# I've setup transport and http layer security but my two nodes can't detect eachother?

**URL:** <https://discuss.elastic.co/t/ive-setup-transport-and-http-layer-security-but-my-two-nodes-cant-detect-eachother/231808>\
**Category:** Elasticsearch\
**Created:** [May 8, 2020, 10:52pm UTC](https://discuss.elastic.co/t/ive-setup-transport-and-http-layer-security-but-my-two-nodes-cant-detect-eachother/231808 "2020-05-08T22:52:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![syost](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@syost](https://discuss.elastic.co/u/syost)\
**Post date:** [May 8, 2020, 10:52pm UTC](https://discuss.elastic.co/t/ive-setup-transport-and-http-layer-security-but-my-two-nodes-cant-detect-eachother/231808/1 "2020-05-08T22:52:16Z")

</div>

I'm trying to secure my cluster through the tutorial in the docs. I have two EC2 instances running. I have installed elasticsearch on both of them. I've setup transport layer and http layer security. I have started the elasticsearch service via systemctl and `systemctl status` shows they are up and running.

From the EC2 that is running my **master-node-1** I have typed the following curl command and the output is shown...

```auto
ec2-user@ip-172-32-56-218
[~] > curl -u elastic -k -XGET 'https://172.32.56.218:9200/_cluster/health?pretty'
Enter host password for user 'elastic':
{
  "cluster_name" : "elasticsearch-cluster",
  "status" : "yellow",
  "timed_out" : false,
  "number_of_nodes" : 1,
  "number_of_data_nodes" : 1,
  "active_primary_shards" : 6,
  "active_shards" : 6,
  "relocating_shards" : 0,
  "initializing_shards" : 0,
  "unassigned_shards" : 1,
  "delayed_unassigned_shards" : 0,
  "number_of_pending_tasks" : 0,
  "number_of_in_flight_fetch" : 0,
  "task_max_waiting_in_queue_millis" : 0,
  "active_shards_percent_as_number" : 85.71428571428571
}

```

You can see there's only one node!? Why isn't the other node ( **data-node-1** ) detected? The following are my two **elasticsearch.yml** configurations for each node.

**master-node-1**

```auto
cluster.name: elasticsearch-cluster                                              
node.name: master-node-1                                                         
path.data: /var/lib/elasticsearch                                                
path.logs: /var/log/elasticsearch                                                
bootstrap.memory_lock: true                                                      
network.host: 172.32.56.218                                                      
http.port: 9200                                                                  
discovery.seed_hosts: ["172.32.57.175:9200"]                                     
xpack.security.enabled: true                                                     
xpack.security.transport.ssl.enabled: true                                       
xpack.security.transport.ssl.verification_mode: full                             
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/master-node-1.p12
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/master-node-1.p12
xpack.security.http.ssl.enabled: true                                            
xpack.security.http.ssl.keystore.path: /etc/elasticsearch/certs/http.p12         
xpack.security.http.ssl.truststore.path: /etc/elasticsearch/certs/http.p12       
xpack.security.http.ssl.client_authentication: optional                          
xpack.security.authc.realms.pki.pki1:                                            
  enabled: true 

```

**data-node-1**

```auto
cluster.name: elasticsearch-cluster                                              
node.name: data-node-1                                                           
path.data: /var/lib/elasticsearch                                                
path.logs: /var/log/elasticsearch                                                
bootstrap.memory_lock: true                                                      
network.host: 172.32.57.175                                                      
http.port: 9200                                                                  
discovery.seed_hosts: ["172.32.56.218:9200"]                                     
xpack.security.enabled: true                                                     
xpack.security.transport.ssl.enabled: true                                       
xpack.security.transport.ssl.verification_mode: full                             
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/data-node-1.p12
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/data-node-1.p12                                                      
xpack.security.http.ssl.enabled: true                                            
xpack.security.http.ssl.keystore.path: /etc/elasticsearch/certs/http.p12         
xpack.security.http.ssl.truststore.path: /etc/elasticsearch/certs/http.p12       
xpack.security.http.ssl.client_authentication: optional                          
xpack.security.authc.realms.pki.pki1:                                            
  enabled: true

