# Master node not trusting node certificate

**URL:** <https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 22, 2022, 10:43am UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606 "2022-08-22T10:43:37Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![dabit\_coder](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dabit\_coder](https://discuss.elastic.co/u/dabit_coder)\
**Post date:** [August 22, 2022, 10:43am UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/1 "2022-08-22T10:43:38Z")

</div>

Hello,

I am writing this post as my previous post was closed by inactivity ([here)](https://discuss.elastic.co/t/cant-connect-node-to-cluster-on-another-server/309432/9)

We are trying to create a cluster with one master node and one data node. So far, we had no success in that regard because we always get some errors we are not able to fix.

Some context:

- We are using same elasticsearch version on both servers: 7.6.2
- SSL, TLS configuration has been done with this article [here](https://www.elastic.co/blog/configuring-ssl-tls-and-https-to-secure-elasticsearch-kibana-beats-and-logstash)
- Master has never belonged to another cluster

Here is what our configuration elasticsearch.yml looks like on the master node:

```auto
cluster.name: goulue
node.name: master
node.master: true

path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch

network.host: goulue.icopartners.com
http.max_content_length: 100mb

discovery.seed_hosts: ["95.179.139.6", "127.0.0.1", "goulue.icopartners.com"]

cluster.initial_master_nodes: ["master"]

xpack.license.self_generated.type: "basic"

xpack.security.enabled: true

xpack.security.http.ssl.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.http.ssl.key: certificates/master.key
xpack.security.http.ssl.certificate: certificates/master.crt
xpack.security.http.ssl.certificate_authorities: certificates/ca.crt
xpack.security.transport.ssl.key: certificates/master.key
xpack.security.transport.ssl.certificate: certificates/master.crt
xpack.security.transport.ssl.certificate_authorities: certificates/ca.crt

```

Here is the same file for our data-node

```auto

cluster.name: goulue

node.name: ico-elastic-node-2
node.data: true
node.master: false

path.data: /var/lib/elasticsearch

path.logs: /var/log/elasticsearch

network.host: goulue-node.icopartners.com

discovery.seed_hosts: ["goulue.icopartners.com"]

cluster.initial_master_nodes: ["master"]

xpack.security.enabled: true
xpack.security.http.ssl.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.http.ssl.key: certificates/ico-elastic-node-2.key
xpack.security.http.ssl.certificate: certificates/ico-elastic-node-2.crt
xpack.security.http.ssl.certificate_authorities: certificates/ca.crt
xpack.security.transport.ssl.key: certificates/ico-elastic-node-2.key
xpack.security.transport.ssl.certificate: certificates/ico-elastic-node-2.crt
xpack.security.transport.ssl.certificate_authorities: certificates/ico-elastic-node-2.crt

```

When we restart the servers, we get this error:

```auto
failed to establish trust with server at [goulue.icopartners.com]; the server provided a certificate with subject name [CN=master] and fingerprint [7ee7d7501e635ec16480c0b99641f207c465cf6c]; the certificate has subject alternative names [DNS:goulue.icopartners.com]; the certificate is issued by [CN=Elastic Certificate Tool Autogenerated CA] but the server did not provide a copy of the issuing certificate in the certificate chain; this ssl context ([xpack.security.transport.ssl]) is not configured to trust that issuer

```

Here is our instance.yml file the previous article suggest to create:

```auto
instances:
  - name: 'master'
    dns: ['goulue.icopartners.com']
  - name: "ico-elastic-node-2"
    dns: ['goulue-node.icopartners.com']

```

We tried to enable the verification\_mode: certificate on the master node but then we get this error:

```auto
[master] client did not trust this server's certificate, closing connection Netty4TcpChannel{localAddress=/95.179.140.41:9300, remoteAddress=/95.179.154.158:56350}

```

And the cluster can't be formed. What are we doing wrong? How we can fix this?

Thank you so much.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [August 23, 2022, 12:57am UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/2 "2022-08-23T00:57:38Z")

</div>

Your data node has the following setting for trust

> [@dabit\_coder](#):
>
> ```auto
> xpack.security.transport.ssl.certificate_authorities: certificates/ico-elastic-node-2.crt
> 
> ```

This is likely the problem. It is configured to trust its own certificate only. Based on your other configurations, you might want to change the value to `certificates/ca.crt`.

