# SSL certificate verify failed when connecting using Route53 CNAME records

**URL:** <https://discuss.elastic.co/t/ssl-certificate-verify-failed-when-connecting-using-route53-cname-records/313648>\
**Category:** Elasticsearch\
**Created:** [September 5, 2022, 7:09am UTC](https://discuss.elastic.co/t/ssl-certificate-verify-failed-when-connecting-using-route53-cname-records/313648 "2022-09-05T07:09:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![r-uehara0219](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/r-uehara0219/32/110462_2.png) [@r-uehara0219](https://discuss.elastic.co/u/r-uehara0219)\
**Post date:** [September 5, 2022, 7:09am UTC](https://discuss.elastic.co/t/ssl-certificate-verify-failed-when-connecting-using-route53-cname-records/313648/1 "2022-09-05T07:09:51Z")

</div>

# using version

Elasticsearch 7.16.1  
curl 7.74.0

# detail

I configured traffic filters using AWS PrivateLink. (Configured with reference to [the official documentation](https://www.elastic.co/guide/en/cloud/current/ec-traffic-filtering-vpc.html).)  
I have created 2 VPC endpoints, and 2 CNAME records like these

- \*.env1.vpce.ap-northeast-1.aws.elastic-cloud.com
- \*.env2.vpce.ap-northeast-1.aws.elastic-cloud.com

Then I tried to connect to Elasticsearch with curl and got a SSL certificate verify error.

```auto
$ curl -u elastic:XXXXXXXXX -XGET 'https://my-cluster.es.env1.vpce.ap-northeast-1.aws.elastic-cloud.com/_cat/indices?v' -v
* Trying 10.XX.XXX.XXX:443...
* Connected to my-cluster.es.env1.vpce.ap-northeast-1.aws.elastic-cloud.com (10.XX.XXX.XXX) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
* CAfile: /etc/ssl/certs/ca-certificates.crt
* CApath: /etc/ssl/certs
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_128_GCM_SHA256
* ALPN, server accepted to use h2
* Server certificate:
* subject: CN=*.ap-northeast-1.aws.elastic-cloud.com
* start date: Jul 22 01:31:02 2022 GMT
* expire date: Oct 20 01:31:01 2022 GMT
* subjectAltName does not match my-cluster.es.env1.vpce.ap-northeast-1.aws.elastic-cloud.com
* SSL: no alternative certificate subject name matches target host name 'my-cluster.es.env1.vpce.ap-northeast-1.aws.elastic-cloud.com'
* Closing connection 0
* TLSv1.3 (OUT), TLS alert, close notify (256):
curl: (60) SSL: no alternative certificate subject name matches target host name 'my-cluster.es.env1.vpce.ap-northeast-1.aws.elastic-cloud.com'

```

On the other hand, if I skip the certificate verify with the -k option, the response comes back.

```auto
$ curl -k -u elastic:XXXXXXXXX -XGET 'https://my-cluster.es.env1.vpce.ap-northeast-1.aws.elastic-cloud.com/_cat/indices?v'
health status index
green open .ent-search-actastic-workplace_search_accounts_v16
...

```

For security reasons, I would like to modify the SSL communication to succeed without the k option.  
Please advise me on the configuration items that need to be corrected.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 7, 2022, 4:52am UTC](https://discuss.elastic.co/t/ssl-certificate-verify-failed-when-connecting-using-route53-cname-records/313648/3 "2022-09-07T04:52:46Z")

</div>

Hi @r-uehara0219 Welcome to the community and thanks for trying Elastic Cloud.

> [@r-uehara0219](#):
>
> \*.env1.

Quick look to me you have an extra layer of domain in you vpc endpoint url.

Perhaps take a closer [look at the docs](https://www.elastic.co/guide/en/cloud/current/ec-traffic-filtering-vpc.html#ec-aws-vpc-dns) and retry following the steps exactly and don't add another level of domain.

> Test the connection.
> 
> Find out the endpoint of your deployment. You can do that by selecting **Copy endpoint** in the Cloud UI. It looks something like `my-deployment-d53192.es.us-east-1.aws.found.io`. `my-deployment-d53192` is an alias, and `es` is the product you want to access within your deployment.
> 
> To access your Elasticsearch cluster over PrivateLink:
> 
> - If you have a [custom endpoint alias](https://www.elastic.co/guide/en/cloud/current/ec-regional-deployment-aliases.html) configured, you can use the custom endpoint URL to connect.
> - Alternatively, use the following URL structure:`https://{alias}.{product}.{private_hosted_zone_domain_name}`For example:`https://my-deployment-d53192.es.vpce.us-east-1.aws.elastic-cloud.com`

Yours looks like

`https://my-cluster.es.env1.vpce.ap-northeast-1.aws.elastic-cloud.com`

with the `.env1` in it so it is not matching the Cert CNAME.

Where it should probably look like

`https://my-cluster.es.vpce.ap-northeast-1.aws.elastic-cloud.com`

BTW you can open a support ticket since you are a Elastic Cloud Customer

---

<div class="post-metadata">

**Author:** ![r-uehara0219](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/r-uehara0219/32/110462_2.png) [@r-uehara0219](https://discuss.elastic.co/u/r-uehara0219)\
**Post date:** [September 8, 2022, 3:12am UTC](https://discuss.elastic.co/t/ssl-certificate-verify-failed-when-connecting-using-route53-cname-records/313648/4 "2022-09-08T03:12:18Z")

</div>

Thank you for your response!  
I will re-create the resource and try again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 6, 2022, 3:12am UTC](https://discuss.elastic.co/t/ssl-certificate-verify-failed-when-connecting-using-route53-cname-records/313648/5 "2022-10-06T03:12:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
