# Which certificate do I need for an external Java client linked to a self-hosted docker Elasticsearch 8.x, since the self-signed http\_ca.crt does not function unless the Java client is installed locally on the same server?

**URL:** <https://discuss.elastic.co/t/which-certificate-do-i-need-for-an-external-java-client-linked-to-a-self-hosted-docker-elasticsearch-8-x-since-the-self-signed-http-ca-crt-does-not-function-unless-the-java-client-is-installed-locally-on-the-same-server/324159>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, docker\
**Created:** [January 28, 2023, 12:45pm UTC](https://discuss.elastic.co/t/which-certificate-do-i-need-for-an-external-java-client-linked-to-a-self-hosted-docker-elasticsearch-8-x-since-the-self-signed-http-ca-crt-does-not-function-unless-the-java-client-is-installed-locally-on-the-same-server/324159 "2023-01-28T12:45:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![m.jaafar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/m.jaafar/32/116271_2.png) [@m.jaafar](https://discuss.elastic.co/u/m.jaafar)\
**Post date:** [January 28, 2023, 12:45pm UTC](https://discuss.elastic.co/t/which-certificate-do-i-need-for-an-external-java-client-linked-to-a-self-hosted-docker-elasticsearch-8-x-since-the-self-signed-http-ca-crt-does-not-function-unless-the-java-client-is-installed-locally-on-the-same-server/324159/1 "2023-01-28T12:45:46Z")

</div>

I understand that when I set up a docker image of elasticsearch version 8.x, the security is automatically activated, and three certificates are produced in the config/certs/ directory, which are:

- `http_ca.crt`: The CA certificate that is used to sign the certificates for the HTTP layer
- `http.p12`: Keystore that contains the key and certificate for the HTTP layer
- `transport.p12`: Keystore that contains the key and certificate for the transport layer

I also created a Java client that accepts a CA certificate and converts it to an SSLContext. I obtained the CA certificate by copying and opening the `http ca.crt` certificate using the following command:

```auto
docker cp esdemo01:/usr/share/elasticsearch/config/certs/http_ca.crt .

```

Now, when I try to connect the external Java client to the elasticsearch server using `http ca.crt` and using the url `<server-IP-address>:9200`, it refuses to connect. Using this command:

```auto
docker logs esdemo01

```

I can see that there is an issue in the elasticsearch logs which is :  
`http client did not trust this server's certificate, closing connection`

But when I test a Java client which is found locally on the same server as the elasticsearch, and uses the same exact `http_ca.crt` certificate and connects to the elasticsearch via `localhost:9200` its working fine, and is allowing me to add and call data.

So, which certificate do I need, what certificate do I need, what am I missing? I even followed the instructions for creating a `elastic-stack-ca.p12`, but I don't know how to proceed after this, I don't know if the `elastic-stack-ca.p12` has worked or not.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [January 31, 2023, 4:19am UTC](https://discuss.elastic.co/t/which-certificate-do-i-need-for-an-external-java-client-linked-to-a-self-hosted-docker-elasticsearch-8-x-since-the-self-signed-http-ca-crt-does-not-function-unless-the-java-client-is-installed-locally-on-the-same-server/324159/2 "2023-01-31T04:19:40Z")

</div>

The HTTP certificate's subjectAlternativeNames (`localhost` etc) do not match your docker container's external IP address. SSL by default verifies hostname and it fails because they do not match.

You can either create your own HTTP certificate with matching subjectAlternativeNames or configure your HTTP client to skip hostname verification.

---

<div class="post-metadata">

**Author:** ![m.jaafar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/m.jaafar/32/116271_2.png) [@m.jaafar](https://discuss.elastic.co/u/m.jaafar)\
**Post date:** [January 31, 2023, 9:20am UTC](https://discuss.elastic.co/t/which-certificate-do-i-need-for-an-external-java-client-linked-to-a-self-hosted-docker-elasticsearch-8-x-since-the-self-signed-http-ca-crt-does-not-function-unless-the-java-client-is-installed-locally-on-the-same-server/324159/3 "2023-01-31T09:20:08Z")

</div>

Thanks for answering. I am trying to figure out the terms you just gave me, and how they all link to each other and my own problem:

- **HTTP certificate's subjectAlternativeNames** : Is this field related to why in another test project I got the following error:  
`Host name '<Server-IP-Address>' does not match the certificate subject provided by the peer (CN=b641a36b1bc9)`
- **docker container's external IP address**
- **hostname**

After using this command

```auto
sudo docker container inspect esdemo01

```

Several properties caught my eye:

Is This the **hostname** you are talking about??

