# Unable to load SSL configuration for Elasticsearch

**URL:** <https://discuss.elastic.co/t/unable-to-load-ssl-configuration-for-elasticsearch/268087>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 23, 2021, 11:37am UTC](https://discuss.elastic.co/t/unable-to-load-ssl-configuration-for-elasticsearch/268087 "2021-03-23T11:37:05Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![runchranda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/runchranda/32/85951_2.png) [@runchranda](https://discuss.elastic.co/u/runchranda)\
**Post date:** [March 23, 2021, 11:37am UTC](https://discuss.elastic.co/t/unable-to-load-ssl-configuration-for-elasticsearch/268087/1 "2021-03-23T11:37:05Z")

</div>

Hi, I am trying to **Encrypt communications in Elasticsearch between nodes**.

I refer to this, [Encrypting communications in Elasticsearch] ([Encrypting communications in Elasticsearch | Elasticsearch Reference [7.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-tls.html#node-certificates))

But I encountered such errors when I try to restart my elasticsearch. Below are the error logs stated in my elasticsearch log file:

```auto

```

[2021-03-23T19:00:08,214][ERROR][o.e.b.ElasticsearchUncaughtExceptionHandler] [node-1] uncaught exception in thread [main]  
**org.elasticsearch.bootstrap.StartupException: ElasticsearchSecurityException[failed to load SSL configuration [xpack.security.http.ssl]]; nested: ElasticsearchException[failed to initialize SSL TrustManager]; nested: IOException[keystore password was incorrect]; nested:** UnrecoverableKeyException[failed to decrypt safe contents entry: javax.crypto.BadPaddingException: Given final block not properly padded. Such issues can arise if a bad key is used during decryption.];  
at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:163) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Elasticsearch.execute(Elasticsearch.java:150) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:75) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:116) ~[elasticsearch-cli-7.11.2.jar:7.11.2]  
at org.elasticsearch.cli.Command.main(Command.java:79) ~[elasticsearch-cli-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:115) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:81) ~[elasticsearch-7.11.2.jar:7.11.2]  
**Caused by: org.elasticsearch.ElasticsearchSecurityException: failed to load SSL configuration [xpack.security.http.ssl]**  
at org.elasticsearch.xpack.core.ssl.SSLService.lambda$loadSSLConfigurations$5(SSLService.java:529) ~[?:?]  
at java.util.HashMap.forEach(HashMap.java:1425) ~[?:?]  
at java.util.Collections$UnmodifiableMap.forEach(Collections.java:1521) ~[?:?]  
at org.elasticsearch.xpack.core.ssl.SSLService.loadSSLConfigurations(SSLService.java:525) ~[?:?]  
at org.elasticsearch.xpack.core.ssl.SSLService.(SSLService.java:143) ~[?:?]  
at org.elasticsearch.xpack.core.XPackPlugin.createSSLService(XPackPlugin.java:458) ~[?:?]  
at org.elasticsearch.xpack.core.XPackPlugin.createComponents(XPackPlugin.java:290) ~[?:?]  
at org.elasticsearch.node.Node.lambda$new$16(Node.java:560) ~[elasticsearch-7.11.2.jar:7.11.2]  
at java.util.stream.ReferencePipeline$7$1.accept(ReferencePipeline.java:271) ~[?:?]  
at java.util.ArrayList$ArrayListSpliterator.forEachRemaining(ArrayList.java:1625) ~[?:?]  
at java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:484) ~[?:?]  
at java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:474) ~[?:?]  
at java.util.stream.ReduceOps$ReduceOp.evaluateSequential(ReduceOps.java:913) ~[?:?]  
at java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:234) ~[?:?]  
at java.util.stream.ReferencePipeline.collect(ReferencePipeline.java:578) ~[?:?]  
at org.elasticsearch.node.Node.(Node.java:564) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.node.Node.(Node.java:278) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Bootstrap$5.(Bootstrap.java:216) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Bootstrap.setup(Bootstrap.java:216) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:387) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:159) ~[elasticsearch-7.11.2.jar:7.11.2]  
... 6 more  
Caused by: org.elasticsearch.ElasticsearchException: failed to initialize SSL TrustManager  
at org.elasticsearch.xpack.core.ssl.StoreTrustConfig.createTrustManager(StoreTrustConfig.java:75) ~[?:?]  
at org.elasticsearch.xpack.core.ssl.SSLService.createSslContext(SSLService.java:438) ~[?:?]  
at java.util.HashMap.computeIfAbsent(HashMap.java:1224) ~[?:?]  
at org.elasticsearch.xpack.core.ssl.SSLService.lambda$loadSSLConfigurations$5(SSLService.java:527) ~[?:?]  
at java.util.HashMap.forEach(HashMap.java:1425) ~[?:?]  
at java.util.Collections$UnmodifiableMap.forEach(Collections.java:1521) ~[?:?]  
