# Failed to start elasticsearch|| ssl error

**URL:** <https://discuss.elastic.co/t/failed-to-start-elasticsearch-ssl-error/381173>\
**Category:** Elasticsearch\
**Created:** [August 20, 2025, 3:21pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch-ssl-error/381173 "2025-08-20T15:21:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sreya\_14](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Post date:** [August 20, 2025, 3:21pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch-ssl-error/381173/1 "2025-08-20T15:21:56Z")

</div>

Unable to start elasticsearch

```auto
[2025-08-20T17:16:58,661][ERROR][o.e.b.Elasticsearch] [vfralapelkprd01.canoninf.net] fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: failed to load SSL configuration [xpack.security.http.ssl] - cannot read configured [PKCS12] keystore (as a truststore) [/etc/elasticsearch/certs/http.p12] - this is usually caused by an incorrect password; (a keystore password was provided)at org.elasticsearch.xpack.core.ssl.SSLService.lambda$loadSslConfigurations$11(SSLService.java:622) ~[?:?]at java.util.HashMap.forEach(HashMap.java:1430) ~[?:?]

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 20, 2025, 5:08pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch-ssl-error/381173/2 "2025-08-20T17:08:46Z")

</div>

Hi @sreya_14

If you would like help you are going to need to provide a lot more information.

The error message is self explanatory...

> [@sreya\_14](#):
>
> `cannot read configured [PKCS12] keystore (as a truststore) [/etc/elasticsearch/certs/http.p12] - this is usually caused by an incorrect password; (a keystore password was provided)`

But why is the hard part  
Often that is caused by the `elasticsearch.keystore` not being found because it was not properly populated or can not be found because elasticsearch is not bein started properly

- What Version are you running
- Exactly How did you install / configure?
- How did you create the certs?
- What did you change if anything?
- Exactly How did you start?

---

<div class="post-metadata">

**Author:** ![sreya\_14](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Post date:** [August 20, 2025, 8:25pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch-ssl-error/381173/3 "2025-08-20T20:25:30Z")

</div>

Hi Stephen,

Thanks for responding .PFB the points

What Version are you running

- Exactly How did you install / configure?–\> I have installed the stack using RPM

- How did you create the certs?using the elasticsearch-certutil

- What did you change if anything? It is newly created

- Exactly How did you start?using sudo systemctl

This is fresh installation of 8.18 v for our new OCI prod and we are using self signed certificates because the es servers are internal .Please suggest and also let me know if any more information is needed .

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 20, 2025, 11:03pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch-ssl-error/381173/4 "2025-08-20T23:03:23Z")

</div>

The error says it cannot open the cert http.p12 because it's password protected

So when you created that cer, did you provide a password? If so, you need to put that password in the elastic.keystore with the proper settings

Or you need to create a cert without a password

> **[Set up HTTPS | Elastic Docs](https://www.elastic.co/docs/deploy-manage/security/set-up-basic-security-plus-https)**
>
> Enabling TLS on the HTTP layer, widely known as HTTPS, ensures that all client communications with your cluster are encrypted, adding a critical layer...

> Add the password for your private key to the secure settings in Elasticsearch.

```auto
./bin/elasticsearch-keystore add xpack.security.http.ssl.keystore.secure_password

```

---

<div class="post-metadata">

**Author:** ![sreya\_14](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Post date:** [August 21, 2025, 6:37am UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch-ssl-error/381173/5 "2025-08-21T06:37:28Z")

</div>

Yes i have added password for this .How do I put this password now ? Can you tell what can be done from this point of error ?Do i need to generate the certificate again ? or can be solved from this point

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 21, 2025, 7:46am UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch-ssl-error/381173/6 "2025-08-21T07:46:47Z")

</div>

run this

```auto
elasticsearch-keystore show xpack.security.http.ssl.keystore.secure_password

```

If it has an error, then it probably means that you missed the step that @stephenb has advised you to take. Go back and follow his instructions.

If it worked, then copy the output and paste it into

```auto
keytool -list -keystore /etc/elasticsearch/certs/http.p12 -storepass "PASTE_PASSWORD_HERE"

```

If the password is correct it will list the keystore entries, if it is incorrect it will fail with

> keytool error: java.io.IOException: keystore password was incorrect
