# Failing to start Enterprise Search Once Adding ent\_search.ssl Configs in enterprise-search.yml

**URL:** https://discuss.elastic.co/t/failing-to-start-enterprise-search-once-adding-ent-search-ssl-configs-in-enterprise-search-yml/255245
**Category:** Elastic Search
**Created:** [November 12, 2020, 4:55pm UTC](https://discuss.elastic.co/t/failing-to-start-enterprise-search-once-adding-ent-search-ssl-configs-in-enterprise-search-yml/255245 "2020-11-12T16:55:51Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![dustan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dustan/32/78922_2.png) [@dustan](https://discuss.elastic.co/u/dustan)
#### Post date: [November 12, 2020, 4:55pm UTC](https://discuss.elastic.co/t/failing-to-start-enterprise-search-once-adding-ent-search-ssl-configs-in-enterprise-search-yml/255245/1 "2020-11-12T16:55:51Z")

</div>

Hello Guys,  
I am trying to set HTTPS in my Free Enterprise Search (Installed using .rpm in RedHat7)

(By the way I have setup Elasticsearch it is running fine using HTTPS in the same server)

Here is my enterprise-search.yml configs:

```auto
ent_search.ssl.enabled: true
ent_search.ssl.keystore.path: "certs/clientkeystore"
ent_search.ssl.keystore.password: "XXX"
ent_search.ssl.keystore.key_password: "XXX"

```

My end goal is to use App Search (i.e. that has to be accessed via port 3002 using HTTPS)

I can start enterprise-search using: `systemctl start enterprise-search`  
when I comment these ent\_search.ssl configs

Please note, I created my store key using below command:  
`keytool -keystore clientkeystore -genkey -alias client`

And stored the keystore in:  
/usr/share/enterprise-search/config/certs  
I have chown to enterprise-search

No logs in the log file  
`/var/log/enterprise-search/app-server.log`

---

<div class="post-metadata">

### Author: ![Mark\_Hoy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_hoy/32/99384_2.png) [@Mark\_Hoy](https://discuss.elastic.co/u/Mark_Hoy)
#### Post date: [November 12, 2020, 5:03pm UTC](https://discuss.elastic.co/t/failing-to-start-enterprise-search-once-adding-ent-search-ssl-configs-in-enterprise-search-yml/255245/2 "2020-11-12T17:03:35Z")

</div>

Hi Dustan -

Can you provide the version and the exact error output you receive when you try and start Enterprise Search?

Also, have you tried using the absolute path to the keystore? i.e.:

`ent_search.ssl.keystore.path: "/usr/share/enterprise-search/config/certs/clientkeystore"`

---

<div class="post-metadata">

### Author: ![dustan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dustan/32/78922_2.png) [@dustan](https://discuss.elastic.co/u/dustan)
#### Post date: [November 12, 2020, 5:07pm UTC](https://discuss.elastic.co/t/failing-to-start-enterprise-search-once-adding-ent-search-ssl-configs-in-enterprise-search-yml/255245/3 "2020-11-12T17:07:02Z")

</div>

Hello @Mark_Hoy

Version number is `7.9.2` installed using this: `enterprise-search-7.9.2.rpm` file downloaded from Elasticsearch website

No error when starting, unfortunately there is no logs written here too  
`/var/log/enterprise-search/app-server.log`

I have not tried using the absolute path,  
let me try it right now

---

<div class="post-metadata">

### Author: ![dustan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dustan/32/78922_2.png) [@dustan](https://discuss.elastic.co/u/dustan)
#### Post date: [November 13, 2020, 7:00am UTC](https://discuss.elastic.co/t/failing-to-start-enterprise-search-once-adding-ent-search-ssl-configs-in-enterprise-search-yml/255245/4 "2020-11-13T07:00:54Z")

</div>

I have tried using the absolute path, still, enterprise-search is not starting

---

<div class="post-metadata">

### Author: ![ross.bell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ross.bell/32/77559_2.png) [@ross.bell](https://discuss.elastic.co/u/ross.bell)
#### Post date: [November 13, 2020, 4:21pm UTC](https://discuss.elastic.co/t/failing-to-start-enterprise-search-once-adding-ent-search-ssl-configs-in-enterprise-search-yml/255245/5 "2020-11-13T16:21:58Z")

</div>

Hey Dustan,

I'm surprised you're not seeing any log output. Are you able to start Enterprise Search without ssl? I'm wondering if the problem isn't related to ssl. I'd also recommend testing with `7.10`, which was recently released.

