# Unable to retrieve version information from Elasticsearch nodes. unable to get local issuer certificate

**URL:** <https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-local-issuer-certificate/281008>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, docker\
**Created:** [August 11, 2021, 7:44am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-local-issuer-certificate/281008 "2021-08-11T07:44:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![auasad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/auasad/32/92826_2.png) [@auasad](https://discuss.elastic.co/u/auasad)\
**Post date:** [August 11, 2021, 7:44am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-local-issuer-certificate/281008/1 "2021-08-11T07:44:16Z")

</div>

Hello community, I have setup an elk stack following the URL;

### Run in Docker with TLS enabled

> **[Run in Docker with TLS enabled - Running the Elastic Stack on Docker | Getting...](https://www.elastic.co/guide/en/elastic-stack-get-started/7.14/get-started-docker.html#get-started-docker-tls)**

everything setup successfully with elastic default settings, but I want to configure Letsencrypt SSL for http instead of es01.crt.  
For that I have created SSL using Letsencrypt and also deployed successfully on kibana, lines are given below;

```auto
      ELASTICSEARCH_SSL_CERTIFICATEAUTHORITIES: $CERTS_DIR/ca/ca.crt
      SERVER_SSL_ENABLED: "true"
      SERVER_SSL_KEY: $CERTS_DIR/kib01/privkey.pem
      SERVER_SSL_CERTIFICATE: $CERTS_DIR/kib01/fullchain.pem

```

but when I try with es01, es02 and es03 nodes, as given below;

```-
   - xpack.security.http.ssl.key=$CERTS_DIR/es02/privkey.pem
   - xpack.security.http.ssl.certificate=$CERTS_DIR/es02/fullchain.pem

```

all the container launched successfully and in running state, but at browser I only see the message ;

"Kibana server is not ready yet"

and here are the lines from container logs;  
kib01 container  
"error","savedobjects-service"],"pid":1213,"message":"Unable to retrieve version information from Elasticsearch nodes. unable to get local issuer certificate"}

es01 container  
javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate"

anyone please guide me about it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2021, 7:44am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-local-issuer-certificate/281008/2 "2021-09-08T07:44:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
