# SSL Certificate problem : Unable to get local issuer certificate

**URL:** <https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125>\
**Category:** Elasticsearch\
**Created:** [April 17, 2023, 12:14pm UTC](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125 "2023-04-17T12:14:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dinbabs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dinbabs/32/119905_2.png) [@dinbabs](https://discuss.elastic.co/u/dinbabs)\
**Post date:** [April 17, 2023, 12:14pm UTC](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125/1 "2023-04-17T12:14:29Z")

</div>

Hi,  
I have deployed standalone Elasticsearch in one of the VM instance of Google Cloud(GCP).

The client(Manychat) which I use to connect to Elasticsearch only supports https, so I did the configurations to run Elasticsearch port 9200 in secured mode (HTTPS).

While trying to connect I get an error **'SSL Certificate problem : Unable to get local issuer certificate'**

But unfortunately there is no provision to configure CA cert in my client(Manychat) . Also no options to disable SSL verification. When contacted Manychat customer support, they advised to turn off SSL certificate verification from Elasticsearch.

I tried with `xpack.security.http.ssl.verification_mode: none` , but it did not work.

Can you please suggest how to disable the certificate verification from Elasticsearch side?

As a note, I am able to connect successfully from postman ( by switching OFF SSL verification in settings)

Thank you for the help

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 17, 2023, 12:42pm UTC](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125/2 "2023-04-17T12:42:48Z")

</div>

Welcome!

I believe this is happening because you are using the default self-signed certificate instead of providing your own certificate. You should fix that. See [Set up basic security for the Elastic Stack plus secured HTTPS traffic | Elasticsearch Guide [8.7] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup-https.html)

Or much easier, create a [cloud.elastic.co](http://cloud.elastic.co) cluster running on GCP (or select it directly from your GCP console or from [Google Cloud Marketplace](https://console.cloud.google.com/marketplace/details/endpoints/elasticsearch-service.gcpmarketplace.elastic.co)).

---

<div class="post-metadata">

**Author:** ![dinbabs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dinbabs/32/119905_2.png) [@dinbabs](https://discuss.elastic.co/u/dinbabs)\
**Post date:** [April 17, 2023, 4:35pm UTC](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125/3 "2023-04-17T16:35:22Z")

</div>

Thank you for the quick response.

Unfortunately I cannot use elastic cloud due to budget constraint of my customer.

Will my client be able to communicate with elaticseaerch without certificate exchange if I use my own certificate?

Guess I still need to configure client certificate in Manychat client?

Please let me know if I am wrong here

Thank you

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 17, 2023, 8:09pm UTC](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125/4 "2023-04-17T20:09:57Z")

</div>

That's probably a question for Manychat.

But you can try it for free for 14 days on [cloud.elastic.co](http://cloud.elastic.co). If it works out of the box, without to specify a certificate, then you can probably reproduce this.

---

<div class="post-metadata">

**Author:** ![dinbabs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dinbabs/32/119905_2.png) [@dinbabs](https://discuss.elastic.co/u/dinbabs)\
**Post date:** [April 18, 2023, 1:18am UTC](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125/5 "2023-04-18T01:18:21Z")

</div>

Thanks a lot!  
I will take your suggestions

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2023, 1:18am UTC](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125/6 "2023-05-16T01:18:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
