# Problem with keystore password was incorrect

**URL:** <https://discuss.elastic.co/t/problem-with-keystore-password-was-incorrect/168950>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 19, 2019, 7:21am UTC](https://discuss.elastic.co/t/problem-with-keystore-password-was-incorrect/168950 "2019-02-19T07:21:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Behzad\_Rezaie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/behzad_rezaie/32/48588_2.png) [@Behzad\_Rezaie](https://discuss.elastic.co/u/Behzad_Rezaie)\
**Post date:** [February 19, 2019, 7:21am UTC](https://discuss.elastic.co/t/problem-with-keystore-password-was-incorrect/168950/1 "2019-02-19T07:21:54Z")

</div>

Hi pals,

I have configured my elasticsearch.yml as follow:

```
xpack.security.audit.enabled: true
xpack.security.enabled: true

xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: certs/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: certs/elastic-certificates.p12

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: certs/elastic-certificates.p12
xpack.security.http.ssl.truststore.path: certs/elastic-certificates.p12
xpack.security.http.ssl.client_authentication: optional

xpack.security.authc.realms.pki1.type: pki

```

When running the elasticsearch service on Windows, I get the following error:

```
[2019-02-19T10:40:53,725][WARN][o.e.b.ElasticsearchUncaughtExceptionHandler] [Some-PC] uncaught exception in thread [main]
org.elasticsearch.bootstrap.StartupException: java.lang.IllegalStateException: failed to load plugin class [org.elasticsearch.xpack.core.XPackPlugin]
at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:140) ~[elasticsearch-6.5.4.jar:6.5.4]
.
.
.
Caused by: java.lang.IllegalStateException: failed to load plugin class [org.elasticsearch.xpack.core.XPackPlugin]
at org.elasticsearch.plugins.PluginsService.loadPlugin(PluginsService.java:607) ~[elasticsearch-6.5.4.jar:6.5.4]
.
.
.
Caused by: java.lang.reflect.InvocationTargetException
at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) ~[?:?]
at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62) ~[?:?]
.
.
.
Caused by: org.elasticsearch.ElasticsearchException: failed to initialize a TrustManagerFactory
at org.elasticsearch.xpack.core.ssl.StoreTrustConfig.createTrustManager(StoreTrustConfig.java:61) ~[?:?]
at org.elasticsearch.xpack.core.ssl.SSLService.createSslContext(SSLService.java:356) ~[?:?]
.
.
.
Caused by: java.io.IOException: keystore password was incorrect
at sun.security.pkcs12.PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2059) ~[?:?]
at java.security.KeyStore.load(KeyStore.java:1445) ~[?:1.8.0_202]
.
.
.
Caused by: java.security.UnrecoverableKeyException: failed to decrypt safe contents entry: javax.crypto.BadPaddingException: Given final block not properly padded. Such issues can arise if a bad key is used during decryption.
at sun.security.pkcs12.PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2059) ~[?:?]
at java.security.KeyStore.load(KeyStore.java:1445) ~[?:1.8.0_202]

```

Could you please let me know about the possible reason(s)?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [February 19, 2019, 7:33am UTC](https://discuss.elastic.co/t/problem-with-keystore-password-was-incorrect/168950/2 "2019-02-19T07:33:59Z")

</div>

Hi

> [@Behzad\_Rezaie](#):
>
> Could you please let me know about the possible reason(s)?

You use a keystore in your configuration

> [@Behzad\_Rezaie](#):
>
> pack.security.transport.ssl.keystore.path: certs/elastic-certificates.p12  
> xpack.security.transport.ssl.truststore.path: certs/elastic-certificates.p12  
> xpack.security.http.ssl.keystore.path: certs/elastic-certificates.p12  
> xpack.security.http.ssl.truststore.path: certs/elastic-certificates.p12

and you get an error regarding the password of that keystore

> [@Behzad\_Rezaie](#):
>
> Caused by: java.io.IOException: keystore password was incorrect at sun.security.pkcs12.PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2059) ~[?:?] at java.security.KeyStore.load(KeyStore.java:1445) ~[?:1.8.0\_202]

So it probably means that your keystore is password protected ( you specified a password when creating this with `elasticsearch-certutil` ) and you need to specify this password in your configuration too, otherwise elasticsearch cannot read the keystore to get the keys and certificates from it. How to do this is already [described in detail in our configuration](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/configuring-tls.html), see the sections that start with  
"If you secured the node’s certificate with a password..."