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/6/0649121d8752db7900fc815b6e6d16ef813b6b23.png)

And is this the **docker container's external IP address** you talked about??  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/0/10bfd953ec56eb3e814b2f05e957966ce53e9aa9.png)

So, what you are telling me is that the `http_ca.crt` is created with a **HTTP certificate's subjectAlternativeNames** for the  
`"Hostname": "b641a36b1bc9"` for the IP address `"IPAddress": "172.20.0.2"` and not the `<Server-IP-Address>:9200` and that if I want to fix the issue I have to create one for the `<Server-IP-Address>:9200` instead of `172.20.0.2`

---

<div class="post-metadata">

**Author:** ![m.jaafar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/m.jaafar/32/116271_2.png) [@m.jaafar](https://discuss.elastic.co/u/m.jaafar)\
**Post date:** [February 1, 2023, 2:06pm UTC](https://discuss.elastic.co/t/which-certificate-do-i-need-for-an-external-java-client-linked-to-a-self-hosted-docker-elasticsearch-8-x-since-the-self-signed-http-ca-crt-does-not-function-unless-the-java-client-is-installed-locally-on-the-same-server/324159/4 "2023-02-01T14:06:41Z")

</div>

After a lot of digging, I finally managed to get it to work, I am leaving the way I did it here for anyone facing the same issue I had:

1. use the following command to generate a new http keystore

```bash
./bin/elasticsearch-certutil http

```

```auto
./bin/elasticsearch-certutil http

Generate a CSR? [y/N] N
Use an existing CA? [y/N] N
Do you wish to change any of these options? [y/N] y

CA Name [CN=Elasticsearch HTTP CA] [server-ip-address]

CA Validity [5y] 60y

We recommend that you use one of 2048, 3072 or 4096 bits for your key.
Key Size [2048] [ENTER]

Do you wish to change any of these options? [y/N] [N]

CA password: [<ENTER> for none] 123456
Repeat password to confirm: 123456

For how long should your certificate be valid? [5y] [ENTER]
Generate a certificate per node? [y/N]N

Enter all the hostnames that you need, one per line.
When you are done, press <ENTER> once more to move on to the next step.

[server-ip-address]:[port]

You entered the following hostnames.

 - [server-ip-address]

Is this correct [Y/n]Y

Key Name: [info]
Subject DN: CN=[info], DC=[info], DC=[info]
Key Size: 2048

Do you wish to change any of these options? [y/N]N

If you wish to use a blank password, simply press <enter> at the prompt below.
Provide a password for the "http.p12" file: [<ENTER> for none] 123456
Repeat password to confirm: 123456

What filename should be used for the output zip file? [/usr/share/elasticsearch/elasticsearch-ssl-http.zip] [ENTER]

Zip file written to [docker-cotainer]:/usr/share/elasticsearch/elasticsearch-ssl-http.zip

```

exit the container after you finish using the command `exit`

1. Move the zip file outside the docker container using the following command:

```bash
docker cp [container-name]:/usr/share/elasticsearch/ **elasticsearch-ssl-http.zip .**

```

It is important to move the file outside the docker container so we can manipulate it with the linux commands that do not exist inside the docker container itself.

1. Unzip the default file: **`elasticsearch-ssl-http.zip`** using the **`unzip`** linux library with this command:

```bash
unzip elasticsearch-ssl-http.zip

```

> In case the unzip linux library does not exist, you need to install it, using the command

```bash
sudo apt install unzip

```

1. After you unzip the files, we want its content, the `http.p12` found in the path `/elasticsearch/` , we want to replace the default `http.p12` in the docker image in `config/certs/http.p12` with the one in the unziped folder at `elasticsearch/http.p12` . To replace folders in any docker container: `just copy over it` using the `docker cp` command:

```bash
docker cp [name-of-the-file-we-want-to-copy] [dokcer-container-name]:/usr/share/elasticsearch/config/certs/http.p12

```

1. Re-eneter the docker container(like we did in step 1) and Change the default password of the replaced default http.p12 keystore, using the following command

```bash
./bin/elasticsearch-keystore add "xpack.security.http.ssl.keystore.secure_password" 

```

exit the container after you finish using the command `exit`

1. Do not forget to restart the docker container so changes can take effect

```bash
docker restart [name-of-container]

```

1. Generate the `.pem` file to use in external clients, using this command:

```bash
openssl pkcs12 -nodes -in http.p12 -out http.pem

```

1. Open the generated `.pem` file using the following command:

```bash
cat http.pem

```

Copy the contained charachters to the java client, and make sure its in a straight line(minified), I usually do it by copying and pasting it in google chrome searchbar which condenses it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2023, 2:06pm UTC](https://discuss.elastic.co/t/which-certificate-do-i-need-for-an-external-java-client-linked-to-a-self-hosted-docker-elasticsearch-8-x-since-the-self-signed-http-ca-crt-does-not-function-unless-the-java-client-is-installed-locally-on-the-same-server/324159/5 "2023-03-01T14:06:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
