# javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate

**URL:** <https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/237674>\
**Category:** SIEM\
**Created:** [June 18, 2020, 4:07pm UTC](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/237674 "2020-06-18T16:07:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alvaro\_Sanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alvaro_sanz/32/70648_2.png) [@Alvaro\_Sanz](https://discuss.elastic.co/u/Alvaro_Sanz)\
**Post date:** [June 18, 2020, 4:07pm UTC](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/237674/1 "2020-06-18T16:07:32Z")

</div>

Hello,

Since I have enabled and made the configuration for x-pack security, the following message keeps appearing at my elasticsearch log:

```auto
javax.net.ssl.SSLHandshakeException: Received fatal alert: bad_certificate
	at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:468) ~[netty-codec-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:276) ~[netty-codec-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:377) [netty-transport-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:363) [netty-transport-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:355) [netty-transport-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1410) [netty-transport-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:377) [netty-transport-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:363) [netty-transport-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:919) [netty-transport-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:163) [netty-transport-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:714) [netty-transport-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:615) [netty-transport-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:578) [netty-transport-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:493) [netty-transport-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.util.concurrent.SingleThreadEventExecutor$4.run(SingleThreadEventExecutor.java:989) [netty-common-4.1.45.Final.jar:4.1.45.Final]
	at io.netty.util.internal.ThreadExecutorMap$2.run(ThreadExecutorMap.java:74) [netty-common-4.1.45.Final.jar:4.1.45.Final]
	at java.lang.Thread.run(Thread.java:832) [?:?]

```

Does anyone have any idea of what could be happening?

Thank you in advance.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [June 23, 2020, 3:34am UTC](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/237674/2 "2020-06-23T03:34:33Z")

</div>

I don't want to leave you hanging but that could be caused by numerous things along the way. Here is a thread that similar to this which might shed some light on what is gong on. Your best bet if you're still stuck after reading that thread is to post more information like that poster did to help try to pin point any flaws you might have in any configuration steps:

> [@Need Help with Installing Certificates into Elasticsearch](https://discuss.elastic.co/t/need-help-with-installing-certificates-into-elasticsearch/104715/6):
>
> Let me know if you need more information. I'm not trying to do anything fancy. Just connect to elasticsearch with https

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2020, 3:34am UTC](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/237674/3 "2020-07-21T03:34:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