at org.elasticsearch.xpack.core.ssl.SSLService.loadSSLConfigurations(SSLService.java:525) ~[?:?]  
at org.elasticsearch.xpack.core.ssl.SSLService.(SSLService.java:143) ~[?:?]  
at org.elasticsearch.xpack.core.XPackPlugin.createSSLService(XPackPlugin.java:458) ~[?:?]  
at org.elasticsearch.xpack.core.XPackPlugin.createComponents(XPackPlugin.java:290) ~[?:?]  
at org.elasticsearch.node.Node.lambda$new$16(Node.java:560) ~[elasticsearch-7.11.2.jar:7.11.2]  
at java.util.stream.ReferencePipeline$7$1.accept(ReferencePipeline.java:271) ~[?:?]  
at java.util.ArrayList$ArrayListSpliterator.forEachRemaining(ArrayList.java:1625) ~[?:?]  
at java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:484) ~[?:?]  
at java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:474) ~[?:?]  
at java.util.stream.ReduceOps$ReduceOp.evaluateSequential(ReduceOps.java:913) ~[?:?]  
at java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:234) ~[?:?]  
at java.util.stream.ReferencePipeline.collect(ReferencePipeline.java:578) ~[?:?]  
at org.elasticsearch.node.Node.(Node.java:564) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.node.Node.(Node.java:278) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Bootstrap$5.(Bootstrap.java:216) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Bootstrap.setup(Bootstrap.java:216) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:387) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:159) ~[elasticsearch-7.11.2.jar:7.11.2]  
... 6 more  
**Caused by: java.io.IOException: keystore password was incorrect**  
at sun.security.pkcs12.PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2103) ~[?:?]  
at sun.security.util.KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:220) ~[?:?]  
at java.security.KeyStore.load(KeyStore.java:1472) ~[?:?]  
at org.elasticsearch.xpack.core.ssl.TrustConfig.getStore(TrustConfig.java:98) ~[?:?]  
at org.elasticsearch.xpack.core.ssl.StoreTrustConfig.createTrustManager(StoreTrustConfig.java:66) ~[?:?]  
at org.elasticsearch.xpack.core.ssl.SSLService.createSslContext(SSLService.java:438) ~[?:?]  
at java.util.HashMap.computeIfAbsent(HashMap.java:1224) ~[?:?]  
at org.elasticsearch.xpack.core.ssl.SSLService.lambda$loadSSLConfigurations$5(SSLService.java:527) ~[?:?]  
at java.util.HashMap.forEach(HashMap.java:1425) ~[?:?]  
at java.util.Collections$UnmodifiableMap.forEach(Collections.java:1521) ~[?:?]  
at org.elasticsearch.xpack.core.ssl.SSLService.loadSSLConfigurations(SSLService.java:525) ~[?:?]  
at org.elasticsearch.xpack.core.ssl.SSLService.(SSLService.java:143) ~[?:?]  
at org.elasticsearch.xpack.core.XPackPlugin.createSSLService(XPackPlugin.java:458) ~[?:?]  
at org.elasticsearch.xpack.core.XPackPlugin.createComponents(XPackPlugin.java:290) ~[?:?]  
at org.elasticsearch.node.Node.lambda$new$16(Node.java:560) ~[elasticsearch-7.11.2.jar:7.11.2]  
at java.util.stream.ReferencePipeline$7$1.accept(ReferencePipeline.java:271) ~[?:?]  
at java.util.ArrayList$ArrayListSpliterator.forEachRemaining(ArrayList.java:1625) ~[?:?]  
at java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:484) ~[?:?]  
at java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:474) ~[?:?]  
at java.util.stream.ReduceOps$ReduceOp.evaluateSequential(ReduceOps.java:913) ~[?:?]  
at java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:234) ~[?:?]  
at java.util.stream.ReferencePipeline.collect(ReferencePipeline.java:578) ~[?:?]  
at org.elasticsearch.node.Node.(Node.java:564) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.node.Node.(Node.java:278) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Bootstrap$5.(Bootstrap.java:216) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Bootstrap.setup(Bootstrap.java:216) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:387) ~[elasticsearch-7.11.2.jar:7.11.2]  
at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:159) ~[elasticsearch-7.11.2.jar:7.11.2]  
... 6 more  
[root@node-1 ~]#

```auto

```

Also my elasticsearch.yml configurations:

```auto
# Security
xpack.monitoring.enabled: true
xpack.monitoring.collection.enabled: true
transport.tcp.compress: true

xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: certs/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: certs/elastic-certificates.p12
xpack.security.transport.ssl.keystore.secure_password: "mypassword"
xpack.security.transport.ssl.truststore.secure_password: "mypassword"

# This turns on SSL for HTTP (Rest) interface
xpack.security.http.ssl.enabled: true

#This configures keystore to use for SSL on HTTP
xpack.security.http.ssl.verification_mode: certificate
xpack.security.http.ssl.keystore.path: certs/http.p12
xpack.security.http.ssl.truststore.path: certs/http.p12
xpack.security.authc.api_key.enabled: true
xpack.security.http.ssl.client_authentication: optional