Also

- v7.6.2 is EOL. I highly recommend you upgrade to the latest 8.x version which has [security configured automatically](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-stack-security.html).
- For more updated instructions on how to configure security _manually_, I suggest you refer to [the documentation page](https://www.elastic.co/guide/en/elasticsearch/reference/current/manually-configure-security.html).

---

<div class="post-metadata">

**Author:** ![dabit\_coder](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dabit\_coder](https://discuss.elastic.co/u/dabit_coder)\
**Post date:** [August 23, 2022, 8:26am UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/3 "2022-08-23T08:26:51Z")

</div>

Thank you for your response. However, changing that gives us a different error this time:

```auto
 last failed join attempt was 8.7s ago, failed to join {master}{lQo0td3QSru2lZXERkLXfQ}{jXPO_Tb-TvKL5-DXhXqX4g}{goulue.icopartners.com}{95.179.140.41:9300}{dilm}{ml.machine_memory=33548009472, ml.max_open_jobs=20, xpack.installed=true} with JoinRequest{sourceNode={ico-elastic-node-2}{d6bXnIITQg6uVlDfb8VxzQ}{QA-dhNV8S2W5hgnzRdEd4g}{goulue-node.icopartners.com}{95.179.154.158:9300}{dil}{ml.machine_memory=12558602240, xpack.installed=true, ml.max_open_jobs=20}, optionalJoin=Optional.empty}

 [ico-elastic-node-2] master not discovered yet: have discovered [{ico-elastic-node-2}{d6bXnIITQg6uVlDfb8VxzQ}{QA-dhNV8S2W5hgnzRdEd4g}{goulue-node.icopartners.com}{95.179.154.158:9300}{dil}{ml.machine_memory=12558602240, xpack.installed=true, ml.max_open_jobs=20}]; discovery will continue using [95.179.140.41:9300] from hosts providers and [] from last-known cluster state; node term 147, last-accepted version 0 in term 0

```

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [August 23, 2022, 9:22am UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/4 "2022-08-23T09:22:45Z")

</div>

This error you get on data node?

---

<div class="post-metadata">

**Author:** ![dabit\_coder](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dabit\_coder](https://discuss.elastic.co/u/dabit_coder)\
**Post date:** [August 23, 2022, 9:24am UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/5 "2022-08-23T09:24:35Z")

</div>

Yes, this error is on the data node.

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [August 23, 2022, 9:25am UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/6 "2022-08-23T09:25:32Z")

</div>

Have you checked uuid of cluster on both nodes?

---

<div class="post-metadata">

**Author:** ![dabit\_coder](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dabit\_coder](https://discuss.elastic.co/u/dabit_coder)\
**Post date:** [August 23, 2022, 9:45am UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/7 "2022-08-23T09:45:27Z")

</div>

Yes, only master node has an uuid. Data node has _na_ as value of the cluster\_uuid.

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [August 23, 2022, 9:55am UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/8 "2022-08-23T09:55:11Z")

</div>

That's interesting...  
So master node was not found really.  
Please try:

```auto
cd /usr/share/elasticsearch/bin

```

```auto
sudo ./elasticsearch-node detach-cluster

```

```auto
Do you want to proceed?

Confirm [y/N] y

```

and than:

```auto
sudo systemctl start elasticsearch

```

---

<div class="post-metadata">

**Author:** ![dabit\_coder](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dabit\_coder](https://discuss.elastic.co/u/dabit_coder)\
**Post date:** [August 23, 2022, 10:01am UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/9 "2022-08-23T10:01:56Z")

</div>

I dont know what that does, but the message we get on the data node if we do that sounds unsafe.

We can't afford to lose data on the master node running this.

```auto
 This tool can cause
arbitrary data loss and its use should be your last resort.

