You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Elasticsearch SSL连接失败:无法读取PKCS12密钥库问题求助

问题描述

我尝试建立Elasticsearch连接以追加数据进行分析,但无法通过SSL建立连接,Elasticsearch启动失败。

错误日志

[2023-12-15T11:56:28,285][ERROR][o.e.b.Elasticsearch      ] [node_1] fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: failed to load SSL configuration [xpack.security.transport.ssl] - cannot read configured [PKCS12] keystore [D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12] - this is usually caused by an incorrect password
        at org.elasticsearch.xcore@8.9.0/org.elasticsearch.xpack.core.ssl.SSLService.lambda$loadSslConfigurations$11(SSLService.java:617)
        at java.base/java.util.HashMap.forEach(HashMap.java:1429)
        at java.base/java.util.Collections$UnmodifiableMap.forEach(Collections.java:1553)
        at org.elasticsearch.xcore@8.9.0/org.elasticsearch.xpack.core.ssl.SSLService.loadSslConfigurations(SSLService.java:613)
        at org.elasticsearch.xcore@8.9.0/org.elasticsearch.xpack.core.ssl.SSLService.<init>(SSLService.java:159)

See logs for more details.

ERROR: Elasticsearch did not exit normally - check the logs at D:\Internship_task\elasticsearch\elasticsearch-8.9.0\logs\elasticsearch.log

ERROR: Elasticsearch exited unexpectedly

已执行的密码验证命令

keytool -list -keystore "D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12"
bin/elasticsearch-keystore show xpack.security.http.ssl.keystore.secure_password
bin/elasticsearch-keystore show xpack.security.transport.ssl.truststore.secure_password
bin/elasticsearch-keystore show xpack.security.transport.ssl.keystore.secure_password
bin/elasticsearch-keystore list

Elasticsearch配置文件(.yml)内容

xpack.security.http.ssl:
  enabled: true
  keystore.type: PKCS12
  keystore.path: D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12

xpack.security.transport.ssl:
  enabled: true
  keystore.type: PKCS12
  keystore.path: D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12
  
  truststore.type: PKCS12
  truststore.path: D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12

解决方案

核心问题是PKCS12密钥库密码不匹配或配置缺失,导致Elasticsearch无法加载SSL配置,以下是修复步骤:

  1. 验证密钥库密码正确性
    用keytool确认密钥库密码是否有效:

    keytool -list -keystore "D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12" -storetype PKCS12
    

    输入密码后若能正常列出密钥内容,说明密码正确;若提示错误,需找回或重新生成密钥库密码。

  2. 核对Elasticsearch密钥库存储的密码
    执行命令查看已存储的SSL密码,确保和keytool验证通过的密码完全一致:

    bin/elasticsearch-keystore show xpack.security.http.ssl.keystore.secure_password
    bin/elasticsearch-keystore show xpack.security.transport.ssl.truststore.secure_password
    bin/elasticsearch-keystore show xpack.security.transport.ssl.keystore.secure_password
    

    注意区分大小写和特殊字符。

  3. 补充配置文件的密码引用
    你的配置仅指定了密钥库路径和类型,未关联Elasticsearch密钥库中的密码项,需添加以下配置:

    xpack.security.http.ssl:
      enabled: true
      keystore.type: PKCS12
      keystore.path: D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12
      keystore.secure_password: ${xpack.security.http.ssl.keystore.secure_password}
    
    xpack.security.transport.ssl:
      enabled: true
      keystore.type: PKCS12
      keystore.path: D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12
      keystore.secure_password: ${xpack.security.transport.ssl.keystore.secure_password}
      
      truststore.type: PKCS12
      truststore.path: D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12
      truststore.secure_password: ${xpack.security.transport.ssl.truststore.secure_password}
    
  4. 重启Elasticsearch服务
    修改配置后,重启Elasticsearch,观察启动日志是否消除SSL相关错误。若新增了密码项,可先执行bin/elasticsearch-keystore reload再重启。

  5. 密码丢失时重新生成SSL证书
    若密码无法找回,用Elasticsearch工具重新生成证书:

    bin/elasticsearch-certutil cert -out config/elastic-certificates.p12 -pass ""
    

    上述命令生成无密码证书,若需密码保护,去掉-pass ""并设置密码。生成后将新密码存入密钥库:

    bin/elasticsearch-keystore add xpack.security.http.ssl.keystore.secure_password
    bin/elasticsearch-keystore add xpack.security.transport.ssl.truststore.secure_password
    bin/elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure_password
    

    输入新密码后更新配置文件并重启服务。

内容的提问来源于stack exchange,提问作者vamshi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 01:35:33