# Error "Path does not chain with any of the trust anchors" when enabling TSL between nodes

**URL:** https://discuss.elastic.co/t/error-path-does-not-chain-with-any-of-the-trust-anchors-when-enabling-tsl-between-nodes/131078
**Category:** Elasticsearch
**Created:** [May 8, 2018, 10:46pm UTC](https://discuss.elastic.co/t/error-path-does-not-chain-with-any-of-the-trust-anchors-when-enabling-tsl-between-nodes/131078 "2018-05-08T22:46:34Z")
**Posts on this page:** 1
**Showing post:** 4

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [May 9, 2018, 1:59am UTC](https://discuss.elastic.co/t/error-path-does-not-chain-with-any-of-the-trust-anchors-when-enabling-tsl-between-nodes/131078/4 "2018-05-09T01:59:46Z")

</div>

> [@mlemartien](#):
>
> Doing it separately on each node is probably what caused the different CAs... Am I on the right track?

Yes, that is correct.  
There's a few ways you can approach this, but the main options are:

- generate everything at once using `instances.yml` (on a single machine)
- explicity generate a CA, and then generate a certificate for each node using that CA (on a single machine)
- explicity generate a CA, copy it to each server (with the key), and then generate a certificate on each node using that CA. _(I'd discourage this though, because it means your CA key is copied to lots of machines and that opens up an unnecessary attack vector)_.

---

_[View the full topic](https://discuss.elastic.co/t/error-path-does-not-chain-with-any-of-the-trust-anchors-when-enabling-tsl-between-nodes/131078)._
