# Unable to create an enrollment token for Kibana. "Elasticsearch node HTTP layer SSL configuration Keystore doesn't contain any PrivateKey entries where the associated certificate is a CA certificate"

**URL:** <https://discuss.elastic.co/t/unable-to-create-an-enrollment-token-for-kibana-elasticsearch-node-http-layer-ssl-configuration-keystore-doesnt-contain-any-privatekey-entries-where-the-associated-certificate-is-a-ca-certificate/297032>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 12, 2022, 12:46am UTC](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token-for-kibana-elasticsearch-node-http-layer-ssl-configuration-keystore-doesnt-contain-any-privatekey-entries-where-the-associated-certificate-is-a-ca-certificate/297032 "2022-02-12T00:46:48Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [February 14, 2022, 5:13am UTC](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token-for-kibana-elasticsearch-node-http-layer-ssl-configuration-keystore-doesnt-contain-any-privatekey-entries-where-the-associated-certificate-is-a-ca-certificate/297032/4 "2022-02-14T05:13:36Z")

</div>

> [@maof97](#):
>
> It seems like the default cert generated does not add the IP/Domain to the Subject-Name field. It only worked if I tried via [https://localhost:9200](https://localhost:9200)

We do our best to detect all IP addresses of the interfaces that are up when elasticsearch is installed and then use them as IP Subject Alternative Names in the HTTP TLS certificate. How is the networking configured for your VM ? Is `10.24.1.5` an IP address that the VM itself is aware of or are you using NAT ?

If you still have these around, you can take a look at what IP addresses we found out by inspecting the certificate. (I'm assuming you have installed this with the DEB package, so the following commands apply to that )

```auto
# /usr/share/elasticsearch/bin/elasticsearch-keystore show xpack.security.http.ssl.keystore.secure_password

```

will show you the password for the http.p12 keystore. Then you can run

```auto
keytool -keystore /etc/elasticsearch/config/certs/http.p12 -storepass <password_you_got_above> -list -v

```

and look at the section that starts with `Alias name: http`.

As to what you can do now, you can either:

- Reinstall elasticsearch and use an IP address/hostname to access it that exists in the SANs of the certificate. Use the enrollment process as described in to configure Kibana

or

- Manually configure TLS following the instructions we have in [Set up basic security for the Elastic Stack plus secured HTTPS traffic | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup-https.html)

> [@TimV](#):
>
> > [@maof97](#):
> >
> > ````auto
> > > elasticsearch-create-enrollment-token -s kibana
> > ERROR: Unable to create an enrollment token for Kibana. Elasticsearch node HTTP layer SSL configuration Keystore doesn't contain any PrivateKey entries where the associated certificate is a CA certificate
> > > ```
> > 
> > ````
> 
> I think this can probably be classed as a bug (or at least a rough edge on the feature).  
> Kibana enrollment shouldn't require the CA private key. Node enrollment does, and I suspect we're applying the same validation regardless of the type on token being generated.

We will track this and see if it makes sense to allow creating kibana enrollment tokens with manual/custom TLS setups and/or enhance the error message to make it clearer why it fails. Thanks for reporting this @maof97 !

---

_[View the full topic](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token-for-kibana-elasticsearch-node-http-layer-ssl-configuration-keystore-doesnt-contain-any-privatekey-entries-where-the-associated-certificate-is-a-ca-certificate/297032)._
