# Unable to retrieve version information from Elasticsearch nodes. unable to verify the first certificate

**URL:** https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-verify-the-first-certificate/298371
**Category:** Kibana
**Tags:** docker
**Created:** [February 28, 2022, 4:59am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-verify-the-first-certificate/298371 "2022-02-28T04:59:55Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![shmelkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shmelkin/32/101975_2.png) [@shmelkin](https://discuss.elastic.co/u/shmelkin)
#### Post date: [February 28, 2022, 4:59am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-verify-the-first-certificate/298371/1 "2022-02-28T04:59:55Z")

</div>

I'm running a one node Elastic cluster with Elasticsearch and Kibana. The configuration worked before on an earlier version about a year ago, however, after Kibanas version automatically updated due to new container images, the following error started appearing:

kubectl logs kibana-pod

```auto
{"type":"log","@timestamp":"2022-02-21T08:47:48+00:00","tags":["error","Elasticsearch-service"],"pid":7,"message":"Unable to retrieve version information from Elasticsearch nodes. unable to verify the first certificate"}

```

kubectl version

```auto
Client Version: version.Info{Major:"1", Minor:"23", GitVersion:"v1.23.3", GitCommit:"816c97ab8cff8a1c72eccca1026f7820e93e0d25", GitTreeState:"clean", BuildDate:"2022-01-25T21:25:17Z", GoVersion:"go1.17.6", Compiler:"gc", Platform:"linux/amd64"}
Server Version: version.Info{Major:"1", Minor:"23", GitVersion:"v1.23.3", GitCommit:"816c97ab8cff8a1c72eccca1026f7820e93e0d25", GitTreeState:"clean", BuildDate:"2022-01-25T21:19:12Z", GoVersion:"go1.17.6", Compiler:"gc", Platform:"linux/amd64"}

```

kubeadm version

```auto
kubeadm version: &version.Info{Major:"1", Minor:"23", GitVersion:"v1.23.3", GitCommit:"816c97ab8cff8a1c72eccca1026f7820e93e0d25", GitTreeState:"clean", BuildDate:"2022-01-25T21:24:08Z", GoVersion:"go1.17.6", Compiler:"gc", Platform:"linux/amd64"}

```

I use Let'sEncrypt certificates for Elasticsearch and Kibana. I also renewed the certificates to make sure the configuration has fresh ones.

I use the helm charts for both Elasticsearch and Kibana, however, I use some custom values:

kibana\_values.yaml

```auto
---
elasticsearchHosts: "https://redacted"

extraEnvs:
  - name: "NODE_OPTIONS"
    value: "--max-old-space-size=1800"
  - name: 'ELASTICSEARCH_USERNAME'
    valueFrom:
      secretKeyRef:
        name: elastic-credentials
        key: username
  - name: 'ELASTICSEARCH_PASSWORD'
    valueFrom:
      secretKeyRef:
        name: elastic-credentials
        key: password
  - name: 'KIBANA_ENCRYPTION_KEY'
    valueFrom:
      secretKeyRef:
        name: kibana
        key: encryptionkey

secretMounts:
  - name: elastic-certificates
    secretName: elastic-certificates
    path: /usr/share/kibana/config/certs-gen/

kibanaConfig:
  kibana.yml: |
    server.ssl:
      enabled: true
      key: /usr/share/kibana/config/certs-gen/privkey2.pem
      certificate: /usr/share/kibana/config/certs-gen/cert2.pem
    xpack.reporting.encryptionKey: ${KIBANA_ENCRYPTION_KEY}
    xpack.security.encryptionKey: ${KIBANA_ENCRYPTION_KEY}
    xpack.encryptedSavedObjects.encryptionKey: ${KIBANA_ENCRYPTION_KEY}
    elasticsearch.ssl:
      certificateAuthorities: /usr/share/kibana/config/certs-gen/fullchain2.pem
      verificationMode: certificate

protocol: https

service:
  type: NodePort
  loadBalancerIP: ""
  port: 5601
  nodePort: 30002
  labels: {}
  annotations: {}
  loadBalancerSourceRanges: []
  httpPortName: http

