# Trobling with HTTPS configuration

**URL:** <https://discuss.elastic.co/t/trobling-with-https-configuration/187557>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 26, 2019, 11:47am UTC](https://discuss.elastic.co/t/trobling-with-https-configuration/187557 "2019-06-26T11:47:30Z")\
**Posts on this page:** 10\
**Page:** 2

<div class="post-metadata">

**Author:** ![thewasta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thewasta/32/48818_2.png) [@thewasta](https://discuss.elastic.co/u/thewasta)\
**Post date:** [June 27, 2019, 1:17pm UTC](https://discuss.elastic.co/t/trobling-with-https-configuration/187557/21 "2019-06-27T13:17:04Z")

</div>

> [@ikakavas](#):
>
> We can't _not_ check the name. You have to give us exact information if we are to help you. When you use different filenames in every post it's very very hard for us to follow you and to find out what goes on in your deployment.

I know, it was my bad, I copied the line from the guide but didn't change the name to the name of my file.

This is the config of all nodes:

### Master Config YML:

```auto
cluster.name: elasticppo
node.name: ${HOSTNAME}
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
bootstrap.memory_lock: true
network.host: ["127.0.0.1","192.168.1.142"]
discovery.zen.ping.unicast.hosts: ["192.168.1.142","192.168.1.144","192.168.1.146"]
discovery.zen.minimum_master_nodes: 2
xpack.security.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/elasticmaster.p12
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/elasticmaster.p12
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: certs/elasticmaster.p12 
xpack.security.http.ssl.truststore.path: certs/elasticmaster.p12 

```

### Slave 1 Config YML:

```auto
cluster.name: elasticppo
node.name: ${HOSTNAME}
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
bootstrap.memory_lock: true
network.host: ["127.0.0.1","192.168.1.144"]
discovery.zen.ping.unicast.hosts: ["192.168.1.142","192.168.1.144","192.168.1.146"]
discovery.zen.minimum_master_nodes: 2
xpack.security.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/elasticslave1.p12
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/elasticslave1.p12
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: certs/elasticslave1.p12 
xpack.security.http.ssl.truststore.path: certs/elasticslave1.p12 

```

### Slave 2 Config YML:

```auto
cluster.name: elasticppo
node.name: ${HOSTNAME}
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
bootstrap.memory_lock: true
network.host: ["127.0.0.1","192.168.1.146"]
discovery.zen.ping.unicast.hosts: ["192.168.1.142","192.168.1.144","192.168.1.146"]
discovery.zen.minimum_master_nodes: 2
xpack.security.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/elasticslave2.p12
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/elasticslave2.p12
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: certs/elasticslave2.p12 
xpack.security.http.ssl.truststore.path: certs/elasticslave2.p12 

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [June 27, 2019, 1:21pm UTC](https://discuss.elastic.co/t/trobling-with-https-configuration/187557/22 "2019-06-27T13:21:36Z")

</div>

Do you actially have this section duplicated in each node , or is it just copy paste error ?

```auto
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/elasticslave2.p12
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/elasticslave2.p12
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/elasticslave2.p12
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/elasticslave2.p12

```

Can you please ssh into every node and make sure that all your `.p12` files are owned by the `elasticsearch` user? As in

```auto
chown -R elasticsearch /etc/elasticsearch/certs/

```

---

<div class="post-metadata">

**Author:** ![thewasta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thewasta/32/48818_2.png) [@thewasta](https://discuss.elastic.co/u/thewasta)\
**Post date:** [June 27, 2019, 1:33pm UTC](https://discuss.elastic.co/t/trobling-with-https-configuration/187557/23 "2019-06-27T13:33:28Z")

</div>

> [@ikakavas](#):
>
> Do you actially have this section duplicated in each node , or is it just copy paste error ?

Was Mistake copying lines, already fixed.

I did chown in all nodes, and now seems like now it's working, only accept connection via HTTPS, but if I try  
`GET _cat/indices`  
Returns:

```auto
{
error: {
root_cause: [
{
type: "master_not_discovered_exception",
reason: null,
}
],
type: "master_not_discovered_exception",
reason: null,
},
status: 503,
}

```

I added `node.master: true` in Master node config but nothing.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [June 27, 2019, 1:36pm UTC](https://discuss.elastic.co/t/trobling-with-https-configuration/187557/24 "2019-06-27T13:36:08Z")

</div>

we can't guess what might be wrong with your configuration if you don't share your logs with us 🙂

---

<div class="post-metadata">

**Author:** ![thewasta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thewasta/32/48818_2.png) [@thewasta](https://discuss.elastic.co/u/thewasta)\
**Post date:** [June 27, 2019, 1:49pm UTC](https://discuss.elastic.co/t/trobling-with-https-configuration/187557/25 "2019-06-27T13:49:26Z")

</div>

As you know It's a extense file, if I paste all here I won't be able to answer more until tomorrow, so I will share it with a link:  
[Master Logs](http://pasted.co/e6f8b9ed)  
[Slave 2 logs](http://pasted.co/d88d64b6)  
[Slave 1 logs](http://pasted.co/82aa3f2a)  
The pass to view all files is `elastic`  
Thanks a lot

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [June 27, 2019, 2:20pm UTC](https://discuss.elastic.co/t/trobling-with-https-configuration/187557/26 "2019-06-27T14:20:42Z")

</div>

```auto
[2019-06-27T15:40:34,530][WARN][o.e.d.z.ZenDiscovery] [elasticmaster] not enough master nodes discovered during pinging (found [[Candidate{node={elasticmaster}{RhMwLe4rQO-oKoBjUxHFSw}{LhNDr75LTVSrQex0J-OZbA}{192.168.1.142}{192.168.1.142:9300}{ml.machine_memory=8363855872, xpack.installed=true, ml.max_open_jobs=20, ml.enabled=true}, clusterStateVersion=-1}]], but needed [2]), pinging again

```

```auto
[2019-06-27T15:47:06,671][WARN][o.e.d.z.ZenDiscovery] [elasticslave2] not enough master nodes discovered during pinging (found [[Candidate{node={elasticmaster}{RhMwLe4rQO-oKoBjUxHFSw}{LhNDr75LTVSrQex0J-OZbA}{192.168.1.142}{192.168.1.142:9300}{ml.machine_memory=8363855872, ml.max_open_jobs=20, xpack.installed=true, ml.enabled=true}, clusterStateVersion=-1}]], but needed [2]), pinging again

```

```auto
[2019-06-27T15:48:36,020][WARN][o.e.d.z.ZenDiscovery] [elasticslave1] not enough master nodes discovered during pinging (found [[Candidate{node={elasticmaster}{RhMwLe4rQO-oKoBjUxHFSw}{LhNDr75LTVSrQex0J-OZbA}{192.168.1.142}{192.168.1.142:9300}{ml.machine_memory=8363855872, ml.max_open_jobs=20, xpack.installed=true, ml.enabled=true}, clusterStateVersion=-1}]], but needed [2]), pinging again

```

looks like your nodes can only connect to `192.168.1.142` but not to `192.168.1.144` and/or `192.168.1.146`. Can you ping `192.168.1.144` and `192.168.1.146` from all nodes ? Is port 9300 blocked by a firewall ?

---

<div class="post-metadata">

**Author:** ![thewasta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thewasta/32/48818_2.png) [@thewasta](https://discuss.elastic.co/u/thewasta)\
**Post date:** [June 28, 2019, 6:13am UTC](https://discuss.elastic.co/t/trobling-with-https-configuration/187557/27 "2019-06-28T06:13:28Z")

</div>

I used `ping` command in all node to the rest nodes, and all works good. Example:  
From `192.168.1.142 to 192.168.144` , `192.168.1.142 to 192.168.1.146` etc.

> [@ikakavas](#):
>
> Is port 9300 blocked by a firewall ?

Not, I think so. Because `UFW` and other firewall isn't installed or even activated in all nodes.

Now I used `lsof -i -P -n | grep LISTEN` and this is the output:

#### Master .142

