# Setup Up SSL in elasticsearch error

**URL:** <https://discuss.elastic.co/t/setup-up-ssl-in-elasticsearch-error/51525>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 1, 2016, 8:33am UTC](https://discuss.elastic.co/t/setup-up-ssl-in-elasticsearch-error/51525 "2016-06-01T08:33:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chris\_wang](https://avatars.discourse-cdn.com/v4/letter/c/5fc32e/32.png) [@Chris\_wang](https://discuss.elastic.co/u/Chris_wang)\
**Post date:** [June 1, 2016, 8:33am UTC](https://discuss.elastic.co/t/setup-up-ssl-in-elasticsearch-error/51525/1 "2016-06-01T08:33:17Z")

</div>

i'm following the document to open SSL in one node of elasticsearch cluster.

i got the error message below

"Turn on TLS 1.0, TLS 1.1, and TLS 1.2 in Advanced settings and try connecting to [https://x.x.x.x:9200](https://x.x.x.x:9200) again. If this error persists, it is possible that this site uses an unsupported protocol or cipher suite such as RC4 (link for the details), which is not considered secure. Please contact your site administrator. "

in fact, i already checked TLS in browser (IE, Chrome)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 2, 2016, 12:53am UTC](https://discuss.elastic.co/t/setup-up-ssl-in-elasticsearch-error/51525/2 "2016-06-02T00:53:40Z")

</div>

Are you using Shield?

---

<div class="post-metadata">

**Author:** ![Chris\_wang](https://avatars.discourse-cdn.com/v4/letter/c/5fc32e/32.png) [@Chris\_wang](https://discuss.elastic.co/u/Chris_wang)\
**Post date:** [June 2, 2016, 1:53am UTC](https://discuss.elastic.co/t/setup-up-ssl-in-elasticsearch-error/51525/3 "2016-06-02T01:53:13Z")

</div>

yes, shield pulgin already installed

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 2, 2016, 3:27am UTC](https://discuss.elastic.co/t/setup-up-ssl-in-elasticsearch-error/51525/4 "2016-06-02T03:27:26Z")

</div>

What version of ES are you running?

---

<div class="post-metadata">

**Author:** ![Chris\_wang](https://avatars.discourse-cdn.com/v4/letter/c/5fc32e/32.png) [@Chris\_wang](https://discuss.elastic.co/u/Chris_wang)\
**Post date:** [June 2, 2016, 3:36am UTC](https://discuss.elastic.co/t/setup-up-ssl-in-elasticsearch-error/51525/5 "2016-06-02T03:36:49Z")

</div>

**es 2.1.0**

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 7, 2016, 5:28pm UTC](https://discuss.elastic.co/t/setup-up-ssl-in-elasticsearch-error/51525/6 "2016-06-07T17:28:12Z")

</div>

@Chris_wang did you get to the bottom of this?

If not, you can use nmap to see what is happening with the [ssl enum ciphers script](https://nmap.org/nsedoc/scripts/ssl-enum-ciphers.html)

```
nmap --script=ssl-enum-ciphers -p 9200 127.0.0.1

Starting Nmap 7.12 ( https://nmap.org ) at 2016-06-07 13:25 EDT
Nmap scan report for localhost (127.0.0.1)
Host is up (0.00033s latency).
PORT STATE SERVICE
9200/tcp open wap-wsp
| ssl-enum-ciphers: 
| TLSv1.0: 
| ciphers: 
| TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp160k1) - A
| TLS_RSA_WITH_AES_128_CBC_SHA (rsa 2048) - A
| compressors: 
| NULL
| cipher preference: client
| warnings: 
| Key exchange parameters of lower strength than certificate key
| TLSv1.1: 
| ciphers: 
| TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp160k1) - A
| TLS_RSA_WITH_AES_128_CBC_SHA (rsa 2048) - A
| compressors: 
| NULL
| cipher preference: client
| warnings: 
| Key exchange parameters of lower strength than certificate key
| TLSv1.2: 
| ciphers: 
| TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp160k1) - A
| TLS_RSA_WITH_AES_128_CBC_SHA (rsa 2048) - A
| TLS_RSA_WITH_AES_128_CBC_SHA256 (rsa 2048) - A
| compressors: 
| NULL
| cipher preference: client
| warnings: 
| Key exchange parameters of lower strength than certificate key
|_ least strength: A
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/setup-up-ssl-in-elasticsearch-error/51525/7 "2017-07-06T13:44:15Z")

</div>