```

Can someone please help me on how can I fix this? I'm not sure where I did wrong, I tried to troubleshoot but I keep getting the same errors.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 24, 2021, 2:48am UTC](https://discuss.elastic.co/t/unable-to-load-ssl-configuration-for-elasticsearch/268087/2 "2021-03-24T02:48:24Z")

</div>

> [@runchranda](#):
>
> ```auto
> xpack.security.transport.ssl.keystore.secure_password: "mypassword"
> xpack.security.transport.ssl.truststore.secure_password: "mypassword"
> 
> ```

You cannot set `secure_password` in the YAML, you need to add it to the [Elasticsearch keystore](https://www.elastic.co/guide/en/elasticsearch/reference/7.11/secure-settings.html).

> [@runchranda](#):
>
> ```auto
> xpack.security.http.ssl.truststore.path: certs/http.p12
> 
> ```

Did you apply a password when you created this file? The error is complaining that the password for this file is incorrect.

---

<div class="post-metadata">

**Author:** ![runchranda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/runchranda/32/85951_2.png) [@runchranda](https://discuss.elastic.co/u/runchranda)\
**Post date:** [March 24, 2021, 5:50am UTC](https://discuss.elastic.co/t/unable-to-load-ssl-configuration-for-elasticsearch/268087/3 "2021-03-24T05:50:07Z")

</div>

Does that mean I should remove these parameter settings from the elastic yaml file?

> [@runchranda](#):
>
> ```auto
> xpack.security.transport.ssl.keystore.secure_password: "mypassword"
> xpack.security.transport.ssl.truststore.secure_password: "mypassword"
> 
> ```

I also have added the secure password settings to the Elasticsearch keystore as you suggest, but I'm not sure if I did it correctly. Could you help take a look at the snippet below and verify it?

```auto
    root@node-3 bin]# /usr/share/elasticsearch/bin/elasticsearch-keystore list
    Enter password for the elasticsearch keystore :
    keystore.seed
    xpack.security.http.ssl.keystore.secure_password
    xpack.security.http.ssl.truststore.secure_password
    xpack.security.transport.ssl.keystore.secure_password
    xpack.security.transport.ssl.truststore.secure_password
    [root@node-3 bin]#

```

---

<div class="post-metadata">

**Author:** ![runchranda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/runchranda/32/85951_2.png) [@runchranda](https://discuss.elastic.co/u/runchranda)\
**Post date:** [March 24, 2021, 6:04am UTC](https://discuss.elastic.co/t/unable-to-load-ssl-configuration-for-elasticsearch/268087/4 "2021-03-24T06:04:42Z")

</div>

I comment out these parameters settings in the Elasticsearch YAML file

```auto
xpack.security.transport.ssl.keystore.secure_password: "mypassword"
xpack.security.transport.ssl.truststore.secure_password: "mypassword"

```

Then I restart the elasticsearch service, but I got another error below which from what I see it **"failed to read keystore password on console"**. What could be the cause of this?

```auto
-- Unit elasticsearch.service has begun starting up.
Mar 24 13:56:43 node-3 kernel: xfs filesystem being remounted at /tmp supports timestamps until 2038 (0x7fffffff)
Mar 24 13:56:43 node-3 kernel: xfs filesystem being remounted at /var/tmp supports timestamps until 2038 (0x7fffffff)
Mar 24 13:56:44 node-3 systemd-entrypoint[7368]: Failed to read keystore password on console
Mar 24 13:56:44 node-3 systemd[1]: elasticsearch.service: main process exited, code=exited, status=1/FAILURE
Mar 24 13:56:44 node-3 systemd[1]: Failed to start Elasticsearch.
-- Subject: Unit elasticsearch.service has failed
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
--
-- Unit elasticsearch.service has failed.

```

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 24, 2021, 6:20am UTC](https://discuss.elastic.co/t/unable-to-load-ssl-configuration-for-elasticsearch/268087/5 "2021-03-24T06:20:57Z")

</div>

> [@runchranda](#):
>
> `Mar 24 13:56:44 node-3 systemd-entrypoint[7368]: Failed to read keystore password on console`

It looks like you have a password on the elasticsearch keystore.

If that is the case you need to provide that password to systemd, see: [Starting Elasticsearch | Elasticsearch Guide [7.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.11/starting-elasticsearch.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2021, 6:20am UTC](https://discuss.elastic.co/t/unable-to-load-ssl-configuration-for-elasticsearch/268087/6 "2021-04-21T06:20:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
