# SSL Communication Client and Cluster Error

**URL:** <https://discuss.elastic.co/t/ssl-communication-client-and-cluster-error/120607>\
**Category:** Elasticsearch\
**Created:** [February 20, 2018, 10:48am UTC](https://discuss.elastic.co/t/ssl-communication-client-and-cluster-error/120607 "2018-02-20T10:48:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![vigneshaj](https://avatars.discourse-cdn.com/v4/letter/v/0ea827/32.png) [@vigneshaj](https://discuss.elastic.co/u/vigneshaj)\
**Post date:** [February 20, 2018, 10:48am UTC](https://discuss.elastic.co/t/ssl-communication-client-and-cluster-error/120607/1 "2018-02-20T10:48:43Z")

</div>

I have a cluster with 2 nodes one master and one data.  
Elastic with x-pack has been installed.  
Authentication LDAP is setup  
Internode communication has been encrypted, which is again successful.

Successful:  
xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.keystore.path: /usr/share/elasticsearch/bin/x-pack/elastic-certificates.p12  
xpack.security.transport.ssl.truststore.path: /usr/share/elasticsearch/bin/x-pack/elastic-certificates.p12

Unsuccessful: [SSL configuration between HTTP client [browser] and cluster]

xpack.security.http.ssl.enabled: true  
xpack.security.http.ssl.keystore.path: /usr/share/elasticsearch/bin/x-pack/elastic-certificates.p12  
xpack.security.http.ssl.truststore.path: /usr/share/elasticsearch/bin/x-pack/elastic-certificates.p12

On restarting both the nodes, I don’t see any error --- but when I try [https://XX.XX.XXX.XXX:9200](https://XX.XX.XXX.XXX:9200) I get the below screen.

 ![error](https://us1.discourse-cdn.com/elastic/original/3X/2/6/26cbaff25ed8141b297e3836d8afba76fee30bd3.png)

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [February 20, 2018, 1:01pm UTC](https://discuss.elastic.co/t/ssl-communication-client-and-cluster-error/120607/2 "2018-02-20T13:01:24Z")

</div>

Hi Aj Vignesh,

I assume you are using certificates generated by using certutil script. By default, these are the self-signed certificate, auto-generated CA certificates. This is the reason for the error in the browser. By default browser do not trust these.

In production environments, you would use a certificate which is signed by a public trusted CAs like Symantec, Verisign, Thwate etc. or you could install the CA certificate in the browser that you trust.  
certutil allows you to generate csr (certificate signing request) and then you can get the signed certificate from above mentioned trusted CAs.

Refer for more info:

> **[Self-Signed SSL Vs Trusted CA Signed SSL Certificate](https://cheapsslsecurity.com/blog/self-signed-ssl-versus-trusted-ca-signed-ssl-certificate/)**
>
> Self-Signed SSL Vs Trusted CA Signed SSL Certificate, Learn the actual difference between a Self signed SSL certificate and Trust Certificate Authority.

~  
Yogesh

---

<div class="post-metadata">

**Author:** ![Aby](https://avatars.discourse-cdn.com/v4/letter/a/a88e57/32.png) [@Aby](https://discuss.elastic.co/u/Aby)\
**Post date:** [February 21, 2018, 7:01am UTC](https://discuss.elastic.co/t/ssl-communication-client-and-cluster-error/120607/3 "2018-02-21T07:01:29Z")

</div>

Thanks, After setting up the below configuration:

Note: Trusted CA was generated in base 64 encoded .cer file and i converted to crt format.

xpack.ssl.key: /usr/share/elasticsearch/bin/x-pack/certificate.demo.key  
xpack.ssl.certificate: /usr/share/elasticsearch/bin/x-pack/certificate.crt  
xpack.ssl.certificate\_authorities: ["/usr/share/elasticsearch/bin/x-pack/certificateca.crt"]

xpack.security.http.ssl.enabled: true

and then restarting the node i get the below issue..