```

---

<div class="post-metadata">

**Author:** ![dabit\_coder](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dabit\_coder](https://discuss.elastic.co/u/dabit_coder)\
**Post date:** [August 23, 2022, 2:32pm UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/10 "2022-08-23T14:32:56Z")

</div>

Hi again. Here is my full log file after we solved the certificate issue I posted previously

```auto
[2022-08-23T14:27:25,090][INFO][o.e.t.TransportService] [ico-elastic-node-2] publish_address {95.179.154.158:9300}, bound_addresses {[::]:9300}
[2022-08-23T14:27:25,347][INFO][o.e.b.BootstrapChecks] [ico-elastic-node-2] bound or publishing to a non-loopback address, enforcing bootstrap checks
[2022-08-23T14:27:35,362][WARN][o.e.c.c.ClusterFormationFailureHelper] [ico-elastic-node-2] master not discovered yet: have discovered [{ico-elastic-node-2}{RAOWxCxLRiugEl83rPZ3Mg}{jOUI2yapRL2QLm-x1bQUKA}{95.179.154.158}{95.179.154.158:9300}{dil}{ml.machine_memory=12558602240, xpack.installed=true, ml.max_open_jobs=20}, {master}{lQo0td3QSru2lZXERkLXfQ}{VIX8Mw8CQJ2h_Ag3K7S-sQ}{goulue.icopartners.com}{95.179.140.41:9300}{dilm}{ml.machine_memory=33548009472, ml.max_open_jobs=20, xpack.installed=true}]; discovery will continue using [95.179.140.41:9300] from hosts providers and [] from last-known cluster state; node term 156, last-accepted version 0 in term 0
[2022-08-23T14:27:45,365][WARN][o.e.c.c.ClusterFormationFailureHelper] [ico-elastic-node-2] master not discovered yet: have discovered [{ico-elastic-node-2}{RAOWxCxLRiugEl83rPZ3Mg}{jOUI2yapRL2QLm-x1bQUKA}{95.179.154.158}{95.179.154.158:9300}{dil}{ml.machine_memory=12558602240, xpack.installed=true, ml.max_open_jobs=20}, {master}{lQo0td3QSru2lZXERkLXfQ}{VIX8Mw8CQJ2h_Ag3K7S-sQ}{goulue.icopartners.com}{95.179.140.41:9300}{dilm}{ml.machine_memory=33548009472, ml.max_open_jobs=20, xpack.installed=true}]; discovery will continue using [95.179.140.41:9300] from hosts providers and [] from last-known cluster state; node term 156, last-accepted version 0 in term 0
[2022-08-23T14:27:55,368][WARN][o.e.c.c.ClusterFormationFailureHelper] [ico-elastic-node-2] master not discovered yet: have discovered [{ico-elastic-node-2}{RAOWxCxLRiugEl83rPZ3Mg}{jOUI2yapRL2QLm-x1bQUKA}{95.179.154.158}{95.179.154.158:9300}{dil}{ml.machine_memory=12558602240, xpack.installed=true, ml.max_open_jobs=20}, {master}{lQo0td3QSru2lZXERkLXfQ}{VIX8Mw8CQJ2h_Ag3K7S-sQ}{goulue.icopartners.com}{95.179.140.41:9300}{dilm}{ml.machine_memory=33548009472, ml.max_open_jobs=20, xpack.installed=true}]; discovery will continue using [95.179.140.41:9300] from hosts providers and [] from last-known cluster state; node term 156, last-accepted version 0 in term 0
[2022-08-23T14:27:55,371][WARN][o.e.n.Node] [ico-elastic-node-2] timed out while waiting for initial discovery state - timeout: 30s
[2022-08-23T14:27:55,394][INFO][o.e.h.AbstractHttpServerTransport] [ico-elastic-node-2] publish_address {95.179.154.158:9200}, bound_addresses {[::]:9200}
[2022-08-23T14:27:55,395][INFO][o.e.n.Node] [ico-elastic-node-2] started
[2022-08-23T14:27:55,932][INFO][o.e.c.c.JoinHelper] [ico-elastic-node-2] failed to join {master}{lQo0td3QSru2lZXERkLXfQ}{VIX8Mw8CQJ2h_Ag3K7S-sQ}{goulue.icopartners.com}{95.179.140.41:9300}{dilm}{ml.machine_memory=33548009472, ml.max_open_jobs=20, xpack.installed=true} with JoinRequest{sourceNode={ico-elastic-node-2}{RAOWxCxLRiugEl83rPZ3Mg}{jOUI2yapRL2QLm-x1bQUKA}{95.179.154.158}{95.179.154.158:9300}{dil}{ml.machine_memory=12558602240, xpack.installed=true, ml.max_open_jobs=20}, optionalJoin=Optional[Join{term=156, lastAcceptedTerm=0, lastAcceptedVersion=0, sourceNode={ico-elastic-node-2}{RAOWxCxLRiugEl83rPZ3Mg}{jOUI2yapRL2QLm-x1bQUKA}{95.179.154.158}{95.179.154.158:9300}{dil}{ml.machine_memory=12558602240, xpack.installed=true, ml.max_open_jobs=20}, targetNode={master}{lQo0td3QSru2lZXERkLXfQ}{VIX8Mw8CQJ2h_Ag3K7S-sQ}{goulue.icopartners.com}{95.179.140.41:9300}{dilm}{ml.machine_memory=33548009472, ml.max_open_jobs=20, xpack.installed=true}}]}
org.elasticsearch.transport.RemoteTransportException: [master][95.179.140.41:9300][internal:cluster/coordination/join]
Caused by: org.elasticsearch.transport.ConnectTransportException: [ico-elastic-node-2][95.179.154.158:9300] connect_timeout[30s]
        at org.elasticsearch.transport.TcpTransport$ChannelsConnectedListener.onTimeout(TcpTransport.java:995) ~[elasticsearch-7.6.2.jar:7.6.2]
