# Setting AWS Snapshot Repository Fails For VirtualHost

**URL:** <https://discuss.elastic.co/t/setting-aws-snapshot-repository-fails-for-virtualhost/117903>\
**Category:** Elasticsearch\
**Created:** [January 31, 2018, 8:54pm UTC](https://discuss.elastic.co/t/setting-aws-snapshot-repository-fails-for-virtualhost/117903 "2018-01-31T20:54:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Steven\_Arnott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steven_arnott/32/27218_2.png) [@Steven\_Arnott](https://discuss.elastic.co/u/Steven_Arnott)\
**Post date:** [January 31, 2018, 8:54pm UTC](https://discuss.elastic.co/t/setting-aws-snapshot-repository-fails-for-virtualhost/117903/1 "2018-01-31T20:54:50Z")

</div>

ES 5.6.3

When setting up a S3 snapshot repository, using the default endpoint works

```auto
{ "type" : "s3", "settings" : { "bucket" : "a-bucket", "region" : "us-east-1" } } 

```

However, as we are using a proxy to get to AWS, we want to use Virtual Host based so our proxy rules do not need to allow all of S3.

This does not work:

```auto
{ "type" : "s3", "settings" : { "bucket" : "a-bucket", "endpoint" : "a-bucket.s3.amazonaws.com"} } 

```

```auto
{"type":"amazon_s3_exception",
"reason":"amazon_s3_exception: The request signature we calculated does not match the signature you provided. Check your key and signing method. (Service: Amazon S3; Status Code: 403; Error Code: SignatureDoesNotMatch; Request ID: E3472D6FCF883CCE)"
}}},

```

Is there a way to enable more debuging logs for the S3 plugin, so we can dig further?

Any suggestions?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 31, 2018, 9:24pm UTC](https://discuss.elastic.co/t/setting-aws-snapshot-repository-fails-for-virtualhost/117903/2 "2018-01-31T21:24:45Z")

</div>

`endpoint` should be `us-east-1.s3.amazonaws.com` I think.

---

<div class="post-metadata">

**Author:** ![Steven\_Arnott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steven_arnott/32/27218_2.png) [@Steven\_Arnott](https://discuss.elastic.co/u/Steven_Arnott)\
**Post date:** [January 31, 2018, 9:26pm UTC](https://discuss.elastic.co/t/setting-aws-snapshot-repository-fails-for-virtualhost/117903/3 "2018-01-31T21:26:43Z")

</div>

Only if your using path based access.. this is using virtual host based where the bucket name forms part of the host.

EDIT: Oh wait your saying that having a end point means the code adds bucket to endpoint to create the host?

---

<div class="post-metadata">

**Author:** ![Steven\_Arnott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steven_arnott/32/27218_2.png) [@Steven\_Arnott](https://discuss.elastic.co/u/Steven_Arnott)\
**Post date:** [January 31, 2018, 9:37pm UTC](https://discuss.elastic.co/t/setting-aws-snapshot-repository-fails-for-virtualhost/117903/4 "2018-01-31T21:37:19Z")

</div>

OK can confirm that

```auto
    "type" : "s3",
    "settings" : {
      "bucket" : "a-bucket",
      "endpoint" : "s3.amazonaws.com"
    }
  }

```

works... I'd suggest that maybe a guided example be added to the documentation

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2018, 9:57pm UTC](https://discuss.elastic.co/t/setting-aws-snapshot-repository-fails-for-virtualhost/117903/6 "2018-02-28T21:57:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