[2018-02-21T06:48:57,126][ERROR][o.e.b.Bootstrap] Exception  
java.lang.IllegalStateException: failed to load plugin class [org.elasticsearch.xpack.XPackPlugin]  
at org.elasticsearch.plugins.PluginsService.loadPlugin(PluginsService.java:452) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.plugins.PluginsService.loadBundles(PluginsService.java:392) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.plugins.PluginsService.(PluginsService.java:142) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.node.Node.(Node.java:302) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.node.Node.(Node.java:245) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.bootstrap.Bootstrap$5.(Bootstrap.java:212) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.bootstrap.Bootstrap.setup(Bootstrap.java:212) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:322) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:121) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.bootstrap.Elasticsearch.execute(Elasticsearch.java:112) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:86) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:124) [elasticsearch-cli-6.1.1.jar:6.1.1]  
at org.elasticsearch.cli.Command.main(Command.java:90) [elasticsearch-cli-6.1.1.jar:6.1.1]  
at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:92) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:85) [elasticsearch-6.1.1.jar:6.1.1]  
Caused by: java.lang.reflect.InvocationTargetException  
at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) ~[?:?]  
at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62) ~[?:?]  
at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45) ~[?:?]  
at java.lang.reflect.Constructor.newInstance(Constructor.java:423) ~[?:1.8.0\_121]  
at org.elasticsearch.plugins.PluginsService.loadPlugin(PluginsService.java:443) ~[elasticsearch-6.1.1.jar:6.1.1]  
... 14 more

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [February 21, 2018, 10:19am UTC](https://discuss.elastic.co/t/ssl-communication-client-and-cluster-error/120607/4 "2018-02-21T10:19:45Z")

</div>

Hi Aby,

I hope your installation of x-pack was successful.  
Could you please post your output for `<ES-Home>/bin/elasticsearch-plugin list -v`?  
Also please check if you see any root cause exception in your exception stack trace and share that.

~  
Yogesh

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 22, 2018, 12:14am UTC](https://discuss.elastic.co/t/ssl-communication-client-and-cluster-error/120607/5 "2018-02-22T00:14:03Z")

</div>

> [@Aby](#):
>
> ```
> [2018-02-21T06:48:57,126][ERROR][o.e.b.Bootstrap] Exception java.lang.IllegalStateException: failed to load plugin class [org.elasticsearch.xpack.XPackPlugin]
> // ...
> at org.elasticsearch.plugins.PluginsService.loadPlugin(PluginsService.java:443) ~[elasticsearch-6.1.1.jar:6.1.1]
> ... 14 more
> 
> ```

Is there any more to this error message?  
It looks like a misconfiguration in your X-Pack settings, but the key part of the error message is missing.

---

<div class="post-metadata">

**Author:** ![Aby](https://avatars.discourse-cdn.com/v4/letter/a/a88e57/32.png) [@Aby](https://discuss.elastic.co/u/Aby)\
**Post date:** [February 22, 2018, 5:08am UTC](https://discuss.elastic.co/t/ssl-communication-client-and-cluster-error/120607/6 "2018-02-22T05:08:13Z")

</div>

Hi Yogesh - yes the X-pack installation is successful.

There was an issue with the trusted certificate generated and the format.

After the successful generation of the right certificate and configuration, the issue is resolved.

---

<div class="post-metadata">

**Author:** ![Aby](https://avatars.discourse-cdn.com/v4/letter/a/a88e57/32.png) [@Aby](https://discuss.elastic.co/u/Aby)\
**Post date:** [February 22, 2018, 5:09am UTC](https://discuss.elastic.co/t/ssl-communication-client-and-cluster-error/120607/7 "2018-02-22T05:09:36Z")

</div>

Hi Tim - yes the X-pack installation is successful.

There was an issue with the trusted certificate generated and the format.

After the successful generation of the right certificate and configuration.

Moreover, certificate was generated on the hostname and i was using the ipaddress, the issue is resolved now. Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2018, 5:09am UTC](https://discuss.elastic.co/t/ssl-communication-client-and-cluster-error/120607/8 "2018-03-22T05:09:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
