# User\_bundle from internal Artifactory problem

**URL:** <https://discuss.elastic.co/t/user-bundle-from-internal-artifactory-problem/263087>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Created:** [February 3, 2021, 8:04am UTC](https://discuss.elastic.co/t/user-bundle-from-internal-artifactory-problem/263087 "2021-02-03T08:04:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zerobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zerobot/32/48977_2.png) [@Zerobot](https://discuss.elastic.co/u/Zerobot)\
**Post date:** [February 3, 2021, 8:04am UTC](https://discuss.elastic.co/t/user-bundle-from-internal-artifactory-problem/263087/1 "2021-02-03T08:04:52Z")

</div>

Hi!

I'm trying to add a custom cacerts.zip User\_Bundle to my ELK deployment in our ECE.  
Elasticsearch is bootlooping and the reason is an untrusted certificate.

```auto
    "elasticsearch": {
      "user_bundles": [
       {
        "elasticsearch_version": "7.*",
        "name": "ldap-cert",
        "url": "https://<artifactory_address>/cacerts.zip"
      }
    ],
    "version": "7.10.2"
   },

```

My problem is - the certificate of artificatory is signed by my company's CA, I can't do much about that.  
I'm able to download this bundle on the VM ECE is installed on but I can't from inside of Elasticsearch containers.

Is there any way to ignore cert verification like wget does?

```auto
wget --no-check-certificate

```

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [February 3, 2021, 1:47pm UTC](https://discuss.elastic.co/t/user-bundle-from-internal-artifactory-problem/263087/2 "2021-02-03T13:47:42Z")

</div>

Unfortunately this is a known issue

The workarounds until we fix it (there are plans, but no ETA) are:

- Run an nginx container on each allocator that will proxy to the artifactory
- (not supported `(*)`) unzip the stackpack, add `--no-check-certificate` to the `wget` in `elasticsearch.sh`, rezip, and re-upload

Apologies - we appreciate neither workaround is great

`(*)` in the sense that issues with a custom stackpack might come down to "does it fail in the same way with the supported stackpack"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2021, 11:32am UTC](https://discuss.elastic.co/t/user-bundle-from-internal-artifactory-problem/263087/4 "2021-02-26T11:32:04Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