---

<div class="post-metadata">

### Author: ![dustan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dustan/32/78922_2.png) [@dustan](https://discuss.elastic.co/u/dustan)
#### Post date: [November 14, 2020, 9:34am UTC](https://discuss.elastic.co/t/failing-to-start-enterprise-search-once-adding-ent-search-ssl-configs-in-enterprise-search-yml/255245/6 "2020-11-14T09:34:48Z")

</div>

Hello @ross.bell,

Yes, I am able to start Enterprise Search without ssl,

Currently, I can see logs, but 'Enterprise Search' keeps on "Starting HTTP server" after every few minutes,

Some of the logs:

```auto
#########################################################

Success! Elastic Enterprise Search is starting successfully.

In a few moments, you'll be able to login at the following address:

* URL: https://MyServerIP:3002
  * If this is your first time starting Enterprise Search, check the console output above for your user authentication credentials.
  * Visit the documentation: https://www.elastic.co/guide/en/enterprise-search

Secret session key has been generated.

Set the key in your config file to persist user sessions through process restarts:

secret_session_key: 8e9968c0d4cc6ecbc45dc20d587b88d0f6daa72485079d028848831810f5dd4496600687eaad516025811e1cead88ab2e44d37f2aea7c49a8e24a19911f87e1f

#########################################################

[2020-11-14T09:03:36.867+00:00][110101][2002][app-server][INFO]: Successfully connected to Elasticsearch

```

when trying to curl the endpoint this is the response:  
` error: ConnectionError: ('Connection aborted.', error(111, 'Connection refused')) while doing GET request to URL: https://MyServerIP:3002/`

These are SSL configs in my `/usr/share/enterprise-search/config/enterprise-search.yml` file

```auto
ent_search.ssl.enabled: true
ent_search.ssl.keystore.path: /usr/share/enterprise-search/config/certs/myCertificate.cer

```

Note, I am using the same certificate in Elasticsearch and it's running fine in HTTPS

By the way, what value should I put in this: `ent_search.listen_host: `  
I have tried both 127.0.0.1 and MyServerIP with no luck.

---

<div class="post-metadata">

### Author: ![ross.bell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ross.bell/32/77559_2.png) [@ross.bell](https://discuss.elastic.co/u/ross.bell)
#### Post date: [November 17, 2020, 7:38pm UTC](https://discuss.elastic.co/t/failing-to-start-enterprise-search-once-adding-ent-search-ssl-configs-in-enterprise-search-yml/255245/7 "2020-11-17T19:38:21Z")

</div>

Hey Dustan,

What if you try setting `log_level: debug` in the yml config? I'm hoping it can give us anything else to help debug where the failure is happening.

---

<div class="post-metadata">

### Author: ![dustan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dustan/32/78922_2.png) [@dustan](https://discuss.elastic.co/u/dustan)
#### Post date: [November 24, 2020, 3:49pm UTC](https://discuss.elastic.co/t/failing-to-start-enterprise-search-once-adding-ent-search-ssl-configs-in-enterprise-search-yml/255245/8 "2020-11-24T15:49:10Z")

</div>

Okay, @ross.bell I will try this today

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 4, 2022, 8:17am UTC](https://discuss.elastic.co/t/failing-to-start-enterprise-search-once-adding-ent-search-ssl-configs-in-enterprise-search-yml/255245/9 "2022-11-04T08:17:32Z")

</div>


