# Failed signature check

**URL:** https://discuss.elastic.co/t/failed-signature-check/290046
**Category:** Elastic Cloud on Kubernetes (ECK)
**Tags:** license
**Created:** [November 24, 2021, 10:58am UTC](https://discuss.elastic.co/t/failed-signature-check/290046 "2021-11-24T10:58:57Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![WookWook](https://avatars.discourse-cdn.com/v4/letter/w/54ee81/32.png) [@WookWook](https://discuss.elastic.co/u/WookWook)
#### Post date: [November 24, 2021, 10:58am UTC](https://discuss.elastic.co/t/failed-signature-check/290046/1 "2021-11-24T10:58:57Z")

</div>

Hello,

I got an extended trial license for "Elastic Cloud on Kubernetes". At least I expect the license is for that product.

Following the instructions out of the mail for ECK.

> To install the license, please follow the instructions in our documentation:
> 
> - Elastic Cloud Enterprise (ECE): [Manage licenses | Elastic Cloud Enterprise Reference [3.6] | Elastic](https://www.elastic.co/guide/en/cloud-enterprise/current/ece-add-license.html)
> 
> - Elastic Cloud on Kubernetes (ECK): [Manage licenses in ECK | Elastic Cloud on Kubernetes [2.10] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-licensing.html)
> 
> - Self-managed cluster (Stack): [License Management | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/managing-licenses.html)

I can only find this error message:

> {"log.level":"error","@timestamp":"2021-11-24T10:48:13.496Z","log.logger":"license","message":"Failed signature check","service.version":"1.8.0+4f367c38","service.type":"eck","ecs.version":"1.4.0","error":"crypto/rsa: verification error","error.stack\_trace":"[github.com/elastic/cloud-on-k8s/pkg/controller/common/license.(\*Verifier).Valid](http://github.com/elastic/cloud-on-k8s/pkg/controller/common/license.(*Verifier).Valid)\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/controller/common/license/verifier.go:35\ngithub.com/elastic/cloud-on-k8s/pkg/controller/common/license.(\*checker).Valid\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/controller/common/license/check.go:111\ngithub.com/elastic/cloud-on-k8s/pkg/controller/common/license.(\*checker).CurrentEnterpriseLicense\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/controller/common/license/check.go:77\ngithub.com/elastic/cloud-on-k8s/pkg/license.LicensingResolver.getOperatorLicense\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/license/license.go:135\ngithub.com/elastic/cloud-on-k8s/pkg/license.LicensingResolver.ToInfo\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/license/license.go:79\ngithub.com/elastic/cloud-on-k8s/pkg/license.ResourceReporter.Get\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/license/reporter.go:74\ngithub.com/elastic/cloud-on-k8s/pkg/license.ResourceReporter.Report\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/license/reporter.go:58\ngithub.com/elastic/cloud-on-k8s/pkg/license.ResourceReporter.Start\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/license/reporter.go:49\ngithub.com/elastic/cloud-on-k8s/cmd/manager.asyncTasks.func1\n\t/go/src/github.com/elastic/cloud-on-k8s/cmd/manager/main.go:612"}  
> {"log.level":"info","@timestamp":"2021-11-24T10:48:13.497Z","log.logger":"generic-reconciler","message":"Updating resource","service.version":"1.8.0+4f367c38","service.type":"eck","ecs.version":"1.4.0","kind":"ConfigMap","namespace":"elastic-system","name":"elastic-licensing"}  
> {"log.level":"error","@timestamp":"2021-11-24T10:50:13.497Z","log.logger":"license","message":"Failed signature check","service.version":"1.8.0+4f367c38","service.type":"eck","ecs.version":"1.4.0","error":"crypto/rsa: verification error","error.stack\_trace":"[github.com/elastic/cloud-on-k8s/pkg/controller/common/license.(\*Verifier).Valid](http://github.com/elastic/cloud-on-k8s/pkg/controller/common/license.(*Verifier).Valid)\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/controller/common/license/verifier.go:35\ngithub.com/elastic/cloud-on-k8s/pkg/controller/common/license.(\*checker).Valid\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/controller/common/license/check.go:111\ngithub.com/elastic/cloud-on-k8s/pkg/controller/common/license.(\*checker).CurrentEnterpriseLicense\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/controller/common/license/check.go:77\ngithub.com/elastic/cloud-on-k8s/pkg/license.LicensingResolver.getOperatorLicense\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/license/license.go:135\ngithub.com/elastic/cloud-on-k8s/pkg/license.LicensingResolver.ToInfo\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/license/license.go:79\ngithub.com/elastic/cloud-on-k8s/pkg/license.ResourceReporter.Get\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/license/reporter.go:74\ngithub.com/elastic/cloud-on-k8s/pkg/license.ResourceReporter.Report\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/license/reporter.go:58\ngithub.com/elastic/cloud-on-k8s/pkg/license.ResourceReporter.Start\n\t/go/src/github.com/elastic/cloud-on-k8s/pkg/license/reporter.go:49\ngithub.com/elastic/cloud-on-k8s/cmd/manager.asyncTasks.func1\n\t/go/src/github.com/elastic/cloud-on-k8s/cmd/manager/main.go:612"}  
> {"log.level":"info","@timestamp":"2021-11-24T10:50:13.497Z","log.logger":"generic-reconciler","message":"Updating resource","service.version":"1.8.0+4f367c38","service.type":"eck","ecs.version":"1.4.0","kind":"ConfigMap","namespace":"elastic-system","name":"elastic-licensing"}

