# Failed to load plugin class \[org.elasticsearch.xpack.core.XPackPlugin\]

**URL:** <https://discuss.elastic.co/t/failed-to-load-plugin-class-org-elasticsearch-xpack-core-xpackplugin/120627>\
**Category:** Elasticsearch\
**Created:** [February 20, 2018, 11:37am UTC](https://discuss.elastic.co/t/failed-to-load-plugin-class-org-elasticsearch-xpack-core-xpackplugin/120627 "2018-02-20T11:37:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sbu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sbu/32/27718_2.png) [@sbu](https://discuss.elastic.co/u/sbu)\
**Post date:** [February 20, 2018, 11:37am UTC](https://discuss.elastic.co/t/failed-to-load-plugin-class-org-elasticsearch-xpack-core-xpackplugin/120627/1 "2018-02-20T11:37:34Z")

</div>

Hi,

I'm getting **"failed to load plugin class [org.elasticsearch.xpack.core.XPackPlugin]"** and then right at the bottom of the exception I'm getting **access denied ("java.io.FilePermission" "/certs/ca/ca.crt" "read")** which is really odd because I've temporarily opened up the /certs directory permissions to 777 with a -R option, so it should be wide open for testing.

I installed the plugin using :-  
`sudo /usr/share/elasticsearch/bin/elasticsearch-plugin install x-pack`

And plugin list -v :-  
# sudo /usr/share/elasticsearch/bin/elasticsearch-plugin list -v  
Plugins directory: /usr/share/elasticsearch/plugins  
x-pack  
x-pack-core  
- Plugin information:  
Name: x-pack-core  
Description: Elasticsearch Expanded Pack Plugin - Core  
Version: 6.2.1  
Native Controller: false  
Requires Keystore: false  
Extended Plugins: []  
.... plus a whole load more.

Something awry here, but I'm not seeing it. Why would it not be able to read my certs, when the perms are wide open?

Logs here....

> <https://gist.github.com/sbutt/1737c94f505dc2f6e12162e642bc6777>

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [February 21, 2018, 10:32am UTC](https://discuss.elastic.co/t/failed-to-load-plugin-class-org-elasticsearch-xpack-core-xpackplugin/120627/2 "2018-02-21T10:32:26Z")

</div>

> [@sbu](#):
>
> "java.io.FilePermission"

Hi sbu,

This looks like java security policy which is not allowing you read access to `/certs/ca/ca.crt`  
You could modify the java security policy to add permission to /certs folder or  
you could move `/certs/*` folder to say `<ES-Home>/config/certs/*`.  
Also please update the elasticsearch.yml file after the change and restart ES.  
Hope this resolves your problem.

~  
Yogesh

---

<div class="post-metadata">

**Author:** ![sbu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sbu/32/27718_2.png) [@sbu](https://discuss.elastic.co/u/sbu)\
**Post date:** [February 21, 2018, 2:36pm UTC](https://discuss.elastic.co/t/failed-to-load-plugin-class-org-elasticsearch-xpack-core-xpackplugin/120627/3 "2018-02-21T14:36:15Z")

</div>

That's brilliant, thanks. I wasn't aware that "java security policy" was even a thing, so really useful to know. It's now reading the certificates fine, and I'm getting "client did not trust this server's certificate, closing connection" so I'll need to do some googling for that one, and perhaps come back here if I can't figure that out.

Thanks again,

Steve

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2018, 2:36pm UTC](https://discuss.elastic.co/t/failed-to-load-plugin-class-org-elasticsearch-xpack-core-xpackplugin/120627/4 "2018-03-21T14:36:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