        at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:633) ~[elasticsearch-7.6.2.jar:7.6.2]
        at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128) ~[?:?]
        at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628) ~[?:?]
        at java.lang.Thread.run(Thread.java:830) [?:?]
[2022-08-23T14:27:55,941][INFO][o.e.c.c.JoinHelper] [ico-elastic-node-2] failed to join {master}{lQo0td3QSru2lZXERkLXfQ}{VIX8Mw8CQJ2h_Ag3K7S-sQ}{goulue.icopartners.com}{95.179.140.41:9300}{dilm}{ml.machine_memory=33548009472, ml.max_open_jobs=20, xpack.installed=true} with JoinRequest{sourceNode={ico-elastic-node-2}{RAOWxCxLRiugEl83rPZ3Mg}{jOUI2yapRL2QLm-x1bQUKA}{95.179.154.158}{95.179.154.158:9300}{dil}{ml.machine_memory=12558602240, xpack.installed=true, ml.max_open_jobs=20}, optionalJoin=Optional[Join{term=156, lastAcceptedTerm=0, lastAcceptedVersion=0, sourceNode={ico-elastic-node-2}{RAOWxCxLRiugEl83rPZ3Mg}{jOUI2yapRL2QLm-x1bQUKA}{95.179.154.158}{95.179.154.158:9300}{dil}{ml.machine_memory=12558602240, xpack.installed=true, ml.max_open_jobs=20}, targetNode={master}{lQo0td3QSru2lZXERkLXfQ}{VIX8Mw8CQJ2h_Ag3K7S-sQ}{goulue.icopartners.com}{95.179.140.41:9300}{dilm}{ml.machine_memory=33548009472, ml.max_open_jobs=20, xpack.installed=true}}]}
org.elasticsearch.transport.RemoteTransportException: [master][95.179.140.41:9300][internal:cluster/coordination/join]
Caused by: org.elasticsearch.transport.ConnectTransportException: [ico-elastic-node-2][95.179.154.158:9300] connect_timeout[30s]
        at org.elasticsearch.transport.TcpTransport$ChannelsConnectedListener.onTimeout(TcpTransport.java:995) ~[elasticsearch-7.6.2.jar:7.6.2]
        at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:633) ~[elasticsearch-7.6.2.jar:7.6.2]
        at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128) ~[?:?]
        at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628) ~[?:?]
        at java.lang.Thread.run(Thread.java:830) [?:?]
[2022-08-23T14:28:05,370][INFO][o.e.c.c.JoinHelper] [ico-elastic-node-2] last failed join attempt was 9.4s ago, failed to join {master}{lQo0td3QSru2lZXERkLXfQ}{VIX8Mw8CQJ2h_Ag3K7S-sQ}{goulue.icopartners.com}{95.179.140.41:9300}{dilm}{ml.machine_memory=33548009472, ml.max_open_jobs=20, xpack.installed=true} with JoinRequest{sourceNode={ico-elastic-node-2}{RAOWxCxLRiugEl83rPZ3Mg}{jOUI2yapRL2QLm-x1bQUKA}{95.179.154.158}{95.179.154.158:9300}{dil}{ml.machine_memory=12558602240, xpack.installed=true, ml.max_open_jobs=20}, optionalJoin=Optional[Join{term=156, lastAcceptedTerm=0, lastAcceptedVersion=0, sourceNode={ico-elastic-node-2}{RAOWxCxLRiugEl83rPZ3Mg}{jOUI2yapRL2QLm-x1bQUKA}{95.179.154.158}{95.179.154.158:9300}{dil}{ml.machine_memory=12558602240, xpack.installed=true, ml.max_open_jobs=20}, targetNode={master}{lQo0td3QSru2lZXERkLXfQ}{VIX8Mw8CQJ2h_Ag3K7S-sQ}{goulue.icopartners.com}{95.179.140.41:9300}{dilm}{ml.machine_memory=33548009472, ml.max_open_jobs=20, xpack.installed=true}}]}
org.elasticsearch.transport.RemoteTransportException: [master][95.179.140.41:9300][internal:cluster/coordination/join]
Caused by: org.elasticsearch.transport.ConnectTransportException: [ico-elastic-node-2][95.179.154.158:9300] connect_timeout[30s]
        at org.elasticsearch.transport.TcpTransport$ChannelsConnectedListener.onTimeout(TcpTransport.java:995) ~[elasticsearch-7.6.2.jar:7.6.2]
        at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:633) ~[elasticsearch-7.6.2.jar:7.6.2]
        at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128) [?:?]
        at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628) [?:?]
        at java.lang.Thread.run(Thread.java:830) [?:?]
[2022-08-23T14:28:05,373][WARN][o.e.c.c.ClusterFormationFailureHelper] [ico-elastic-node-2] master not discovered yet: have discovered [{ico-elastic-node-2}{RAOWxCxLRiugEl83rPZ3Mg}{jOUI2yapRL2QLm-x1bQUKA}{95.179.154.158}{95.179.154.158:9300}{dil}{ml.machine_memory=12558602240, xpack.installed=true, ml.max_open_jobs=20}, {master}{lQo0td3QSru2lZXERkLXfQ}{VIX8Mw8CQJ2h_Ag3K7S-sQ}{goulue.icopartners.com}{95.179.140.41:9300}{dilm}{ml.machine_memory=33548009472, ml.max_open_jobs=20, xpack.installed=true}]; discovery will continue using [95.179.140.41:9300] from hosts providers and [] from last-known cluster state; node term 156, last-accepted version 0 in term 0

