# Unable to configure Wildcard certificate in Elasticsearch

**URL:** <https://discuss.elastic.co/t/unable-to-configure-wildcard-certificate-in-elasticsearch/280379>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 4, 2021, 4:05am UTC](https://discuss.elastic.co/t/unable-to-configure-wildcard-certificate-in-elasticsearch/280379 "2021-08-04T04:05:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sathish22](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@Sathish22](https://discuss.elastic.co/u/Sathish22)\
**Post date:** [August 4, 2021, 4:05am UTC](https://discuss.elastic.co/t/unable-to-configure-wildcard-certificate-in-elasticsearch/280379/1 "2021-08-04T04:05:46Z")

</div>

Hi Team,

We are facing issue replacing wildcard certificate with self-signed certificate, due to below issue.

```auto
Caused by: java.security.UnrecoverableKeyException: failed to decrypt safe contents entry: javax.crypto.BadPaddingException: Given final block not properly padded.
Such issues can arise if a bad key is used during decryption.
at sun.security.pkcs12.PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2103) ~[?:?]
        at sun.security.util.KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:220) ~[?:?]
        at java.security.KeyStore.load(KeyStore.java:1472) ~[?:?]
        at org.elasticsearch.xpack.core.ssl.TrustConfig.getStore(TrustConfig.java:97) ~[?:?]
        at org.elasticsearch.xpack.core.ssl.StoreTrustConfig.createTrustManager(StoreTrustConfig.java:65) ~[?:?]
        at org.elasticsearch.xpack.core.ssl.SSLService.createSslContext(SSLService.java:437) ~[?:?]
        at java.util.HashMap.computeIfAbsent(HashMap.java:1224) ~[?:?]
        at org.elasticsearch.xpack.core.ssl.SSLService.lambda$loadSSLConfigurations$5(SSLService.java:526) ~[?:?]
        at java.util.HashMap.forEach(HashMap.java:1425) ~[?:?]
        at java.util.Collections$UnmodifiableMap.forEach(Collections.java:1521) ~[?:?]
        at org.elasticsearch.xpack.core.ssl.SSLService.loadSSLConfigurations(SSLService.java:524) ~[?:?]
        at org.elasticsearch.xpack.core.ssl.SSLService.<init>(SSLService.java:142) ~[?:?]
        at org.elasticsearch.xpack.core.XPackPlugin.createSSLService(XPackPlugin.java:455) ~[?:?]
        at org.elasticsearch.xpack.core.XPackPlugin.createComponents(XPackPlugin.java:288) ~[?:?]
        at org.elasticsearch.node.Node.lambda$new$15(Node.java:553) ~[elasticsearch-7.10.0.jar:7.10.0]

```

PFB elasticsearch.yml configuration for SSL

```auto
xpack.security.http.ssl.keystore.type: PKCS12
xpack.security.http.ssl.keystore.path: /opt/elasticsearch/config/xxxxxx.p12
xpack.security.http.ssl.truststore.path: /opt/elasticsearch/config/xxxxxx.p12
xpack.security.http.ssl.truststore.type: PKCS12
xpack.security.http.ssl.client_authentication: required
xpack.security.http.ssl.keystore.password: xxxxxxxxxx

```

Please let me know we are using any wrong configuration or missing any configuration commands.

Thanks,  
Sathish Thumma.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 4, 2021, 4:56am UTC](https://discuss.elastic.co/t/unable-to-configure-wildcard-certificate-in-elasticsearch/280379/2 "2021-08-04T04:56:12Z")

</div>

It doesn't look like you have provided a `truststore.password`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2021, 4:57am UTC](https://discuss.elastic.co/t/unable-to-configure-wildcard-certificate-in-elasticsearch/280379/3 "2021-09-01T04:57:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
