# Unable to setup Elasticsearch python instance on https

**URL:** <https://discuss.elastic.co/t/unable-to-setup-elasticsearch-python-instance-on-https/311018>\
**Category:** Elasticsearch\
**Created:** [July 29, 2022, 8:26pm UTC](https://discuss.elastic.co/t/unable-to-setup-elasticsearch-python-instance-on-https/311018 "2022-07-29T20:26:46Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Edinpain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/edinpain/32/109040_2.png) [@Edinpain](https://discuss.elastic.co/u/Edinpain)\
**Post date:** [July 29, 2022, 8:26pm UTC](https://discuss.elastic.co/t/unable-to-setup-elasticsearch-python-instance-on-https/311018/1 "2022-07-29T20:26:46Z")

</div>

Sweet lord it's been a long day. Ubuntu newb, ~0 zero knowledge in cryptography certificates. Creating a flask project and want to follow this [tutorial](https://blog.miguelgrinberg.com/post/the-flask-mega-tutorial-part-xvi-full-text-search?need=help) to use elastic to index my postgres + sqlalchemy database.

Python: 3.1+  
Ubuntu: 22.04 LTS  
Elastic: 8.3.3

When I failed to setup instance with `pip3 install elastisearch` I embarked on a mission to install elastic on Ubuntu. After some sweat, managed to get json response via curl. So service is running. However elastic service is nowhere to be found in `service --status-all`  
What is up with that?!

I don't even know if installing along this [tutorial](https://www.elastic.co/guide/en/elasticsearch/reference/current/deb.html) was necessary when using python...

I failed to generate .pem file using certutils. I managed to generate .zip with .crt and .key inside. However [documentation on website](https://www.elastic.co/guide/en/elasticsearch/client/python-api/current/config.html) suggests using .pem: `ca_certs="/path/to/certs.pem"` HOW?

`ssl_assert_fingerprint` in documenation is like ~50 chrs long. my fingerprint is like 2000 chars long and is in file.

This [documentation](https://elasticsearch-py.readthedocs.io/en/v8.3.3/index.html) has nothing on https connection. This [one does](https://elasticsearch-py.readthedocs.io/en/master/#tls-ssl-and-authentication), but when I use:

`es = Elasticsearch(['https://elastic:<password>@localhost:9200'])`  
`es.ping()` returns `False`.

however on browser when I goto `https://localhost:9200` go pass chrome security warnings and enter login: elastic and password issued at elastic setup I do get json response back.

People, HELP.

---

<div class="post-metadata">

**Author:** ![Edinpain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/edinpain/32/109040_2.png) [@Edinpain](https://discuss.elastic.co/u/Edinpain)\
**Post date:** [July 30, 2022, 6:46am UTC](https://discuss.elastic.co/t/unable-to-setup-elasticsearch-python-instance-on-https/311018/2 "2022-07-30T06:46:22Z")

</div>

After more hours on this. I found this stackoverflow, and followed setting permissions for my user (not "root", not "elastic").

when I run:  
`/usr/share/elasticsearch/bin/elasticsearch`

bunch of logging takes place and last lines before ending (not exiting though) are:

```auto
[2022-07-30T09:03:54,729][INFO][o.e.i.g.DatabaseNodeService] [<myuser>] successfully loaded geoip database file [GeoLite2-Country.mmdb]
[2022-07-30T09:03:54,811][INFO][o.e.i.g.DatabaseNodeService] [<myuser>] successfully loaded geoip database file [GeoLite2-ASN.mmdb]
[2022-07-30T09:03:55,944][INFO][o.e.i.g.DatabaseNodeService] [<myuser>] successfully loaded geoip database file [GeoLite2-City.mmdb]

```

I assume I launched elastic?

when I go to browser and go to `https://127.0.0.1:9200` I tied logging in with two times (failed), then finally with elastic user and provided pass on installation.