```auto
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN 1319/nginx: master  
tcp 0 0 127.0.0.53:53 0.0.0.0:* LISTEN 735/systemd-resolve 
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 1178/sshd           
tcp 0 0 0.0.0.0:5601 0.0.0.0:* LISTEN 2317/node           
tcp6 0 0 192.168.1.142:9200 :::* LISTEN 2103/java           
tcp6 0 0 127.0.0.1:9200 :::* LISTEN 2103/java           
tcp6 0 0 :::80 :::* LISTEN 1319/nginx: master  
tcp6 0 0 192.168.1.142:9300 :::* LISTEN 2103/java           
tcp6 0 0 127.0.0.1:9300 :::* LISTEN 2103/java           
tcp6 0 0 :::22 :::* LISTEN 1178/sshd 

```

#### Slave 1 .144

```auto
tcp 0 0 127.0.0.53:53 0.0.0.0:* LISTEN 696/systemd-resolve 
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 1067/sshd           
tcp6 0 0 192.168.1.144:9200 :::* LISTEN 1835/java           
tcp6 0 0 127.0.0.1:9200 :::* LISTEN 1835/java           
tcp6 0 0 192.168.1.144:9300 :::* LISTEN 1835/java           
tcp6 0 0 127.0.0.1:9300 :::* LISTEN 1835/java           
tcp6 0 0 :::22 :::* LISTEN 1067/sshd 

```

#### Slave 2 .146

```auto
tcp 0 0 127.0.0.53:53 0.0.0.0:* LISTEN 675/systemd-resolve 
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 1102/sshd           
tcp6 0 0 192.168.1.146:9200 :::* LISTEN 1856/java           
tcp6 0 0 127.0.0.1:9200 :::* LISTEN 1856/java           
tcp6 0 0 192.168.1.146:9300 :::* LISTEN 1856/java           
tcp6 0 0 127.0.0.1:9300 :::* LISTEN 1856/java           
tcp6 0 0 :::22 :::* LISTEN 1102/sshd     

```

9300 and 9200 is open to listen from any IP, right?

---

<div class="post-metadata">

**Author:** ![thewasta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thewasta/32/48818_2.png) [@thewasta](https://discuss.elastic.co/u/thewasta)\
**Post date:** [June 28, 2019, 8:09am UTC](https://discuss.elastic.co/t/trobling-with-https-configuration/187557/28 "2019-06-28T08:09:47Z")

</div>

Thanks a lot! I fixed it with command  
`ufw allow 9300/tcp` in Slave 1 and Slave 2. For now I'm disabling ufw in each node to know which one needs ufw and why.  
Now it is connected with via HTTPS with Password and user, now have to know how to configurate users, but it isn't for this post and first must to investigate by my own.

### Thanks!

---

<div class="post-metadata">

**Author:** ![Meet](https://avatars.discourse-cdn.com/v4/letter/m/73ab20/32.png) [@Meet](https://discuss.elastic.co/u/Meet)\
**Post date:** [July 2, 2019, 1:51am UTC](https://discuss.elastic.co/t/trobling-with-https-configuration/187557/29 "2019-07-02T01:51:59Z")

</div>

> [@thewasta](#):
>
> Caused by: org.elasticsearch.ElasticsearchException: failed to initialize a TrustManagerFactory  
> at org.elasticsearch.xpack.core.ssl.StoreTrustConfig.createTrustManager(StoreTrustConfig.java:61)

Hi Schenier,  
.put("xpack.security.transport.ssl.verification\_mode","certificate")  
adding this property would solve the above error.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2019, 1:52am UTC](https://discuss.elastic.co/t/trobling-with-https-configuration/187557/30 "2019-07-30T01:52:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/trobling-with-https-configuration/187557.md?page=1)
