# The client is unable to verify that the server is Elasticsearch due to an unsuccessful product check call

**URL:** <https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510>\
**Category:** Elasticsearch\
**Tags:** language-clients\
**Created:** [August 23, 2023, 6:30pm UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510 "2023-08-23T18:30:17Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Erdem\_Sekerci](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erdem_sekerci/32/124907_2.png) [@Erdem\_Sekerci](https://discuss.elastic.co/u/Erdem_Sekerci)\
**Post date:** [August 23, 2023, 6:30pm UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510/1 "2023-08-23T18:30:17Z")

</div>

Hello.  
I see that similar issues have been reported before, but I cannot solve my problem using them.

I'm using NEST 7.17.5 dotnet core client and with the following configurations.

```auto
var elasticSettings = new ConnectionSettings(new SingleNodeConnectionPool(new Uri("https://my-cloud-uri")))
                .PrettyJson()
                 
                .BasicAuthentication("elasdtic", "password")
                .DefaultIndex("my_index")
                .EnableApiVersioningHeader();

```

I'm connecting the elastic cloud, and locally on my windows 10 environment, I can connect it successfully. But I when I run the client in the Ubuntu v22.04 container, a got the following error.

```auto
The client is unable to verify that the server is Elasticsearch due to an unsuccessful product check call. Some functionality may not be compatible if the server is running an unsupported product. Call: Status code unknown from: GET /?pretty=true
 ---> Elasticsearch.Net.PipelineException: The client is unable to verify that the server is Elasticsearch due to an unsuccessful product check call. Some functionality may not be compatible if the server is running an unsupported product.
 ---> System.Net.Http.HttpRequestException: The SSL connection could not be established, see inner exception.
 ---> System.Security.Authentication.AuthenticationException: The remote certificate is invalid because of errors in the certificate chain: UntrustedRoot
   at System.Net.Security.SslStream.SendAuthResetSignal(ProtocolToken message, ExceptionDispatchInfo exception)
   at System.Net.Security.SslStream.CompleteHandshake(SslAuthenticationOptions sslAuthenticationOptions)
   at System.Net.Security.SslStream.ForceAuthenticationAsync[TIOAdapter](Boolean receiveFirst, Byte[] reAuthenticationData, CancellationToken cancellationToken)

```

Every single config is the same with windows environment.

What changes on Ubuntu, and how come I can connect successfully to elastic cloud with the same credentials?

---

<div class="post-metadata">

**Author:** ![Erdem\_Sekerci](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erdem_sekerci/32/124907_2.png) [@Erdem\_Sekerci](https://discuss.elastic.co/u/Erdem_Sekerci)\
**Post date:** [August 23, 2023, 9:25pm UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510/2 "2023-08-23T21:25:50Z")

</div>

> [@Erdem\_Sekerci](#):
>
> What changes on Ubuntu, and how come I can connect successfully to elastic cloud with the same credentials?

Typo correction  
What changes on Ubuntu, and how come I can connect successfully to elastic cloud with the same credentials on windows?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 23, 2023, 10:36pm UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510/3 "2023-08-23T22:36:24Z")

</div>

Hi @Erdem_Sekerci  
Welcome to the community and thanks for trying Elastic Cloud

Not sure if typo or on purpose

`BasicAuthentication("elasdtic",`  
`.........................^`

The first thing I would try is a curl from the Ubuntu box with the same creds

`curl -v -u elastic https://url`

You may want to add `:443` port there was a time a few of the clients would tack on the default `9200` if a port was not provided.. I don't think that is the issue though.

Curious why you are not using the recommended Cloud ID + API Key.

---

<div class="post-metadata">

**Author:** ![stevejgordon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stevejgordon/32/80912_2.png) [@stevejgordon](https://discuss.elastic.co/u/stevejgordon)\
**Post date:** [August 24, 2023, 6:33am UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510/4 "2023-08-24T06:33:26Z")

</div>

@Erdem_Sekerci This message is slightly misleading in your case. Looking at the stack trace, I see `The SSL connection could not be established,` which is the root cause. Something local to your container is causing the SSL handshake to fail to the cloud URL. What image are you using? If it's an older image, potentially, it uses unsupported TLS versions. If you SSH into your container, you will likely be unable to contact the server, even with CURL. You will need to diagnose that first, and then the client should function as expected.

As a side note, we provide a shortcut to configure the client to communicate with the cloud instances where you can provide the cloud ID in the constructor instead of a URL.

---

<div class="post-metadata">

**Author:** ![Erdem\_Sekerci](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erdem_sekerci/32/124907_2.png) [@Erdem\_Sekerci](https://discuss.elastic.co/u/Erdem_Sekerci)\
**Post date:** [August 24, 2023, 8:36am UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510/5 "2023-08-24T08:36:47Z")

</div>

Hi Stephen, thanks for your response. Sorry it's a typo that I've done while changed my credentials to dummy text. I have tried Cloud ID + API Key previously and got the same result. I also tried to add certificate finger print I've got the same result as well.  
I will try to do curl in the container and share the result shortly.

---

<div class="post-metadata">

**Author:** ![Erdem\_Sekerci](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erdem_sekerci/32/124907_2.png) [@Erdem\_Sekerci](https://discuss.elastic.co/u/Erdem_Sekerci)\
**Post date:** [August 24, 2023, 8:50am UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510/6 "2023-08-24T08:50:06Z")

</div>

Hi Steve. thanks a lot for your response. I'm suspicious too, the problem may be due to local container.

I pulled the latest released version through the docker hub.

My ubuntu version:

PRETTY\_NAME="Ubuntu 22.04.3 LTS"  
NAME="Ubuntu"  
VERSION\_ID="22.04"  
VERSION="22.04.3 LTS (Jammy Jellyfish)"  
VERSION\_CODENAME=jammy  
ID=ubuntu  
ID\_LIKE=debian  
HOME\_URL="...www.ubuntu.com/"  
SUPPORT\_URL="..../help.ubuntu.com/"  
BUG\_REPORT\_URL="....bugs.launchpad.net/ubuntu/"  
PRIVACY\_POLICY\_URL="...www.ubuntu.com/legal/terms-and-policies/privacy-policy"

I will try to connect with CURL inside the container and share the results shortly.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 24, 2023, 8:56am UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510/7 "2023-08-24T08:56:21Z")

</div>

> [@Erdem\_Sekerci](#):
>
> ```auto
> ---> System.Security.Authentication.AuthenticationException: The remote certificate is invalid because of errors in the certificate chain: UntrustedRoot
> 
> ```

A likely explanation for this error is that your .NET runtime on Ubuntu has a very old (or empty) set of trusted certificate authorities.

[Elastic Cloud uses Let's Encrypt as an issuer](https://www.elastic.co/blog/migrating-ess-certs-letsencrypt). If your runtime does not have the pets encrypt root cert as a trusted issuer then you would see an `UntrustedRoot` error such as this.

---

<div class="post-metadata">

**Author:** ![Erdem\_Sekerci](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erdem_sekerci/32/124907_2.png) [@Erdem\_Sekerci](https://discuss.elastic.co/u/Erdem_Sekerci)\
**Post date:** [August 24, 2023, 10:51am UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510/8 "2023-08-24T10:51:22Z")

</div>

Hi everyone, thanks for your support. This problem is obviously caused by the old TLS versions of the container as you pointed too. It's been solved after I update the Ubuntu using the command `apt-get -y update;`  
Now all is well. thanks for your quick support.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2023, 10:51am UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510/9 "2023-09-21T10:51:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
