# \[x-pack\] enabled: Unable to communicate to Elasticsearch using only cacert from client machines

**URL:** <https://discuss.elastic.co/t/x-pack-enabled-unable-to-communicate-to-elasticsearch-using-only-cacert-from-client-machines/194280>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 7, 2019, 3:55pm UTC](https://discuss.elastic.co/t/x-pack-enabled-unable-to-communicate-to-elasticsearch-using-only-cacert-from-client-machines/194280 "2019-08-07T15:55:07Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 8, 2019, 4:28pm UTC](https://discuss.elastic.co/t/x-pack-enabled-unable-to-communicate-to-elasticsearch-using-only-cacert-from-client-machines/194280/6 "2019-08-08T16:28:50Z")

</div>

> [@vijayakrishna.rg](#):
>
> ```auto
> these are used for http communication
> 1. nprod-elastic-client.key
> 2. nprod-elastic-client.pem
> 3. cacert
> 
> ```

As I said above, you need a different pair for the server and a different for the client. You can't use one key/certificate for both sides.

```auto
xpack.security.http.ssl.key
xpack.security.http.ssl.certificate

```

is one thing.

The ones you will use with `--key` and `--certificate` is another thing.

---

_[View the full topic](https://discuss.elastic.co/t/x-pack-enabled-unable-to-communicate-to-elasticsearch-using-only-cacert-from-client-machines/194280)._
