# ES cluster with Shield - node not joining cluster

**URL:** <https://discuss.elastic.co/t/es-cluster-with-shield-node-not-joining-cluster/54799>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 6, 2016, 5:20am UTC](https://discuss.elastic.co/t/es-cluster-with-shield-node-not-joining-cluster/54799 "2016-07-06T05:20:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 6, 2016, 5:20am UTC](https://discuss.elastic.co/t/es-cluster-with-shield-node-not-joining-cluster/54799/1 "2016-07-06T05:20:09Z")

</div>

I am trying to configure 2 nodes ELK cluster with Shield plugin enabled but cluster status says its yellow.  
The version I am using is 2.3 for ELK. When I check the cluster status its NOT showing me 2 nodes where as I have configured unique cluster name. Also tried using unicast and multicast option but no luck.

The logs does not have any suspicious entries. I do see the entries on authenticated user and access granted entries. No errors or warnings.

If I put explicit node.master and node.data entries then on second node which is only data node I get following exception -

> [2016-07-06 11:46:32,053][WARN][discovery.zen.ping.unicast] [irldxvm022] failed to send ping to [{#zen\_unicast\_1#}{9.126.112.35}{9.126.112.35:9300}]  
> RemoteTransportException[[irldxvm002][9.126.112.35:9300][internal:discovery/zen/unicast]]; nested: IllegalArgumentException[tampered signed text];  
> Caused by: java.lang.IllegalArgumentException: tampered signed text

And on my first node which is explisitely configured master , I get following entries in the logs

> [2016-07-06 11:48:45,773] [irldxvm002] [transport] [tampered\_request] origin\_type=[transport], origin\_address=[9.126.112.72], action=[internal:discovery/zen/unicast]  
> [2016-07-06 11:48:47,274] [irldxvm002] [transport] [tampered\_request] origin\_type=[transport], origin\_address=[9.126.112.72], action=[internal:discovery/zen/unicast]  
> [2016-07-06 11:48:47,278] [irldxvm002] [transport] [tampered\_request] origin\_type=[transport], origin\_address=[9.126.112.72], action=[internal:discovery/zen/unicast]

Ping working from both machines as well as telnet to port 9300. Am I missing anything ?

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 6, 2016, 7:25am UTC](https://discuss.elastic.co/t/es-cluster-with-shield-node-not-joining-cluster/54799/2 "2016-07-06T07:25:36Z")

</div>

Hi ,

I could resolve this issue by removing the system key from master server. We are not using tribe nodes.

Regards,  
Vinod

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 6, 2016, 11:43am UTC](https://discuss.elastic.co/t/es-cluster-with-shield-node-not-joining-cluster/54799/3 "2016-07-06T11:43:27Z")

</div>

You need the system key on all of the nodes. Did you add it to the new node? If not, that is why the node cannot join the cluster.

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 6, 2016, 12:06pm UTC](https://discuss.elastic.co/t/es-cluster-with-shield-node-not-joining-cluster/54799/4 "2016-07-06T12:06:54Z")

</div>

Yes that is correct, the key was not there on second machine. But we are not using tribe nodes, still I should add the system key on all nodes ?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 6, 2016, 12:23pm UTC](https://discuss.elastic.co/t/es-cluster-with-shield-node-not-joining-cluster/54799/5 "2016-07-06T12:23:33Z")

</div>

Yes the system key has to be on ALL nodes as [documented](https://www.elastic.co/guide/en/shield/current/enable-message-authentication.html) otherwise they cannot communicate with each other.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/es-cluster-with-shield-node-not-joining-cluster/54799/6 "2017-07-06T13:42:57Z")

</div>


