# How to get certificate from Windows MY store for ES call in python

**URL:** <https://discuss.elastic.co/t/how-to-get-certificate-from-windows-my-store-for-es-call-in-python/157624>\
**Category:** Elasticsearch\
**Created:** [November 21, 2018, 5:43am UTC](https://discuss.elastic.co/t/how-to-get-certificate-from-windows-my-store-for-es-call-in-python/157624 "2018-11-21T05:43:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jthoni](https://avatars.discourse-cdn.com/v4/letter/j/b9e5f3/32.png) [@jthoni](https://discuss.elastic.co/u/jthoni)\
**Post date:** [November 21, 2018, 5:43am UTC](https://discuss.elastic.co/t/how-to-get-certificate-from-windows-my-store-for-es-call-in-python/157624/1 "2018-11-21T05:43:57Z")

</div>

We have a service that connects to Elasticsearch from C# and Python. We are using a reverse proxy with client certificate authentication. From C# we pull the certificate from the local store and include it with the request. I was never able to figure out how to do this from Python (see [Connecting to Elasticsearch via Python with SSL and client certificate --\> CERTIFICATE\_VERIFY\_FAILED](https://discuss.elastic.co/t/connecting-to-elasticsearch-via-python-with-ssl-and-client-certificate-certificate-verify-failed/86159)). I ended up storing the certificate as a pem file and reading that in on the creation of the Elasticsearch client.

I am currently tasked with moving all of our secrets (i.e. keys, certs, connection strings, etc.) out of source code. I have moved everything to Azure KeyVault except the ES client cert in Python (because we access KeyVault with a cert, which again is the same problem). I found that i am able to access the cert

```
    for cert in store.itercerts(usage=wincertstore.CLIENT_AUTH):
        if cert.get_name() == "xxx":
            cert_pem = cert.get_pem()
            file = open("esCertTest.pem", "w")
            file.write(cert_pem)
            file.close()

            return os.path.realpath(file.name)

```

This works, except... This is just the cert and does not inclde the private key, so the call to ES fails.

I need to find out one of the following:

- Can I get the private key from the cert I get from wincertstore?
- If not, by what method can I get a certificate in Python that does not involve storing any secrets in my source code?

Thanks,  
~john

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 19, 2018, 5:43am UTC](https://discuss.elastic.co/t/how-to-get-certificate-from-windows-my-store-for-es-call-in-python/157624/2 "2018-12-19T05:43:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
