# "Signed fields invalid" for configuring HTTPS transport layer

**URL:** <https://discuss.elastic.co/t/signed-fields-invalid-for-configuring-https-transport-layer/262491>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 28, 2021, 11:43am UTC](https://discuss.elastic.co/t/signed-fields-invalid-for-configuring-https-transport-layer/262491 "2021-01-28T11:43:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gvx3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gvx3/32/82972_2.png) [@gvx3](https://discuss.elastic.co/u/gvx3)\
**Post date:** [January 28, 2021, 11:43am UTC](https://discuss.elastic.co/t/signed-fields-invalid-for-configuring-https-transport-layer/262491/1 "2021-01-28T11:43:16Z")

</div>

Hi all,  
I know that these kind of questions have been asking a lot, but I'm really stuck and can't help it

I'm using Helm to deploy elasticsearch, I use letsencrypt to generate cert, so I have fullchain.pem which is for certificate and privkey.pem for private key.

I copied all of them into 1 file call all.pem and mounted it into a Pod. I can see it in Pod. This is the current config

```
secretMounts:
  - name: certall
    secretName: certall
    path: /usr/share/elasticsearch/config/certs

esConfig:                                                                                                                                                                        
    elasticsearch.yml: |                                                                                                                                                           
      xpack.security.enabled: true                                                                                                                                                 
      xpack.security.transport.ssl.enabled: true                                                                                                                                   
      xpack.security.transport.ssl.key: /usr/share/elasticsearch/config/certs/all.pem                                                                                                 
      xpack.security.transport.ssl.certificate: /usr/share/elasticsearch/config/certs/all.pem   

```

The exact error I got is the CertificateParsingException  
I dont know what is wrong when it comes to certification exception, please help.  
Thanks!

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 29, 2021, 5:38am UTC](https://discuss.elastic.co/t/signed-fields-invalid-for-configuring-https-transport-layer/262491/2 "2021-01-29T05:38:54Z")

</div>

> [@gvx3](#):
>
> ```auto
> xpack.security.transport.ssl.key: /usr/share/elasticsearch/config/certs/all.pem                                                                                                 
> xpack.security.transport.ssl.certificate: /usr/share/elasticsearch/config/certs/all.pem  
> 
> ```

It looks like you have the same setting for both `key` and `certificate`.  
That's not right - you need to have the key & cert in different files.

---

<div class="post-metadata">

**Author:** ![gvx3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gvx3/32/82972_2.png) [@gvx3](https://discuss.elastic.co/u/gvx3)\
**Post date:** [January 29, 2021, 6:53am UTC](https://discuss.elastic.co/t/signed-fields-invalid-for-configuring-https-transport-layer/262491/3 "2021-01-29T06:53:01Z")

</div>

yes, I have just separated them and it's fine now, but there's 1 more problem about file read exception. I'm following this [https://discuss.elastic.co/t/trying-to-set-up-tls-on-elastic-cluster/143323/2](https://discuss.elastic.co/t/trying-to-set-up-tls-on-elastic-cluster/143323/2) article, and I am trying to find the configuration path of `es.path.conf` in this helm chart. This path `/usr/share/elasticsearch/config/` maybe not the right folder for the read permission although all files here have 777 permission. I've read the log but I haven't found the path. Do you have any idea ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2021, 6:53am UTC](https://discuss.elastic.co/t/signed-fields-invalid-for-configuring-https-transport-layer/262491/4 "2021-02-26T06:53:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
