# Unable to enable https and internode communication in 2 node cluster

**URL:** <https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 12, 2020, 7:31pm UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306 "2020-05-12T19:31:47Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 12, 2020, 7:31pm UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/1 "2020-05-12T19:31:47Z")

</div>

Hi,

I have setup a 2 node ES cluster as follows  
node-1 : elasticsearch and kibana  
node-2: elasticsearch

I have enabled https and tls level security on node-1 successfully on both between kibana and browser and between kibana and elasticsearch. However

1. When I try to add https to node-2 it is asking me for username and password.
2. Unable to make it join the cluster with node-1

I have generated a organisation level certificate in .pfx format for node-1 and using the same for node-2. Is this an issue? Should there be a new certificate issued for node-2?

Following is my es config from node-1 and node-2:  
`node-1:`

```auto
cluster.name: cluster1
node.name: node-1
path.data: E:/elasticsearch/data
path.logs: E:/elasticsearch/logs
network.host: node-1

discovery.seed_hosts: ["node-2", "node-1"]
cluster.initial_master_nodes: ["node-1"]
node.master: true
node.data: true

xpack.security.enabled: true

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: <path-to-file-elk.pfx>
xpack.security.http.ssl.truststore.path: <path-to-file-elk.pfx> 

xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: <path-to-file-elk.pfx>
xpack.security.transport.ssl.truststore.path: <path-to-file-elk.pfx> 

```

`node-2:`

```auto
cluster.name: cluster1
node.name: node-2
path.data: E:/elasticsearch/data
path.logs: E:/elasticsearch/logs
network.host: node-2
discovery.seed_hosts: ["node-2", "node-1"]
cluster.initial_master_nodes: ["node-1"]
node.master: true
node.data: true

xpack.security.enabled: true

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: <path-to-file-elk.pfx>
xpack.security.http.ssl.truststore.path: <path-to-file-elk.pfx>

xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: <path-to-file-elk.pfx>
xpack.security.transport.ssl.truststore.path: <path-to-file-elk.pfx>

```

Could someone kindly guide me on this?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 13, 2020, 6:15am UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/2 "2020-05-13T06:15:29Z")

</div>

> [@nityaraj06](#):
>
> When I try to add https to node-2 it is asking me for username and password.

Can you clarify what you mean with "try to add https" and what is asking you for a username and a password and at which point ?

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 13, 2020, 6:35am UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/3 "2020-05-13T06:35:41Z")

</div>

Hi @ikakavas, thanks for looking into this 🙂  
I mean when I try to enable https on elasticsearch on node-2 (from [http://node-2:9200](http://node-2:9200) to [https://node-2:9200](https://node-2:9200)). I am being asked for username and password on accessing [https://node-2:9200](https://node-2:9200).

The ES logs on this node is also showing the following error in logs :  
`io.netty.handler.codec.DecoderException: javax.net.ssl.SSLException: Received fatal alert: bad_certificate`

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 13, 2020, 2:31pm UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/4 "2020-05-13T14:31:43Z")

</div>

Could someone pls help me out here? @ikakavas @Magnus_Kessler @magnusbaeck

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 14, 2020, 8:38am UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/5 "2020-05-14T08:38:48Z")

</div>

Please be patient in waiting for responses to your question and refrain from pinging multiple times asking for a response or opening multiple topics for the same question. This is a community forum, it may take time for someone to reply to your question. For more information please refer to the [Community Code of Conduct](https://www.elastic.co/community/codeofconduct) specifically the section "Be patient". Also, please refrain from pinging folks directly, this is a forum and anyone that participates might be able to assist you.

If you are in need of a service with an SLA that covers response times for questions then you may want to consider talking to us about a [subscription](https://www.elastic.co/subscriptions).

It's fine to answer on your own thread after 2 or 3 days (not including weekends) if you don't have an answer.

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 14, 2020, 8:55am UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/6 "2020-05-14T08:55:02Z")

</div>

Apologies for the pings.

Kindly look into my query when you have the time.

---

<div class="post-metadata">

**Author:** ![hunsw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hunsw/32/93637_2.png) [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Post date:** [May 14, 2020, 12:16pm UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/7 "2020-05-14T12:16:29Z")

</div>

You need a separate certificate for node2.

Here's an excellent guide that I advise you to follow through:

> **[Configuring SSL, TLS, and HTTPS to secure Elasticsearch, Kibana, Beats, and...](https://www.elastic.co/blog/configuring-ssl-tls-and-https-to-secure-elasticsearch-kibana-beats-and-logstash)**
>
> Feeling insecure about your Elastic Stack security? Run through these step-by-step instructions for setting up TLS encryption and https on Elasticsearch, Kibana, Logstash, and Beats to shore up your stack's defenses. Highly recommended for end-to-end...

