# SSL/TLS setup with PKCS8 keys

**URL:** <https://discuss.elastic.co/t/ssl-tls-setup-with-pkcs8-keys/80846>\
**Category:** Elasticsearch\
**Created:** [March 31, 2017, 4:47pm UTC](https://discuss.elastic.co/t/ssl-tls-setup-with-pkcs8-keys/80846 "2017-03-31T16:47:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lidiyam](https://avatars.discourse-cdn.com/v4/letter/l/ecd19e/32.png) [@lidiyam](https://discuss.elastic.co/u/lidiyam)\
**Post date:** [March 31, 2017, 4:47pm UTC](https://discuss.elastic.co/t/ssl-tls-setup-with-pkcs8-keys/80846/1 "2017-03-31T16:47:25Z")

</div>

Hi,

I'm trying to set up SSL/TLS with x-pack and running into this when I point to pem encoded files:

```
java.lang.IllegalArgumentException: parsed an unsupported object [PKCS8EncryptedPrivateKeyInfo]
at org.elasticsearch.xpack.ssl.CertUtils.readPrivateKey(CertUtils.java:268) ~[?:?]
at org.elasticsearch.xpack.ssl.PEMKeyConfig.readPrivateKey(PEMKeyConfig.java:80) ~[?:?]

```

elasticsearch.yml includes all of these settings  
xpack.ssl.key: /path/to/cakey.pem  
xpack.ssl.key\_passphrase: password  
xpack.ssl.certificate: /path/to/01.pem  
xpack.ssl.certificate\_authorities: ["/path/to/cacert.pem"]

When I use certgen to generate CA & node certificates I get PKCS1 keys, and pointing to them in elasticsearch.yml works fine. How can I use keys/certs that were generated this way: [https://www.elastic.co/guide/en/shield/current/certificate-authority.html](https://www.elastic.co/guide/en/shield/current/certificate-authority.html) ?

Thanks!

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 3, 2017, 3:58am UTC](https://discuss.elastic.co/t/ssl-tls-setup-with-pkcs8-keys/80846/2 "2017-04-03T03:58:03Z")

</div>

> [@lidiyam](#):
>
> How can I use keys/certs that were generated this way: [Setting Up a Certificate Authority | Shield [2.4] | Elastic](https://www.elastic.co/guide/en/shield/current/certificate-authority.html) ?

Certgen is the recommended approach to generating certificates for Elasticsearch 5.x with X-Pack. If you are able to use certificates from certgen, that will be the most straightforward approach.

Can you explain why you want to use the old (shield) method?

> [@](#):
>
> ```auto
> xpack.ssl.key: /path/to/cakey.pem
> xpack.ssl.key_passphrase: password
> xpack.ssl.certificate: /path/to/01.pem
> xpack.ssl.certificate_authorities: ["/path/to/cacert.pem"]
> 
> ```

These don't seem quite right. You have the `key` pointing to the CA key, but the `certificate` pointing to `01`.  
`xpack.ssl.key` should be pointing to `01.key` (or perhaps `01key.pem`, depending on how it was named)

> [@](#):
>
> parsed an unsupported object [PKCS8EncryptedPrivateKeyInfo]

My guess if that this is caused by the same problem as above - you've gotten your key and cert files mixed up somewhere along the way.

* * *

```
xpack.ssl.certificate

```

This should be the (public) certificate for your node.  
The first line of that file should say: `-----BEGIN CERTIFICATE-----`

* * *

```
xpack.ssl.key

```

## This should be the key for the certificate above. The first line of that file should say: `-----BEGIN RSA PRIVATE KEY-----`

```
xpack.ssl.key_passphrase

```

This is the passphrase for the key above.

* * *

```
xpack.ssl.certificate_authorities

```

These should be the (public) certificates for each of the CAs that you wish to trust.  
The first line of each file should say: `-----BEGIN CERTIFICATE-----`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2017, 3:58am UTC](https://discuss.elastic.co/t/ssl-tls-setup-with-pkcs8-keys/80846/3 "2017-05-01T03:58:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
