# SOLVED : Multiple ES instances with SSL

**URL:** <https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 24, 2016, 2:50pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355 "2016-03-24T14:50:39Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Clement\_Ros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_ros/32/6198_2.png) [@Clement\_Ros](https://discuss.elastic.co/u/Clement_Ros)\
**Post date:** [March 24, 2016, 2:50pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/1 "2016-03-24T14:50:39Z")

</div>

Hi,

I have multiple instances of Elasticsearch on the same server.

I have signed my certificate with my own CA. i have created on keystore by ES instance, and in this keystore i have the root certificate, my private key, and may signed certificate.

I also had to copy the shield directory on each ES instance and make sure it had the propers rights and owner.

when i start my node i have the following error:

`[2016-03-24 15:37:28,412][ERROR][shield.transport.netty] [uat-node01] SSL/TLS handshake failed, closing channel: General SSLEngine problem`

Somebody have an idea ?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [March 24, 2016, 6:32pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/2 "2016-03-24T18:32:27Z")

</div>

Is there a caused by exception in the stacktrace? The general problem could mean a lot of different things and usually the root cause is much more helpful.

---

<div class="post-metadata">

**Author:** ![peppetrick](https://avatars.discourse-cdn.com/v4/letter/p/3d9bf3/32.png) [@peppetrick](https://discuss.elastic.co/u/peppetrick)\
**Post date:** [April 11, 2016, 4:18pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/3 "2016-04-11T16:18:06Z")

</div>

Hi have the same problem posted some day ago .. Did you solve?

---

<div class="post-metadata">

**Author:** ![Clement\_Ros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_ros/32/6198_2.png) [@Clement\_Ros](https://discuss.elastic.co/u/Clement_Ros)\
**Post date:** [April 11, 2016, 4:35pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/4 "2016-04-11T16:35:50Z")

</div>

Unfortunatly not, after many attempt we had abandoned the idea to intergrate shield with our multiple instance architecture.

But if you find one solution please share 🙂

---

<div class="post-metadata">

**Author:** ![peppetrick](https://avatars.discourse-cdn.com/v4/letter/p/3d9bf3/32.png) [@peppetrick](https://discuss.elastic.co/u/peppetrick)\
**Post date:** [April 11, 2016, 4:37pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/5 "2016-04-11T16:37:00Z")

</div>

Shure

I will play next days with it according to my spare time ..

Regards

Giuseppe

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [April 12, 2016, 11:52am UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/6 "2016-04-12T11:52:39Z")

</div>

Hi Clement,

If you provide more details we would be more than happy to try to help.

-Jay

---

<div class="post-metadata">

**Author:** ![Clement\_Ros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_ros/32/6198_2.png) [@Clement\_Ros](https://discuss.elastic.co/u/Clement_Ros)\
**Post date:** [April 12, 2016, 1:13pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/7 "2016-04-12T13:13:02Z")

</div>

Hi Jay,

We juste try to install shield following your documentation (part installing shield), We had plan to use native user authentification in a first time.  
Then we created an user.

And after all these steps, we had no restriction to access to our cluster. So we try to search during 3 days and the next weeks we decides to stop the installation of shield for the moment.

I have uninstall shield for the moment but when i will have a little time i could retry the installation and share our issues with you.

-Clément

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [April 12, 2016, 1:26pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/8 "2016-04-12T13:26:21Z")

</div>

Are you using a license already, maybe for Marvel? If so and it is a basic license, shield will not protect the cluster. You can request a trial license extension from [info@elastic.co](mailto:info@elastic.co)

---

<div class="post-metadata">

**Author:** ![Clement\_Ros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_ros/32/6198_2.png) [@Clement\_Ros](https://discuss.elastic.co/u/Clement_Ros)\
**Post date:** [April 12, 2016, 1:41pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/9 "2016-04-12T13:41:44Z")

</div>

I already use a trial license. Maybe too old ?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [April 12, 2016, 2:05pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/10 "2016-04-12T14:05:38Z")

</div>

Hmm I am not sure. You can check the status by issuing a GET on `/_license`

---

<div class="post-metadata">

**Author:** ![Clement\_Ros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_ros/32/6198_2.png) [@Clement\_Ros](https://discuss.elastic.co/u/Clement_Ros)\
**Post date:** [April 12, 2016, 2:22pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/11 "2016-04-12T14:22:27Z")

