# Shield Exception

**URL:** <https://discuss.elastic.co/t/shield-exception/59620>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 2, 2016, 4:29am UTC](https://discuss.elastic.co/t/shield-exception/59620 "2016-09-02T04:29:08Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kishore](https://avatars.discourse-cdn.com/v4/letter/k/8edcca/32.png) [@Kishore](https://discuss.elastic.co/u/Kishore)\
**Post date:** [September 2, 2016, 4:29am UTC](https://discuss.elastic.co/t/shield-exception/59620/1 "2016-09-02T04:29:08Z")

</div>

I have integrated Shield with Active directory, i hope i didnt miss any step but still getting below error.

_ElasticsearchException[failed to initialize a TrustManagerFactory]; nested: AccessControlException[access denied ("java.io.FilePermission" "/home/node50.jks" "read")];_

What is the fix for this?

---

<div class="post-metadata">

**Author:** ![Joshua\_Rich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_rich/32/44953_2.png) [@Joshua\_Rich](https://discuss.elastic.co/u/Joshua_Rich)\
**Post date:** [September 2, 2016, 5:55am UTC](https://discuss.elastic.co/t/shield-exception/59620/2 "2016-09-02T05:55:20Z")

</div>

It looks like whatever user your Elasticsearch process is running under does not have permission to access the keystore/truststore you have configured. Check the permissions on the `/home/node50.jks` file and ensure the Elasticsearch user has read access.

---

<div class="post-metadata">

**Author:** ![Kishore](https://avatars.discourse-cdn.com/v4/letter/k/8edcca/32.png) [@Kishore](https://discuss.elastic.co/u/Kishore)\
**Post date:** [September 2, 2016, 6:02am UTC](https://discuss.elastic.co/t/shield-exception/59620/3 "2016-09-02T06:02:35Z")

</div>

Thanks Joshua,

I had given full permissions to the file ( chmod 777 /home/node50.jks ), even though getting the error.

---

<div class="post-metadata">

**Author:** ![Joshua\_Rich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_rich/32/44953_2.png) [@Joshua\_Rich](https://discuss.elastic.co/u/Joshua_Rich)\
**Post date:** [September 2, 2016, 6:07am UTC](https://discuss.elastic.co/t/shield-exception/59620/4 "2016-09-02T06:07:16Z")

</div>

Ah right, sorry this is the security manager restricting access to a keystore/truststore not located under `<config_dir>/shield`. i.e., you need to put this file in the same directory as the other Shield config files.

---

<div class="post-metadata">

**Author:** ![Kishore](https://avatars.discourse-cdn.com/v4/letter/k/8edcca/32.png) [@Kishore](https://discuss.elastic.co/u/Kishore)\
**Post date:** [September 2, 2016, 6:18am UTC](https://discuss.elastic.co/t/shield-exception/59620/5 "2016-09-02T06:18:35Z")

</div>

It worked, but when i tried to login with my AD user getting below error:

_[2016-09-02 02:16:59,532][WARN][shield.authc.activedirectory] [aip\_ossec] authentication failed for user [kishore.uppala]: unable to authenticate user [kishore.uppala] to active directory domain [AIPTEST-MAD.AIPTEST.LOCAL]_  
_cause: com.unboundid.ldap.sdk.LDAPException: 80090308: LdapErr: DSID-0C0903CF, comment: AcceptSecurityContext error, data 52e, v2580\_emphasized text_\_

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [September 2, 2016, 11:59am UTC](https://discuss.elastic.co/t/shield-exception/59620/6 "2016-09-02T11:59:24Z")

</div>

That error indicates that the Active Directory service rejected the bind attempt due to invalid credentials. Does `kishore.uppala` exist in the `APITEST-MAD.APITEST.LOCAL` domain or does the user exist in a different domain in the forest?

---

<div class="post-metadata">

**Author:** ![imHarshj](https://avatars.discourse-cdn.com/v4/letter/i/e495f1/32.png) [@imHarshj](https://discuss.elastic.co/u/imHarshj)\
**Post date:** [October 5, 2016, 1:57pm UTC](https://discuss.elastic.co/t/shield-exception/59620/7 "2016-10-05T13:57:24Z")

</div>

I was having the same issue with Kibana. I extrapolated your solution and applied to Kibana. Moving the openSSL generated key for Kibana server to the /opt/kibana/installedPlugins/shield/ directory solved the "Permission Denied" issue on the key.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:41pm UTC](https://discuss.elastic.co/t/shield-exception/59620/8 "2017-07-06T13:41:41Z")

</div>