This gets added in terminal  
`[2022-07-30T09:06:20,118][WARN][o.e.x.s.t.n.SecurityNetty4HttpServerTransport [<myuser>] http client did not trust this server's certificate, closing connection Netty4HttpChannel{localAddress=/127.0.0.1:9200, remoteAddress=/127.0.0.1:44032}`

Launching service with:  
`systemctl start elasticsearch.service `  
gives:

`Job for elasticsearch.service failed because the control process exited with error code. See "systemctl status elasticsearch.service" and "journalctl -xeu elasticsearch.service" for details.`

`systemctl status elasticsearch.service`  
gives error:

`liep. 30 09:17:22 <myuser> systemd-entrypoint[20435]: /usr/share/elasticsearch/bin/elasticsearch-env: line 78: /etc/default/elasticsearch: Permission denied>`

`ls -l` viewing from gives:  
`-rw-rw---- 1 <myuser> <myuser> 688 liep. 30 09:17 /etc/default/elasticsearch`

Since `/etc/default/elasticsearch` is a config file from what I can see and it has a read and write permissions, what's wrong?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 2, 2022, 1:59am UTC](https://discuss.elastic.co/t/unable-to-setup-elasticsearch-python-instance-on-https/311018/3 "2022-08-02T01:59:56Z")

</div>

Welcome to our community! 😃

Generally you would install Elasticsearch via the apt/deb method, as [you linked](https://www.elastic.co/guide/en/elasticsearch/reference/current/deb.html), then install the python client and interact with Elasticsearch there.

> [@Edinpain](#):
>
> I assume I launched elastic?

Yes, that looks right.

Regarding your other issues following this, how did you install Elasticsearch exactly?

---

<div class="post-metadata">

**Author:** ![Edinpain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/edinpain/32/109040_2.png) [@Edinpain](https://discuss.elastic.co/u/Edinpain)\
**Post date:** [August 2, 2022, 7:22am UTC](https://discuss.elastic.co/t/unable-to-setup-elasticsearch-python-instance-on-https/311018/4 "2022-08-02T07:22:41Z")

</div>

Hey, thanks for engaging. Through deb package. Adding GPG keys, url to apt package index, etc. Obviously messed up at some point.

Another observation: I can't login to elasticsearch user using  
`su elasticsearch` with provided password on installation.

Just a reminder, I changed ownership to myself, referred in my question as `<myuser>` from user `elasticsearch`.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 2, 2022, 8:10am UTC](https://discuss.elastic.co/t/unable-to-setup-elasticsearch-python-instance-on-https/311018/5 "2022-08-02T08:10:12Z")

</div>

> [@Edinpain](#):
>
> `su elasticsearch` with provided password on installation.

What are you trying to do what that user?

---

<div class="post-metadata">

**Author:** ![Edinpain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/edinpain/32/109040_2.png) [@Edinpain](https://discuss.elastic.co/u/Edinpain)\
**Post date:** [August 2, 2022, 8:23am UTC](https://discuss.elastic.co/t/unable-to-setup-elasticsearch-python-instance-on-https/311018/6 "2022-08-02T08:23:21Z")

</div>

Nothing, just providing additional info about my setup. Main issue (edit: at least what I perceive to be the main issue):

```auto
<myuser>@<myuser>:~$ sudo systemctl start elasticsearch
[sudo] password for <myuser>: 
Job for elasticsearch.service failed because the control process exited with error code.
See "systemctl status elasticsearch.service" and "journalctl -xeu elasticsearch.service" for details.

```

Although I did not setup service journal, I tracked down the problematic permissions line in reply above.  
`liep. 30 09:17:22 <myuser> systemd-entrypoint[20435]: /usr/share/elasticsearch/bin/elasticsearch-env: line 78: /etc/default/elasticsearch: Permission denied>`

But for and group, both read and write permissions are present.  
`-rw-rw---- 1 <myuser> <myuser> 688 liep. 30 09:17 /etc/default/elasticsearch`

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 2, 2022, 1:32pm UTC](https://discuss.elastic.co/t/unable-to-setup-elasticsearch-python-instance-on-https/311018/7 "2022-08-02T13:32:30Z")

</div>

Changing user / groups on the elastic installed files is not best practice and can lead to issues much like your experiencing.

Curious why you You did this in the first place... What are you trying to accomplish?

Elasticsearch is designed to run in a specific user and group when it's installed.

---

<div class="post-metadata">

**Author:** ![Edinpain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/edinpain/32/109040_2.png) [@Edinpain](https://discuss.elastic.co/u/Edinpain)\
**Post date:** [August 2, 2022, 5:05pm UTC](https://discuss.elastic.co/t/unable-to-setup-elasticsearch-python-instance-on-https/311018/8 "2022-08-02T17:05:27Z")

</div>

You are right. Changed back ownership to `elasticsearch` and service starts.

My conclusion: probably missed configuration part at first, changed rights (just trying stackoverflow solutions), then finished up config and missed the last part of giving rights back to `elasticsearch` user.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2022, 5:06pm UTC](https://discuss.elastic.co/t/unable-to-setup-elasticsearch-python-instance-on-https/311018/9 "2022-08-30T17:06:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