---

<div class="post-metadata">

**Author:** ![Behzad\_Rezaie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/behzad_rezaie/32/48588_2.png) [@Behzad\_Rezaie](https://discuss.elastic.co/u/Behzad_Rezaie)\
**Post date:** [February 19, 2019, 8:27am UTC](https://discuss.elastic.co/t/problem-with-keystore-password-was-incorrect/168950/3 "2019-02-19T08:27:20Z")

</div>

Firstly, thanks for your reply.

Secondly, I did the following commands:

```
bin/elasticsearch-keystore add xpack.security.http.ssl.keystore.secure_password

bin/elasticsearch-keystore add xpack.security.http.ssl.truststore.secure_password

bin/elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure_password

bin/elasticsearch-keystore add xpack.security.transport.ssl.truststore.secure_password

```

and set the passwords again. When running the elasticsearch with the previous mentioned config (first post), again the same error occurred!

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [February 19, 2019, 8:39am UTC](https://discuss.elastic.co/t/problem-with-keystore-password-was-incorrect/168950/4 "2019-02-19T08:39:37Z")

</div>

> [@Behzad\_Rezaie](#):
>
> When running the elasticsearch with the previous mentioned config

Did you restart elasticsearch after you added the passwords to the secure settings as you show above?

> [@Behzad\_Rezaie](#):
>
> again the same error occurred!

Please share the error logs every time, even if they look similar.

The most obvious reason is that you used the wrong password. Can you please verify that the correct password is used by running:

```auto
openssl pkcs12 -info -in /the/path/to/your/certs/elastic-certificates.p12

```

and entering the password you have configured?

---

<div class="post-metadata">

**Author:** ![Behzad\_Rezaie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/behzad_rezaie/32/48588_2.png) [@Behzad\_Rezaie](https://discuss.elastic.co/u/Behzad_Rezaie)\
**Post date:** [February 19, 2019, 9:32am UTC](https://discuss.elastic.co/t/problem-with-keystore-password-was-incorrect/168950/5 "2019-02-19T09:32:09Z")

</div>

Thanks so much for your help. I did the steps mentioned [here](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/configuring-tls.html) one-by-one from the beginning and it worked now.

---

<div class="post-metadata">

**Author:** ![prerna](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@prerna](https://discuss.elastic.co/u/prerna)\
**Post date:** [February 19, 2019, 6:58pm UTC](https://discuss.elastic.co/t/problem-with-keystore-password-was-incorrect/168950/6 "2019-02-19T18:58:36Z")

</div>

May i know what steps you tried to solve this issue, I am getting same error?  
Can you please help?

---

<div class="post-metadata">

**Author:** ![Behzad\_Rezaie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/behzad_rezaie/32/48588_2.png) [@Behzad\_Rezaie](https://discuss.elastic.co/u/Behzad_Rezaie)\
**Post date:** [February 23, 2019, 6:31am UTC](https://discuss.elastic.co/t/problem-with-keystore-password-was-incorrect/168950/7 "2019-02-23T06:31:25Z")

</div>

I, firstly, just removed all the files generated. Then ran the commands mentioned in [the article](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/configuring-tls.html) to generate the keys. The problem I had before was that after generation of the keys, I had not restarted the Elastic Search service! (Step 4 - Restart Elasticsearch)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2019, 6:33am UTC](https://discuss.elastic.co/t/problem-with-keystore-password-was-incorrect/168950/8 "2019-03-23T06:33:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
