# SSL Transport setup with Ansible

**URL:** <https://discuss.elastic.co/t/ssl-transport-setup-with-ansible/237993>\
**Category:** Elasticsearch\
**Created:** [June 22, 2020, 4:11am UTC](https://discuss.elastic.co/t/ssl-transport-setup-with-ansible/237993 "2020-06-22T04:11:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![biggtimber](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@biggtimber](https://discuss.elastic.co/u/biggtimber)\
**Post date:** [June 22, 2020, 4:11am UTC](https://discuss.elastic.co/t/ssl-transport-setup-with-ansible/237993/1 "2020-06-22T04:11:55Z")

</div>

How do normal installations of the elasticstack work with SSL Transport/HTTP when using Ansible?  
I'm using the github ansible role setup. From the documentation, it shows the cert setup using elasticsearch-certutil to generate the key files. However, this isn't there until the initial install is completed, and if you enable and set the paths, the play fails saying that the key files can't be located.

---

<div class="post-metadata">

**Author:** ![Julien\_MAILLERET](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julien_mailleret/32/45074_2.png) [@Julien\_MAILLERET](https://discuss.elastic.co/u/Julien_MAILLERET)\
**Post date:** [June 24, 2020, 10:25am UTC](https://discuss.elastic.co/t/ssl-transport-setup-with-ansible/237993/2 "2020-06-24T10:25:32Z")

</div>

Hi @biggtimber,

ansible-elasticsearch role require that you generate the certificates before running it.

The certificate need to be passed to `es_ssl_certificate` variable or `es_ssl_keystore`/`es_ssl_truststore` if you use PKCS12 keystore.

Did you do that?

Could you also provide your playbook?

---

<div class="post-metadata">

**Author:** ![biggtimber](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@biggtimber](https://discuss.elastic.co/u/biggtimber)\
**Post date:** [June 29, 2020, 3:54am UTC](https://discuss.elastic.co/t/ssl-transport-setup-with-ansible/237993/3 "2020-06-29T03:54:06Z")

</div>

I ran them manually eventually, and ti worked. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2020, 3:54am UTC](https://discuss.elastic.co/t/ssl-transport-setup-with-ansible/237993/4 "2020-07-27T03:54:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