```

From the other EC2 instance where **data-node-1** is running I ran the following commands to see what would happen. I keep getting `security_exception` errors. Not sure if this is related but could use some tips on what to try.

```auto
ec2-user@ip-172-32-57-175
[~] > curl -k -u elastic -XGET 'https://172.32.57.175:9200/_license?pretty'
Enter host password for user 'elastic':
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "failed to authenticate user [elastic]",
        "header" : {
          "WWW-Authenticate" : [
            "Bearer realm=\"security\"",
            "ApiKey",
            "Basic realm=\"security\" charset=\"UTF-8\""
          ]
        }
      }
    ],
    "type" : "security_exception",
    "reason" : "failed to authenticate user [elastic]",
    "header" : {
      "WWW-Authenticate" : [
        "Bearer realm=\"security\"",
        "ApiKey",
        "Basic realm=\"security\" charset=\"UTF-8\""
      ]
    }
  },
  "status" : 401
}

ec2-user@ip-172-32-57-175
[~] > curl -k -XGET 'https://172.32.57.175:9200/_license?pretty'
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "missing authentication credentials for REST request [/_license?pretty]",
        "header" : {
          "WWW-Authenticate" : [
            "Bearer realm=\"security\"",
            "ApiKey",
            "Basic realm=\"security\" charset=\"UTF-8\""
          ]
        }
      }
    ],
    "type" : "security_exception",
    "reason" : "missing authentication credentials for REST request [/_license?pretty]",
    "header" : {
      "WWW-Authenticate" : [
        "Bearer realm=\"security\"",
        "ApiKey",
        "Basic realm=\"security\" charset=\"UTF-8\""
      ]
    }
  },
  "status" : 401
}

```

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 9, 2020, 1:22am UTC](https://discuss.elastic.co/t/ive-setup-transport-and-http-layer-security-but-my-two-nodes-cant-detect-eachother/231808/2 "2020-05-09T01:22:21Z")

</div>

I have 3 comments:

- with your current configuration, except if you're passing environment variables, both nodes are master eligible
- the setting `discovery.seed_hosts` requires the port 9300
- you're missing the `initial_master_nodes` setting

1. Please add to both nodes:

```auto
cluster.initial_master_nodes: 
   - master-node-1
   - data-node-1

```

Do not use the IPs on `cluster.initial_master_nodes`.

1. Change the port on `discovery.seed_hosts` to 9300.

Once you've done this please restart and if you still have issues, share the logs.

More info at [https://www.elastic.co/guide/en/elasticsearch/reference/current/discovery-settings.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/discovery-settings.html)

---

<div class="post-metadata">

**Author:** ![syost](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@syost](https://discuss.elastic.co/u/syost)\
**Post date:** [May 9, 2020, 1:36am UTC](https://discuss.elastic.co/t/ive-setup-transport-and-http-layer-security-but-my-two-nodes-cant-detect-eachother/231808/3 "2020-05-09T01:36:28Z")

</div>

@Luca_Belluccini

Are you saying that I can no longer use 9200 now? I take it that means `http.port` needs to be changed to 9300 as well then?

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 9, 2020, 3:24am UTC](https://discuss.elastic.co/t/ive-setup-transport-and-http-layer-security-but-my-two-nodes-cant-detect-eachother/231808/4 "2020-05-09T03:24:44Z")

</div>

Each Elasticsearch node requires one port to talk to each other (Transport, 9300) and the http port (9200)

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [May 9, 2020, 7:51am UTC](https://discuss.elastic.co/t/ive-setup-transport-and-http-layer-security-but-my-two-nodes-cant-detect-eachother/231808/5 "2020-05-09T07:51:51Z")

</div>

> [@Luca\_Belluccini](#):
>
> - you're missing the `initial_master_nodes` setting

I think this isn't right. From [the docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/discovery-settings.html):

> You should not use this setting when restarting a cluster or adding a new node to an existing cluster.

Since the OP has already formed a cluster and is trying to add a data-only node to it, they should not be using this setting.

I think the problem is the port in `discovery.seed_hosts` and the fact that the data node doesn't have `node.master: false`.

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 9, 2020, 8:40am UTC](https://discuss.elastic.co/t/ive-setup-transport-and-http-layer-security-but-my-two-nodes-cant-detect-eachother/231808/6 "2020-05-09T08:40:16Z")

</div>

Thank you @DavidTurner  
Right as @syost requested a data only node.

Depending on what we want to obtain, the `master-node-1` should have `node.data: false` to be a master **only** node.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2020, 8:40am UTC](https://discuss.elastic.co/t/ive-setup-transport-and-http-layer-security-but-my-two-nodes-cant-detect-eachother/231808/7 "2020-06-06T08:40:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
