# Need help in - TLS in elastic cluster settings

**URL:** <https://discuss.elastic.co/t/need-help-in-tls-in-elastic-cluster-settings/158502>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 28, 2018, 8:41am UTC](https://discuss.elastic.co/t/need-help-in-tls-in-elastic-cluster-settings/158502 "2018-11-28T08:41:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sl1729](https://avatars.discourse-cdn.com/v4/letter/s/ba8739/32.png) [@sl1729](https://discuss.elastic.co/u/sl1729)\
**Post date:** [November 28, 2018, 8:41am UTC](https://discuss.elastic.co/t/need-help-in-tls-in-elastic-cluster-settings/158502/1 "2018-11-28T08:41:30Z")

</div>

I am setting up a three node cluster currently, Got it working successfully without security, which I am trying currently,

From the organization I got a signed certificate on the DNS name which is load balanced externally on all three nodes. After signing I have a dns cert (with SAN updated on all three host names), intermediate cert and a root cert.

And below is my configuration on elasticsearch.yml,

```
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.key: /apps/elasticsearch/certs/node01-cert.key
xpack.security.transport.ssl.certificate: /apps/elasticsearch/certs/node01-cert.cer
xpack.security.transport.ssl.certificate_authorities: ["/apps/elasticsearch/certs/root-cert.cer"]

```

When I start the cluster I am getting below error,

`[2018-11-28T16:37:39,298][WARN][o.e.x.s.t.n.SecurityNetty4ServerTransport] [node01] client did not trust this server's certificate, closing connection NettyTcpChannel{localAddress=0.0.0.0/0.0.0.0:9300, remoteAddress=/1.1.1.1:43166}`

Can you please help in understanding against which root cert this is verified against, or any other guidance ...

Note: I do not have the CA bundle from the company

Thanks in advance.

Thanks,  
Sivakumar

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 2, 2018, 11:56pm UTC](https://discuss.elastic.co/t/need-help-in-tls-in-elastic-cluster-settings/158502/2 "2018-12-02T23:56:08Z")

</div>

> `remoteAddress=/1.1.1.1:43166`

You need to check logs from whatever is on `1.1.1.1` (I assume another node in your cluster).  
The problem is on that node

> client did not trust this server's certificate

and those logs will give you more indication about why.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2018, 11:56pm UTC](https://discuss.elastic.co/t/need-help-in-tls-in-elastic-cluster-settings/158502/3 "2018-12-30T23:56:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