```

These are the values for my elastic\_search.yml

```auto
replicas: 1
minimumMasterNodes: 1

esConfig:
   elasticsearch.yml: |
     xpack.security.enabled: true
     xpack.security.transport.ssl.enabled: true
     xpack.security.transport.ssl.verification_mode: certificate
     xpack.security.transport.ssl.key: /usr/share/elasticsearch/config/certs-gen/privkey2.pem
     xpack.security.transport.ssl.certificate: /usr/share/elasticsearch/config/certs-gen/cert2.pem
     xpack.security.transport.ssl.certificate_authorities: ["/usr/share/elasticsearch/config/certs-gen/fullchain2.pem"]
     xpack.security.http.ssl.enabled: true
     xpack.security.http.ssl.verification_mode: certificate
     xpack.security.http.ssl.key: /usr/share/elasticsearch/config/certs-gen/privkey2.pem
     xpack.security.http.ssl.certificate: /usr/share/elasticsearch/config/certs-gen/cert2.pem
     xpack.security.http.ssl.certificate_authorities: ["/usr/share/elasticsearch/config/certs-gen/fullchain2.pem"]

extraEnvs:
  - name: ELASTIC_PASSWORD
    valueFrom:
      secretKeyRef:
        name: elastic-credentials
        key: password
  - name: ELASTIC_USERNAME
    valueFrom:
      secretKeyRef:
        name: elastic-credentials
        key: username
secretMounts:
  - name: elastic-certificates
    secretName: elastic-certificates
    path: /usr/share/elasticsearch/config/certs-gen/
protocol: https
service:
  labels: {}
  labelsHeadless: {}
  type: NodePort
  nodePort: 30001
  annotations: {}
  httpPortName: http
  transportPortName: transport
  loadBalancerIP: ""
  loadBalancerSourceRanges: []
  externalTrafficPolicy: ""
  clusterHealthCheckParams: "wait_for_status=green&timeout=1s"

```

---

<div class="post-metadata">

### Author: ![shmelkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shmelkin/32/101975_2.png) [@shmelkin](https://discuss.elastic.co/u/shmelkin)
#### Post date: [February 28, 2022, 12:54pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-verify-the-first-certificate/298371/2 "2022-02-28T12:54:15Z")

</div>

The solution is to change:

```auto
kibanaConfig:
  kibana.yml: |
    server.ssl:
      enabled: true
      key: /usr/share/kibana/config/certs-gen/privkey2.pem
      certificate: /usr/share/kibana/config/certs-gen/cert2.pem
    xpack.reporting.encryptionKey: ${KIBANA_ENCRYPTION_KEY}
    xpack.security.encryptionKey: ${KIBANA_ENCRYPTION_KEY}
    xpack.encryptedSavedObjects.encryptionKey: ${KIBANA_ENCRYPTION_KEY}
    elasticsearch.ssl:
      certificateAuthorities: /usr/share/kibana/config/certs-gen/fullchain2.pem
      verificationMode: certificate

```

to

```auto
kibanaConfig:
  kibana.yml: |
    server.ssl:
      enabled: true
      keystore.path: /usr/share/kibana/config/certs-gen/keystore.pkcs12
      truststore.path: /usr/share/kibana/config/certs-gen/keystore.pkcs12
      keystore.password: ""
      truststore.password: ""
    xpack.reporting.encryptionKey: ${KIBANA_ENCRYPTION_KEY}
    xpack.security.encryptionKey: ${KIBANA_ENCRYPTION_KEY}
    xpack.encryptedSavedObjects.encryptionKey: ${KIBANA_ENCRYPTION_KEY}

```

and

```auto
esConfig:
   elasticsearch.yml: |
     xpack.security.enabled: true
     xpack.security.transport.ssl.enabled: true
     xpack.security.transport.ssl.verification_mode: certificate
     xpack.security.transport.ssl.key: /usr/share/elasticsearch/config/certs-gen/privkey2.pem
     xpack.security.transport.ssl.certificate: /usr/share/elasticsearch/config/certs-gen/cert2.pem
     xpack.security.transport.ssl.certificate_authorities: ["/usr/share/elasticsearch/config/certs-gen/fullchain2.pem"]
     xpack.security.http.ssl.enabled: true
     xpack.security.http.ssl.verification_mode: certificate
     xpack.security.http.ssl.key: /usr/share/elasticsearch/config/certs-gen/privkey2.pem
     xpack.security.http.ssl.certificate: /usr/share/elasticsearch/config/certs-gen/cert2.pem
     xpack.security.http.ssl.certificate_authorities: ["/usr/share/elasticsearch/config/certs-gen/fullchain2.pem"]

```

to

```auto
esConfig:
   elasticsearch.yml: |
     xpack.security.transport.ssl.enabled: true
     xpack.security.transport.ssl.verification_mode: certificate
     xpack.security.transport.ssl.keystore.path: /usr/share/elasticsearch/config/certs-gen/keystore.pkcs12
     xpack.security.transport.ssl.truststore.path: /usr/share/elasticsearch/config/certs-gen/keystore.pkcs12
     xpack.security.http.ssl.enabled: true
     xpack.security.http.ssl.truststore.path: /usr/share/elasticsearch/config/certs-gen/keystore.pkcs12
     xpack.security.http.ssl.keystore.path: /usr/share/elasticsearch/config/certs-gen/keystore.pkcs12
     xpack.security.enabled: true

```

both stores were generated as follows:

```auto
cat privkey2.pem > store.pem
cat cert2.pem >> store.pem
openssl pkcs12 -export -in store.pem -out keystore.pkcs12

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 28, 2022, 12:54pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-verify-the-first-certificate/298371/3 "2022-03-28T12:54:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
