Elasticsearch SSL连接失败:无法读取PKCS12密钥库问题求助
问题描述
我尝试建立Elasticsearch连接以追加数据进行分析,但无法通过SSL建立连接,Elasticsearch启动失败。
错误日志
[2023-12-15T11:56:28,285][ERROR][o.e.b.Elasticsearch ] [node_1] fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: failed to load SSL configuration [xpack.security.transport.ssl] - cannot read configured [PKCS12] keystore [D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12] - this is usually caused by an incorrect password at org.elasticsearch.xcore@8.9.0/org.elasticsearch.xpack.core.ssl.SSLService.lambda$loadSslConfigurations$11(SSLService.java:617) at java.base/java.util.HashMap.forEach(HashMap.java:1429) at java.base/java.util.Collections$UnmodifiableMap.forEach(Collections.java:1553) at org.elasticsearch.xcore@8.9.0/org.elasticsearch.xpack.core.ssl.SSLService.loadSslConfigurations(SSLService.java:613) at org.elasticsearch.xcore@8.9.0/org.elasticsearch.xpack.core.ssl.SSLService.<init>(SSLService.java:159) See logs for more details. ERROR: Elasticsearch did not exit normally - check the logs at D:\Internship_task\elasticsearch\elasticsearch-8.9.0\logs\elasticsearch.log ERROR: Elasticsearch exited unexpectedly
已执行的密码验证命令
keytool -list -keystore "D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12" bin/elasticsearch-keystore show xpack.security.http.ssl.keystore.secure_password bin/elasticsearch-keystore show xpack.security.transport.ssl.truststore.secure_password bin/elasticsearch-keystore show xpack.security.transport.ssl.keystore.secure_password bin/elasticsearch-keystore list
Elasticsearch配置文件(.yml)内容
xpack.security.http.ssl: enabled: true keystore.type: PKCS12 keystore.path: D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12 xpack.security.transport.ssl: enabled: true keystore.type: PKCS12 keystore.path: D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12 truststore.type: PKCS12 truststore.path: D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12
解决方案
核心问题是PKCS12密钥库密码不匹配或配置缺失,导致Elasticsearch无法加载SSL配置,以下是修复步骤:
验证密钥库密码正确性
用keytool确认密钥库密码是否有效:keytool -list -keystore "D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12" -storetype PKCS12输入密码后若能正常列出密钥内容,说明密码正确;若提示错误,需找回或重新生成密钥库密码。
核对Elasticsearch密钥库存储的密码
执行命令查看已存储的SSL密码,确保和keytool验证通过的密码完全一致:bin/elasticsearch-keystore show xpack.security.http.ssl.keystore.secure_password bin/elasticsearch-keystore show xpack.security.transport.ssl.truststore.secure_password bin/elasticsearch-keystore show xpack.security.transport.ssl.keystore.secure_password注意区分大小写和特殊字符。
补充配置文件的密码引用
你的配置仅指定了密钥库路径和类型,未关联Elasticsearch密钥库中的密码项,需添加以下配置:xpack.security.http.ssl: enabled: true keystore.type: PKCS12 keystore.path: D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12 keystore.secure_password: ${xpack.security.http.ssl.keystore.secure_password} xpack.security.transport.ssl: enabled: true keystore.type: PKCS12 keystore.path: D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12 keystore.secure_password: ${xpack.security.transport.ssl.keystore.secure_password} truststore.type: PKCS12 truststore.path: D:\Internship_task\elasticsearch\elasticsearch-8.9.0\config\elastic-certificates.p12 truststore.secure_password: ${xpack.security.transport.ssl.truststore.secure_password}重启Elasticsearch服务
修改配置后,重启Elasticsearch,观察启动日志是否消除SSL相关错误。若新增了密码项,可先执行bin/elasticsearch-keystore reload再重启。密码丢失时重新生成SSL证书
若密码无法找回,用Elasticsearch工具重新生成证书:bin/elasticsearch-certutil cert -out config/elastic-certificates.p12 -pass ""上述命令生成无密码证书,若需密码保护,去掉
-pass ""并设置密码。生成后将新密码存入密钥库:bin/elasticsearch-keystore add xpack.security.http.ssl.keystore.secure_password bin/elasticsearch-keystore add xpack.security.transport.ssl.truststore.secure_password bin/elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure_password输入新密码后更新配置文件并重启服务。
内容的提问来源于stack exchange,提问作者vamshi
相关产品推荐
相关产品推荐

