# "xpack.security.transport.ssl.truststore.path" "SSL resources should be placed in"

**URL:** <https://discuss.elastic.co/t/xpack-security-transport-ssl-truststore-path-ssl-resources-should-be-placed-in/214324>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 9, 2020, 1:08am UTC](https://discuss.elastic.co/t/xpack-security-transport-ssl-truststore-path-ssl-resources-should-be-placed-in/214324 "2020-01-09T01:08:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![johndpalm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johndpalm/32/60518_2.png) [@johndpalm](https://discuss.elastic.co/u/johndpalm)\
**Post date:** [January 9, 2020, 1:08am UTC](https://discuss.elastic.co/t/xpack-security-transport-ssl-truststore-path-ssl-resources-should-be-placed-in/214324/1 "2020-01-09T01:08:28Z")

</div>

I'm storing my elasticsearch.yml config file and the PKCS#12 certificates in different paths.

`ES_PATH_CONF=C:\Repos\DevOps\Elastic\config\elasticsearch\elasticsearch-config`

**elasticsearch.yml**

```
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: '${ES_CERT_PATH}\${node.name}.p12'
xpack.security.transport.ssl.truststore.path: '${ES_CERT_PATH}\${node.name}.p12'

```

I get this exception when I start a node:

```
Caused by: org.elasticsearch.ElasticsearchException: failed to initialize SSL TrustManager - access to read truststore f
ile [C:\elasticstack\certs\node1.p12] is blocked; SSL resources should be placed in the [C:\Repos\DevOps\Elastic
\config\elasticsearch\elasticsearch-config] directory

Caused by: java.security.AccessControlException: access denied ("java.io.FilePermission" "C:\elasticstack\certs\node1.p1
2" "read")

```

Is it possible to store the PKCS#12 certificates in a different location than the config path? If so, what other configuration needs to be set to allow access? (If this can be solved by PEM files, that's an acceptable solution as well.)

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 9, 2020, 7:57am UTC](https://discuss.elastic.co/t/xpack-security-transport-ssl-truststore-path-ssl-resources-should-be-placed-in/214324/2 "2020-01-09T07:57:00Z")

</div>

> [@johndpalm](#):
>
> Is it possible to store the PKCS#12 certificates in a different location than the config path?

No, Elasticsearch runs with a security manager enabled, which intentionally prevents the process from having access to other directories.  
All certificates and keys need to be somewhere under the config directory.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2020, 7:57am UTC](https://discuss.elastic.co/t/xpack-security-transport-ssl-truststore-path-ssl-resources-should-be-placed-in/214324/3 "2020-02-06T07:57:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