Note that the author uses separate certificate/key files and not keystores, IMO it is easier to follow his approach, keystore and truststore concepts are harder to grasp for most users/admins/developers..

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 14, 2020, 12:34pm UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/8 "2020-05-14T12:34:21Z")

</div>

@hunsw - I have followed this blog and it says `You can use the scp command to copy certificates from node1 to node2. Both nodes require the certificate and key in order to secure the connection.`

So does that mean a SINGLE ssl certificate would have domain names of both node-1 and node-2. I am totally new to network security, hence pardon my silly questions.

Also can we use this certificate then on the logstash nodes as well since we would have to enable security there too?

---

<div class="post-metadata">

**Author:** ![hunsw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hunsw/32/93637_2.png) [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Post date:** [May 14, 2020, 12:38pm UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/9 "2020-05-14T12:38:05Z")

</div>

It's ok. In the guide he uses node1 to generate certificates.

After the generation step, the certificate and key of node2 and the certificate authority (CA) certificate has to be copied (with scp for example) from node1 to node2.

---

<div class="post-metadata">

**Author:** ![hunsw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hunsw/32/93637_2.png) [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Post date:** [May 14, 2020, 12:39pm UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/10 "2020-05-14T12:39:26Z")

</div>

You only need the CA certificate on Logstash, so your Logstash nodes can be sure that the certificate of node1 and node2 are issued by a trusted authority.

EDIT: unless you want mutual authentication (with client cert).

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 14, 2020, 12:52pm UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/11 "2020-05-14T12:52:44Z")

</div>

Ok so there will be 2 separate files - node1.cer and node2.cer?

Also regarding CA, we can download this from the browser since https for kibana is working ? @hunsw

For mutual auth - CA and client cert both are needed, correct? 🙂

---

<div class="post-metadata">

**Author:** ![hunsw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hunsw/32/93637_2.png) [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Post date:** [May 14, 2020, 1:03pm UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/12 "2020-05-14T13:03:46Z")

</div>

Yes, you can download it from the browser too, though it has to be on your nodes too somewhere. (Probably in the truststore file.)

Yes, for mutual auth you need the CA _and_ the client cert too. Or you can just use a user/password combination for Logstash to authenticate in Elasticsearch and secure the channel with TLS.

See here:  
[https://www.elastic.co/guide/en/logstash/current/ls-security.html](https://www.elastic.co/guide/en/logstash/current/ls-security.html)

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 14, 2020, 1:07pm UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/13 "2020-05-14T13:07:30Z")

</div>

Great! I will request for a cert for the other node and get back to you in case of any queries.

This is how my logstash output conf looks as of now, kindly let me know if you see anything wrong in this @hunsw

```auto
output {
elasticsearch {
	user => logstash_internal
	password => kibana
	ssl => true
	cacert => "e:/logstash/config/ca-cert.cer" #downloaded from the browser
	hosts => ["https://node1:9200/","https://node2:9200/"]
    index => "ls-%{+YYYY.MM.dd}"	
}
}

```

---

<div class="post-metadata">

**Author:** ![hunsw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hunsw/32/93637_2.png) [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Post date:** [May 14, 2020, 1:13pm UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/14 "2020-05-14T13:13:13Z")

</div>

Looks good to me, hopefully the cacert path is a valid one. (I haven't run LS on Windows, but shouldn't that be e:\logstash\config\ca-cert.cer?)

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 14, 2020, 1:17pm UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/15 "2020-05-14T13:17:26Z")

</div>

I will re-check that 🙂  
Thank you for your time! Appreciate it!

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 19, 2020, 10:08am UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/16 "2020-05-19T10:08:29Z")

</div>

Hi @hunsw - the setup is working fine from logstash, thank you for your help!

I am facing issues currently with nodes unable to form a cluster after enabling security and generating node1.pfx and node2.pfx

```auto
[node1] failed to establish trust with server at [<unknown host>]; the server provided a certificate with subject name [CN=node2...] [DNS:node2]; .......... certificate is not trusted in this ssl context ([xpack.security.transport.ssl])

```

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 21, 2020, 7:50am UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/17 "2020-05-21T07:50:37Z")

</div>

@ikakavas - The config I am using is mentioned in this mail. I cannot mention the node names and other organisation specific details as it against the policy. If you need any information pls let me know.

The certificates have been generated by my organisation and both the node certificates have the same CA (i have confirmed this) , the certificates are in .pfx format.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 18, 2020, 7:50am UTC](https://discuss.elastic.co/t/unable-to-enable-https-and-internode-communication-in-2-node-cluster/232306/18 "2020-06-18T07:50:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