Still on the basic license level.

kubectl -n elastic-system get configmap elastic-licensing -o json | jq .data

> {  
> "eck\_license\_level": "basic",  
> "enterprise\_resource\_units": "1",  
> "timestamp": "2021-11-22T15:28:13Z",  
> "total\_managed\_memory": "7.52GB"  
> }

Secret seems fine

```auto
> kind: Secret
> apiVersion: v1
> metadata:
> name: eck-license
> namespace: elastic-system
> selfLink: /api/v1/namespaces/elastic-system/secrets/eck-license
> uid: c89f5384-00c8-44a2-a132-5bbd415f4606
> resourceVersion: '228887552'
> creationTimestamp: '2021-11-18T09:50:39Z'
> labels:
> license.k8s.elastic.co/scope: operator
> managedFields:
> - manager: kubectl-create
> operation: Update
> apiVersion: v1
> time: '2021-11-18T09:50:39Z'
> fieldsType: FieldsV1
> fieldsV1:
> 'f:data':
> .: {}
> 'f:ngda-netzgesellschaft-deutscher-apotheker-mbh-2b4f91f2-dc5e-467f-a9e1-7121b21ac33d-non_production-stack-v7.json': {}
> 'f:type': {}
> - manager: kubectl-label
> operation: Update
> apiVersion: v1
> time: '2021-11-18T09:51:04Z'
> fieldsType: FieldsV1
> fieldsV1:
> 'f:metadata':
> 'f:labels':
> .: {}
> 'f:license.k8s.elastic.co/scope': {}
> data:
> ngda-netzgesellschaft-deutscher-apotheker-mbh-2b4f91f2-dc5e-467f-a9e1-7121b21ac33d-non_production-stack-v7.json: >-
> eyJsaWNlbnNlIjp7InVpZCI6...NjM3MTA3MjAwMDAwfX0=
> type: Opaque

```

---

<div class="post-metadata">

### Author: ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)
#### Post date: [November 25, 2021, 9:05am UTC](https://discuss.elastic.co/t/failed-signature-check/290046/3 "2021-11-25T09:05:46Z")

</div>

I think something went wrong when you created that secret. The recommended way is to use the `create secret` feature in `kubectl`

```auto
kubectl create secret generic eck-license --from-file=my-license-file.json -n elastic-system
kubectl label secret eck-license "license.k8s.elastic.co/scope"=operator -n elastic-system

```

If I look at the license you shared in your post I looks like a bit of your license was cut off at the end. `NjM3MTA3MjAwMDAwfX0=` is what you shared, when it should be `NjM3MTA3MjAwMDAwfX1dfX0=` so a few closing parentheses were cut off.

---

<div class="post-metadata">

### Author: ![WookWook](https://avatars.discourse-cdn.com/v4/letter/w/54ee81/32.png) [@WookWook](https://discuss.elastic.co/u/WookWook)
#### Post date: [November 25, 2021, 9:37am UTC](https://discuss.elastic.co/t/failed-signature-check/290046/4 "2021-11-25T09:37:55Z")

</div>

Hello Peter,

thank you for your help!

I did it with the recommended way.

The data ist 1:1 the same like in the .json if I compare it local. So I guess that is fine.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/1/915f2b54c5b8ccf84026830d3d04797f59075a58.png)

NjM3MTA3MjAwMDAwfX0=  
Did not cut off the ending. This is how it looks like in the .yaml

---

<div class="post-metadata">

### Author: ![WookWook](https://avatars.discourse-cdn.com/v4/letter/w/54ee81/32.png) [@WookWook](https://discuss.elastic.co/u/WookWook)
#### Post date: [November 25, 2021, 9:42am UTC](https://discuss.elastic.co/t/failed-signature-check/290046/5 "2021-11-25T09:42:02Z")

</div>

A bit more info.

ECK 1.8  
Elastic/Metricbeat/Kibana version 7.15.0  
Azure Redhat Openshift Cluster 4.7.x

---

<div class="post-metadata">

### Author: ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)
#### Post date: [November 25, 2021, 10:02am UTC](https://discuss.elastic.co/t/failed-signature-check/290046/6 "2021-11-25T10:02:01Z")

</div>

> [@WookWook](#):
>
> NjM3MTA3MjAwMDAwfX0=  
> Did not cut off the ending. This is how it looks like in the .yaml

That is what I mean, you are missing the closing `]}}` parentheses here. The document you have in the secret is not valid JSON. I am not sure where this got lost, maybe a copy paste mistake?

I realised too late that this is the wrong license type, this is an individual Elasticsearch cluster license but the ECK operator needs an orchestration license. You need to either download the correct type or reach out to your contact at Elastic to provide your with the correct license. Sorry about that.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 10, 2022, 12:00pm UTC](https://discuss.elastic.co/t/failed-signature-check/290046/8 "2022-01-10T12:00:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
