localhost. Assuming that both your elasticsearch docker container and your enterprise search docker container are running on the same host, you should be able to use:

```auto
enterpriseSearch.host: 'https://host.docker.internal:3002'

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:22am UTC](https://discuss.elastic.co/t/enterprise-search/262523/10 "2022-11-04T08:22:46Z")

</div>


