# java.lang.IllegalArgumentException: Setting \[xpack.security.transport.ssl.keystore.path\] is a non-secure setting and must be stored inside elasticsearch.yml, but was found inside the Elasticsearch keystore

**URL:** <https://discuss.elastic.co/t/java-lang-illegalargumentexception-setting-xpack-security-transport-ssl-keystore-path-is-a-non-secure-setting-and-must-be-stored-inside-elasticsearch-yml-but-was-found-inside-the-elasticsearch-keystore/333700>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 18, 2023, 1:15am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-setting-xpack-security-transport-ssl-keystore-path-is-a-non-secure-setting-and-must-be-stored-inside-elasticsearch-yml-but-was-found-inside-the-elasticsearch-keystore/333700 "2023-05-18T01:15:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tungnx1](https://avatars.discourse-cdn.com/v4/letter/t/c0e974/32.png) [@tungnx1](https://discuss.elastic.co/u/tungnx1)\
**Post date:** [May 18, 2023, 1:15am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-setting-xpack-security-transport-ssl-keystore-path-is-a-non-secure-setting-and-must-be-stored-inside-elasticsearch-yml-but-was-found-inside-the-elasticsearch-keystore/333700/1 "2023-05-18T01:15:31Z")

</div>

Why after run:

./bin/elasticsearch-certutil http

- folder master:

```auto
total 12
-rwxr-xr-x 1 root elasticsearch 3620 May 17 17:24 http.p12
-rwxr-xr-x 1 root elasticsearch 1365 May 17 17:24 README.txt
-rwxr-xr-x 1 root elasticsearch 849 May 17 17:24 sample-elasticsearch.yml

```

-folder data:

```auto
total 12
-rwxr-xr-x 1 root elasticsearch 3620 May 17 17:24 http.p12
-rwxr-xr-x 1 root elasticsearch 1365 May 17 17:24 README.txt
-rwxr-xr-x 1 root elasticsearch 849 May 17 17:24 sample-elasticsearch.yml

```

I am copy folder data to node data in cluster and config:

Error start service:

```auto
java.lang.IllegalArgumentException: Setting [xpack.security.transport.ssl.keystore.path] is a non-secure setting and must be stored inside elasticsearch.yml, but was found inside the Elasticsearch keystore
        at org.elasticsearch.common.settings.Setting.innerGetRaw(Setting.java:597) ~[elasticsearch-8.7.0.jar:?]
        at org.elasticsearch.common.settings.Setting.getRaw(Setting.java:583) ~[elasticsearch-8.7.0.jar:?]
        at org.elasticsearch.common.settings.Setting.get(Setting.java:516) ~[elasticsearch-8.7.0.jar:?]
        at org.elasticsearch.common.settings.Setting.get(Setting.java:512) ~[elasticsearch-8.7.0.jar:?]

```

I read Elasticsearch link: [Set up basic security for the Elastic Stack plus secured HTTPS traffic | Elasticsearch Guide [8.7] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.7/security-basic-setup-https.html)

Help me !!!

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [May 29, 2023, 12:38am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-setting-xpack-security-transport-ssl-keystore-path-is-a-non-secure-setting-and-must-be-stored-inside-elasticsearch-yml-but-was-found-inside-the-elasticsearch-keystore/333700/3 "2023-05-29T00:38:18Z")

</div>

> [@tungnx1](#):
>
> `Setting [xpack.security.transport.ssl.keystore.path] is a non-secure setting and must be stored inside elasticsearch.yml, but was found inside the Elasticsearch keystore`

I think the error message is pretty clear. You need remove the said setting from the keystore file and configure it the inside `elasticsearch.yml` file.

You can remove it with

```auto
./bin/elasticsearch-keystore remove xpack.security.transport.ssl.keystore.path

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2023, 12:38am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-setting-xpack-security-transport-ssl-keystore-path-is-a-non-secure-setting-and-must-be-stored-inside-elasticsearch-yml-but-was-found-inside-the-elasticsearch-keystore/333700/4 "2023-06-26T00:38:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
