# SSL fatal error in ES logs

**URL:** <https://discuss.elastic.co/t/ssl-fatal-error-in-es-logs/180208>\
**Category:** Elasticsearch\
**Created:** [May 8, 2019, 3:12pm UTC](https://discuss.elastic.co/t/ssl-fatal-error-in-es-logs/180208 "2019-05-08T15:12:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bkasrai](https://avatars.discourse-cdn.com/v4/letter/b/b5a626/32.png) [@bkasrai](https://discuss.elastic.co/u/bkasrai)\
**Post date:** [May 8, 2019, 3:12pm UTC](https://discuss.elastic.co/t/ssl-fatal-error-in-es-logs/180208/1 "2019-05-08T15:12:56Z")

</div>

Good morning-I am seeing errors in my ES logs on a specific node (no other node within the cluster is reporting this) with regards to SSL fatal error-bad certificate (actual log information is below) This one is a bit tricky with respect to it's configuration because this specific node WAS running Kibana until we stood up our own Kibana instance on a separate node so Kibana is no longer running on this node. I came across a separate thread about SSL and trust store however if Kibana is not running on this node, why would we still see bad certificate errors in the logs and the browser not being trusted. Can someone shed some clarification on this and let me know if I need to start the service, comment out the Cert configuration in Kibana.yml (on this ES node), restart the service to have the changes take hold and then bring down the Kibana service as we are no longer using this instance anymore? (this is the thread I was reading with reference to SSL cert) Any help would greatly be appreciated. Thanks.

> [@Need Help with Installing Certificates into Elasticsearch](https://discuss.elastic.co/t/need-help-with-installing-certificates-into-elasticsearch/104715/7):
>
> OK, Now that you've provided the top half of the error stack trace, it's much clearer. This is caused by your web browser. Your browser is not configured to trust the Certificate Authority that your elasticsearch node is using. That is totally normal, certgen is unable to directly generate certificates that browsers trust by default - for that you need to generate a Certificate Signing Request (which certgen can do) and send it off to a public CA. When the browser encounters a certificate tha…

```
io.netty.handler.codec.DecoderException: javax.net.ssl.SSLException: Received fatal alert: bad_certificate
        at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:472) ~[netty-codec-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:278) ~[netty-codec-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1434) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:965) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:163) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:644) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:544) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:498) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:458) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:897) [netty-common-4.1.30.Final.jar:4.1.30.Final]
        at java.lang.Thread.run(Thread.java:748) [?:1.8.0_191]
Caused by: javax.net.ssl.SSLException: Received fatal alert: bad_certificate

```

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 9, 2019, 2:07am UTC](https://discuss.elastic.co/t/ssl-fatal-error-in-es-logs/180208/2 "2019-05-09T02:07:33Z")

</div>

Can you provide a bit more context for this log message.  
From the bit you've shown we can't tell where this is happening, and it makes a big difference whether it's on "http" or "transport".

---

<div class="post-metadata">

**Author:** ![bkasrai](https://avatars.discourse-cdn.com/v4/letter/b/b5a626/32.png) [@bkasrai](https://discuss.elastic.co/u/bkasrai)\
**Post date:** [May 9, 2019, 9:56am UTC](https://discuss.elastic.co/t/ssl-fatal-error-in-es-logs/180208/3 "2019-05-09T09:56:40Z")

</div>

Hey @TimV Sorry about that, it looks like it is happening at the http level. Here is the full log below.

```
[2019-05-09T00:00:05,229][WARN][o.e.x.s.t.n.SecurityNetty4HttpServerTransport] [server.com] caught exception while handling client http traffic, closing connection [id: 0xbc2df9ee, L:0.0.0.0/0.0.0.0:9200 ! R:/xx.xx.xxx.x:54512]
io.netty.handler.codec.DecoderException: javax.net.ssl.SSLException: Received fatal alert: bad_certificate
        at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:472) ~[netty-codec-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:278) ~[netty-codec-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1434) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:965) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:163) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:644) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:544) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:498) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:458) [netty-transport-4.1.30.Final.jar:4.1.30.Final]
        at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:897) [netty-common-4.1.30.Final.jar:4.1.30.Final]
        at java.lang.Thread.run(Thread.java:748) [?:1.8.0_191]
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2019, 9:56am UTC](https://discuss.elastic.co/t/ssl-fatal-error-in-es-logs/180208/4 "2019-06-06T09:56:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