</div>

Okay my license is not trial 😅

`"status": "active", "type": "basic",`

I sent an email to the address you gave me.  
When i will have the trial license i will retry to install shield and i will tell you if its work or not.

thanks for your help 😄

---

<div class="post-metadata">

**Author:** ![Clement\_Ros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_ros/32/6198_2.png) [@Clement\_Ros](https://discuss.elastic.co/u/Clement_Ros)\
**Post date:** [April 25, 2016, 7:44am UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/12 "2016-04-25T07:44:16Z")

</div>

Hi,

I try again to install shield.

I update the license, and i have done all the first stap of the installation.

I still have a problem of authentication.

`{"error":{"root_cause":[{"type":"security_exception","reason":"unable to authenticate user [es_admin] for REST request [/]","header":{"WWW-Authenticate":"Basic realm=\"shield\""}}],"type":"security_exception","reason":"unable to authenticate user [es_admin] for REST request [/]","header":{"WWW-Authenticate":"Basic realm=\"shield\""}},"status":401}`

I think shield can't work with multi ES node on the same server by default.

My architecture is composed of 3 servers. There are 4 nodes on each servers.

The error occurred when i create the es\_admin user on my second server.

---

<div class="post-metadata">

**Author:** ![Clement\_Ros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_ros/32/6198_2.png) [@Clement\_Ros](https://discuss.elastic.co/u/Clement_Ros)\
**Post date:** [April 25, 2016, 8:10am UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/13 "2016-04-25T08:10:33Z")

</div>

After another attempt to install shield.

I can say that the error is not because of my multiple node.

The error appeared after the shield installation.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [April 25, 2016, 10:26am UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/14 "2016-04-25T10:26:10Z")

</div>

Hi Clement,

Can you provide more details about both installations? (multiple node and single node). This includes versions, how you installed (rpm/deb/tar/zip), custom configuration path, etc

Jay

---

<div class="post-metadata">

**Author:** ![Clement\_Ros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_ros/32/6198_2.png) [@Clement\_Ros](https://discuss.elastic.co/u/Clement_Ros)\
**Post date:** [April 25, 2016, 11:42am UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/15 "2016-04-25T11:42:58Z")

</div>

Thank you for the answer Jay,

I have 3 servers, the OS is CentOS 7 (v 7.2.1511).

Each server contains 4 nodes ES (v 2.2.0). 1 node is a client node, 1 node is a master node and the two others are data nodes. Each server contains also 1 redis-server (v2.8.19), logstash (v 2.2.0) and Kibana (v 4.4.0). I use keepalived to provide loadbalancing.

So i have 3 client nodes, 3 master nodes and 6 data nodes.

I installed my nodes with rpm.

For Elasticsearch the rpm commande create the directory "/etc/elasticsearch". I copied this directory in multiple directory to create each node.

To start each nodes separately, i copied the original systemd file to create 4 systemd files for each node in "/usr/lib/systemd/system/". And i changed paths to point to the correct node configuration files.

I also copied the "/etc/sysconfig/elasticsearch" file in 4 files, one for each node. And i changed the different path to point to the correct node configuration directory.

Clément

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [April 25, 2016, 11:59am UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/16 "2016-04-25T11:59:19Z")

</div>

Ok. The shield esusers script requires an option to be specified in this type of installation so that it places the files in the proper directory.

```
bin/shield/esusers useradd admin -r admin --path.conf=/path/to/configuration/directory

```

You can either run this command for each node config directory or manually copy the `users` and `users_roles` files

---

<div class="post-metadata">

**Author:** ![Clement\_Ros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_ros/32/6198_2.png) [@Clement\_Ros](https://discuss.elastic.co/u/Clement_Ros)\
**Post date:** [April 25, 2016, 12:20pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/17 "2016-04-25T12:20:10Z")

</div>

Thanks it's work for me 😀

Thank you for your time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:45pm UTC](https://discuss.elastic.co/t/solved-multiple-es-instances-with-ssl/45355/18 "2017-07-06T13:45:10Z")

</div>


