# /etc/elasticsearch/certs/ - 3 files

**URL:** <https://discuss.elastic.co/t/etc-elasticsearch-certs-3-files/335459>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 7, 2023, 6:15pm UTC](https://discuss.elastic.co/t/etc-elasticsearch-certs-3-files/335459 "2023-06-07T18:15:21Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Timberwolve77](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Timberwolve77](https://discuss.elastic.co/u/Timberwolve77)\
**Post date:** [June 7, 2023, 6:15pm UTC](https://discuss.elastic.co/t/etc-elasticsearch-certs-3-files/335459/1 "2023-06-07T18:15:21Z")

</div>

I saw there is a directory `/etc/elasticsearch/certs/` and inside there are three files: `http_ca.crt`, `http.p12` and `transport.p12`. What if these files were deleted? Is there a way to generate new ones?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 7, 2023, 11:53pm UTC](https://discuss.elastic.co/t/etc-elasticsearch-certs-3-files/335459/2 "2023-06-07T23:53:56Z")

</div>

Hi @Timberwolve77 Welcome to the community.

> [@Timberwolve77](#):
>
> What if these files were deleted? Is there a way to generate new ones?

Don't delete them 😉

But yes there is a quite detailed tool to recreate them.

> **[elasticsearch-certutil | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/certutil.html)**

And you would follow these instructions

> **[Set up basic security for the Elastic Stack | Elasticsearch Guide \[8.11\] |...](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup.html)**

> **[Set up basic security for the Elastic Stack plus secured HTTPS traffic |...](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup-https.html)**

And you would probably. need to fix kibana settings to if you already did automatic setup.

---

<div class="post-metadata">

**Author:** ![Timberwolve77](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Timberwolve77](https://discuss.elastic.co/u/Timberwolve77)\
**Post date:** [June 8, 2023, 1:15pm UTC](https://discuss.elastic.co/t/etc-elasticsearch-certs-3-files/335459/3 "2023-06-08T13:15:04Z")

</div>

```auto
root@elastic:/usr/share/elasticsearch/bin# ./elasticsearch-certutil http

```

## Elasticsearch HTTP Certificate Utility

The 'http' command guides you through the process of generating certificates  
for use on the HTTP (Rest) interface for Elasticsearch.

This tool will ask you a number of questions in order to generate the right  
set of files for your needs.

## Do you wish to generate a Certificate Signing Request (CSR)?

A CSR is used when you want your certificate to be created by an existing  
Certificate Authority (CA) that you do not control (that is, you don't have  
access to the keys for that CA).

If you are in a corporate environment with a central security team, then you  
may have an existing Corporate CA that can generate your certificate for you.  
Infrastructure within your organisation may already be configured to trust this  
CA, so it may be easier for clients to connect to Elasticsearch if you use a  
CSR and send that request to the team that controls your CA.

If you choose not to generate a CSR, this tool will generate a new certificate  
for you. That certificate will be signed by a CA under your control. This is a  
quick and easy way to secure your cluster with TLS, but you will need to  
configure all your clients to trust that custom CA.

```auto
Generate a CSR? [y/N]N

```

## Do you have an existing Certificate Authority (CA) key-pair that you wish to use to sign your certificate?

If you have an existing CA certificate and key, then you can use that CA to  
sign your new http certificate. This allows you to use the same CA across  
multiple Elasticsearch clusters which can make it easier to configure clients,  
and may be easier for you to manage.