```

Could it be that some kind of connectivity issue is happening between the master and the data?

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [August 23, 2022, 2:38pm UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/11 "2022-08-23T14:38:33Z")

</div>

What port do you use for http and transport?

---

<div class="post-metadata">

**Author:** ![dabit\_coder](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dabit\_coder](https://discuss.elastic.co/u/dabit_coder)\
**Post date:** [August 23, 2022, 2:40pm UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/12 "2022-08-23T14:40:48Z")

</div>

I did not change that configuration so I guess it should be using the default 9200/9300

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [August 23, 2022, 2:42pm UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/13 "2022-08-23T14:42:05Z")

</div>

It should.  
I prefer to set it even it's going to be default value.

Error says about timeout. How about firewall? Are ports open?

---

<div class="post-metadata">

**Author:** ![dabit\_coder](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dabit\_coder](https://discuss.elastic.co/u/dabit_coder)\
**Post date:** [August 23, 2022, 2:57pm UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/14 "2022-08-23T14:57:03Z")

</div>

So I just checked and it seems that the port 9300 was not allowed on the firewall in the data-node. After unlocking that port, it seems the data-node has joined the master node!

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [August 23, 2022, 6:41pm UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/15 "2022-08-23T18:41:15Z")

</div>

That's nice. Please double check cluster uuid on both nodes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 20, 2022, 6:41pm UTC](https://discuss.elastic.co/t/master-node-not-trusting-node-certificate/312606/16 "2022-09-20T18:41:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
