# TLS implementation for Elasticsearch in Openshift

**URL:** https://discuss.elastic.co/t/tls-implementation-for-elasticsearch-in-openshift/268287
**Category:** Elasticsearch
**Tags:** elastic-stack-security, docker
**Created:** [March 25, 2021, 5:12am UTC](https://discuss.elastic.co/t/tls-implementation-for-elasticsearch-in-openshift/268287 "2021-03-25T05:12:11Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Janakiraman](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@Janakiraman](https://discuss.elastic.co/u/Janakiraman)
#### Post date: [March 25, 2021, 5:12am UTC](https://discuss.elastic.co/t/tls-implementation-for-elasticsearch-in-openshift/268287/1 "2021-03-25T05:12:11Z")

</div>

Hi team,  
I am trying to implement TLS for single node elasticsearch(v 7.4.1) and when i try to run the elastic cert utility i am facing the below error. can you help me in providing a path to fix this? note: i do not have admin/super user access to the openshift cluster where i am trying to implement this.

"WARNING: An illegal reflective access operation has occurred  
WARNING: Illegal reflective access by org.bouncycastle.jcajce.provider.drbg.DRBG (file:/usr/share/elasticsearch/lib/tools/security-cli/bcprov-jdk15on-1.61.jar) to constructor sun.security.provider.Sun()  
WARNING: Please consider reporting this to the maintainers of org.bouncycastle.jcajce.provider.drbg.DRBG  
WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations  
WARNING: All illegal access operations will be denied in a future release"

Added on 30/03/2021 : \<\<Error was "no file exception" , i resolved this error as there was some permission issues. \>\>

---

<div class="post-metadata">

### Author: ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)
#### Post date: [March 27, 2021, 8:34am UTC](https://discuss.elastic.co/t/tls-implementation-for-elasticsearch-in-openshift/268287/2 "2021-03-27T08:34:03Z")

</div>

Hi @Janakiraman,

These are warnings, not errors. This wouldn't cause `elasticsearch-certutil` to fail, so it either succeeds or it fails for some other reason. In anyway you need to share the exact command you run and all the output you get.

---

<div class="post-metadata">

### Author: ![Janakiraman](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@Janakiraman](https://discuss.elastic.co/u/Janakiraman)
#### Post date: [March 30, 2021, 9:26am UTC](https://discuss.elastic.co/t/tls-implementation-for-elasticsearch-in-openshift/268287/3 "2021-03-30T09:26:52Z")

</div>

Thanks @ikakavas , managed to resolve the above issue. Another clarification required :  
Do we need a permanent storage in Openshift to implement this TLS ? I have an elastic node running in openshift but when i restart the node the generated certificates gets deleted as i do not have a permanent storage in Openshift. Also, can you mention any specific documentation on implementing TLS for elasticsearch in openshift container platform? i could not find one Thanks

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 27, 2021, 9:27am UTC](https://discuss.elastic.co/t/tls-implementation-for-elasticsearch-in-openshift/268287/4 "2021-04-27T09:27:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
