# Master can not be discovered

**URL:** <https://discuss.elastic.co/t/master-can-not-be-discovered/251237>\
**Category:** Elasticsearch\
**Created:** [October 7, 2020, 8:42am UTC](https://discuss.elastic.co/t/master-can-not-be-discovered/251237 "2020-10-07T08:42:48Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![dorcas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorcas/32/71176_2.png) [@dorcas](https://discuss.elastic.co/u/dorcas)\
**Post date:** [October 7, 2020, 8:42am UTC](https://discuss.elastic.co/t/master-can-not-be-discovered/251237/1 "2020-10-07T08:42:48Z")

</div>

After i enabled  
xpack.security.enabled: true  
xpack.security.transport.ssl.enabled: true  
and i restart my two nodes i get this error  
master not discovered yet, this node has not previously joined a bootstrapped (v7+) cluster, and this node must discover master-eligible nodes [digisvcnode-1] to bootstrap a cluster: have discovered  
without this two enabled the two nodes works perfectly

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [October 7, 2020, 9:28am UTC](https://discuss.elastic.co/t/master-can-not-be-discovered/251237/2 "2020-10-07T09:28:16Z")

</div>

Please format your codes and errors under preformatted text `</>` or backticks `(```)` as sometimes it could be hard to read.

> [@dorcas](#):
>
> xpack.security.transport.ssl.enabled: true

If you set above to true, you will have to put in the certs and update elastic nodes' `hosts` with `https` including your

Below link might able to give u a better idea on where and what needs to be done:

> **[Configure TLS | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-tls.html)**

Hope this can help you!

---

<div class="post-metadata">

**Author:** ![dorcas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorcas/32/71176_2.png) [@dorcas](https://discuss.elastic.co/u/dorcas)\
**Post date:** [October 7, 2020, 1:50pm UTC](https://discuss.elastic.co/t/master-can-not-be-discovered/251237/3 "2020-10-07T13:50:05Z")

</div>

hello  
thanks for the article after setting up ssl this error pops up  
http client did not trust this server's certificate, closing connection Netty4HttpChannel

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [October 7, 2020, 1:56pm UTC](https://discuss.elastic.co/t/master-can-not-be-discovered/251237/4 "2020-10-07T13:56:24Z")

</div>

> [@dorcas](#):
>
> http client did not trust this server's certificate, closing connection Netty4HttpChannel

Where did this error shows? elasticsearch? or other components?

To have a better understanding of the issue, could you share the `elasticsearch.yml`?

format codes and errors under preformatted text `</>` or backticks `(```)` as it could be hard to read otherwise sometimes.

---

<div class="post-metadata">

**Author:** ![dorcas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorcas/32/71176_2.png) [@dorcas](https://discuss.elastic.co/u/dorcas)\
**Post date:** [October 7, 2020, 2:03pm UTC](https://discuss.elastic.co/t/master-can-not-be-discovered/251237/5 "2020-10-07T14:03:59Z")

</div>

```auto
# ======================== Elasticsearch Configuration =========================
#
# NOTE: Elasticsearch comes with reasonable defaults for most settings.
# Before you set out to tweak and tune the configuration, make sure you
# understand what are you trying to accomplish and the consequences.
#
# The primary way of configuring a node is via this file. This template lists
# the most important settings you may want to configure for a production cluster.
#
# Please consult the documentation for further information on configuration options:
# https://www.elastic.co/guide/en/elasticsearch/reference/index.html
#
# ---------------------------------- Cluster -----------------------------------
#
# Use a descriptive name for your cluster:
#
cluster.name: DigisvcElasticSearch_1
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: /etc/config/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /etc/config/elastic-certificates.p12
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: "/etc/config/http.p12"
#
# ------------------------------------ Node ------------------------------------
#
# Use a descriptive name for the node:
#
node.master: true
node.data: true
node.name: digisvcnode-1
#
# Add custom attributes to the node:
#
#node.attr.rack: r1
#
# ----------------------------------- Paths ------------------------------------
#
# Path to directory where to store the data (separate multiple locations by comma):
#
path.data: etc\data
#
# Path to log files:
#
path.logs: etc\logs
#
# ----------------------------------- Memory -----------------------------------
#
# Lock the memory on startup:
#
#bootstrap.memory_lock: true
#
# Make sure that the heap size is set to about half the memory available
# on the system and that the owner of the process is allowed to use this
# limit.
#
# Elasticsearch performs poorly when the system is swapping the memory.
#
# ---------------------------------- Network -----------------------------------
#
# Set the bind address to a specific IP (IPv4 or IPv6):
#
#transport.host: localhost 
#transport.tcp.port: 9300 
network.host: ip
#network.host: 192.168.0.1
#
# Set a custom port for HTTP:
#
http.port: port
#
# For more information, consult the network module documentation.
#
# --------------------------------- Discovery ----------------------------------
#
# Pass an initial list of hosts to perform discovery when this node is started:
# The default list of hosts is ["127.0.0.1", "[::1]"]
#
discovery.zen.minimum_master_nodes: 1
discovery.seed_hosts: ["ip"]
bootstrap.system_call_filter: false
#
# Prevent the "split brain" by configuring the majority of nodes (total number of master-eligible nodes / 2 + 1):
# 
# Bootstrap the cluster using an initial set of master-eligible nodes:
#
cluster.initial_master_nodes: ["digisvcnode-1"]
#
# For more information, consult the discovery and cluster formation module documentation.
#
# ---------------------------------- Gateway -----------------------------------
#
# Block initial recovery after a full cluster restart until N nodes are started:
#
#gateway.recover_after_nodes: 3
#
# For more information, consult the gateway module documentation.
#
# ---------------------------------- Various -----------------------------------
#
# Require explicit names when deleting indices:
#
#action.destructive_requires_name: true

```

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [October 8, 2020, 4:43am UTC](https://discuss.elastic.co/t/master-can-not-be-discovered/251237/6 "2020-10-08T04:43:11Z")

</div>

I just saw that this is a 2-node cluster, there are some recommendation from [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/high-availability-cluster-small-clusters.html#high-availability-cluster-design-two-nodes) about using 2-nodes cluster you might wanna read it up.

> [@dorcas](#):
>
> xpack.security.enabled: true  
> xpack.security.transport.ssl.enabled: true

When you turn on security and ssl, did your another node have the configured the same too?

---

<div class="post-metadata">

**Author:** ![dorcas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorcas/32/71176_2.png) [@dorcas](https://discuss.elastic.co/u/dorcas)\
**Post date:** [October 8, 2020, 10:02am UTC](https://discuss.elastic.co/t/master-can-not-be-discovered/251237/7 "2020-10-08T10:02:14Z")

</div>

i have the same security and ssl configuration for the other node

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2020, 10:02am UTC](https://discuss.elastic.co/t/master-can-not-be-discovered/251237/8 "2020-11-05T10:02:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