If you do not have an existing CA, one will be generated for you.

```auto
Use an existing CA? [y/N]y

```

## What is the path to your CA?

Please enter the full pathname to the Certificate Authority that you wish to  
use for signing your new http certificate. This can be in PKCS#12 (.p12), JKS  
(.jks) or PEM (.crt, .key, .pem) format.

```auto
CA Path: /usr/share/elasticsearch/elastic-stack-ca.p12

```

Reading a PKCS12 keystore requires a password.  
It is possible for the keystore's password to be blank,  
in which case you can simply press at the prompt  
Password for elastic-stack-ca.p12:

I am typing the password correctly but keep receiving this error...

```auto
Exception in thread "main" org.elasticsearch.ElasticsearchException: Failed to read keystore /usr/share/elasticsearch/elastic-stack-ca.p12
        at org.elasticsearch.xpack.security.cli.HttpCertificateCommand.readKeystoreCA(HttpCertificateCommand.java:1028)
        at org.elasticsearch.xpack.security.cli.HttpCertificateCommand.findExistingCA(HttpCertificateCommand.java:816)
        at org.elasticsearch.xpack.security.cli.HttpCertificateCommand.execute(HttpCertificateCommand.java:171)
        at org.elasticsearch.common.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:54)
        at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:85)
        at org.elasticsearch.cli.MultiCommand.execute(MultiCommand.java:94)
        at org.elasticsearch.xpack.security.cli.CertificateTool.execute(CertificateTool.java:160)
        at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:85)
        at org.elasticsearch.cli.Command.main(Command.java:50)
        at org.elasticsearch.launcher.CliToolLauncher.main(CliToolLauncher.java:64)
Caused by: java.io.IOException: keystore password was incorrect
        at java.base/sun.security.pkcs12.PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2097)
        at java.base/sun.security.util.KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:228)
        at java.base/java.security.KeyStore.load(KeyStore.java:1500)
        at org.elasticsearch.common.ssl.KeyStoreUtil.readKeyStore(KeyStoreUtil.java:72)
        at org.elasticsearch.xpack.core.ssl.CertParsingUtils.readKeyPairsFromKeystore(CertParsingUtils.java:105)
        at org.elasticsearch.xpack.security.cli.HttpCertificateCommand.readKeystoreCA(HttpCertificateCommand.java:1013)
        ... 9 more
Caused by: java.security.UnrecoverableKeyException: failed to decrypt safe contents entry: javax.crypto.BadPaddingException: Given final block not properly padded. Such issues can arise if a bad key is used during decryption.
        ... 15 more
root@elastic:/usr/share/elasticsearch/bin#

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 8, 2023, 2:36pm UTC](https://discuss.elastic.co/t/etc-elasticsearch-certs-3-files/335459/4 "2023-06-08T14:36:58Z")

</div>

What version are you using?

Are there special characters in the password (should be ok)?

I just ran the process and it worked fine... with 8.8.0

Are you sure you are referencing the correct elastic-stack-ca.p12? I asked because when you ran the CA part did you give it a full path ... without it may put it in an unexpected place.

---

<div class="post-metadata">

**Author:** ![Timberwolve77](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Timberwolve77](https://discuss.elastic.co/u/Timberwolve77)\
**Post date:** [June 8, 2023, 2:42pm UTC](https://discuss.elastic.co/t/etc-elasticsearch-certs-3-files/335459/5 "2023-06-08T14:42:25Z")

</div>

What version are you using? 8.8.0

Are there special characters in the password (should be ok)? Yes.

I just ran the process and it worked fine...

Are you sure you are referencing the correct elastic-stack-ca.p12? The original is in /usr/share/elasticsearch/ and there is a copy in /etc/elasticsearch. I guess if the password is forgotten or doesn't work just recreate the ca is my guess. I appreciate your help.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 8, 2023, 2:52pm UTC](https://discuss.elastic.co/t/etc-elasticsearch-certs-3-files/335459/6 "2023-06-08T14:52:57Z")

</div>

> [@Timberwolve77](#):
>
> and there is a copy in /etc/elasticsearch

I suspect you are referencing the wrong one my suggestion always use full qualified path on create and reference. ... and yes if you forgot or lose you will need to recreate BUT typically you put that value in the elasticsearch keystore (not to be confused with the .p12 as a keystore ... to0 many uses of the word keystore)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2023, 2:53pm UTC](https://discuss.elastic.co/t/etc-elasticsearch-certs-3-files/335459/7 "2023-07-06T14:53:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
