You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 20.04部署Elasticsearch 7.17.11时设置密码失败求助

问题描述

Ubuntu 20.04 部署单节点 Elasticsearch 7.17.11,同时独立部署 Kibana 和 Logstash。通过 Terraform 创建全新实例,Ansible 剧本配置,复刻现有环境(移除集群配置)。运行 bin/elasticsearch-setup-passwords 工具时触发认证错误:

Failed to authenticate user 'elastic' against https://localhost:9200/_security/_authenticate?pretty
Possible causes include:

  • The password for the 'elastic' user has already been changed on this cluster
  • Your elasticsearch node is running against a different keystore
    This tool used the keystore at /etc/elasticsearch/elasticsearch.keystore

ERROR: Failed to verify bootstrap password

确认信息:

  • 密钥库确实位于 /etc/elasticsearch/elasticsearch.keystore
  • 全新实例,elastic 密码不可能已被修改

Elasticsearch 配置(elasticsearch.yml)

node.name: test-elasticsearch
network.host: localhost
http.port: 9200
discovery.type: single-node

# Transport layer
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.key: /etc/elasticsearch/certs/elasticsearch.key
xpack.security.transport.ssl.certificate: /etc/elasticsearch/certs/elasticsearch.crt
xpack.security.transport.ssl.certificate_authorities: /etc/elasticsearch/certs/ca/ca.crt

# HTTP layer
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.verification_mode: certificate
xpack.security.http.ssl.key: /etc/elasticsearch/certs/elasticsearch.key
xpack.security.http.ssl.certificate: /etc/elasticsearch/certs/elasticsearch.crt
xpack.security.http.ssl.certificate_authorities: /etc/elasticsearch/certs/ca/ca.crt

# Elasticsearch authentication
xpack.security.enabled: true
#xpack.security.enabled: false

path.data: /mnt/elastic_data_disk
path.logs: /mnt/elastic_data_disk

证书配置(instances.yml)

通过 bin/elasticsearch-certutil 生成证书,配置文件内容:

instances:
- name: "test-elasticsearch"
  ip:
  - "35.xx.xx.xx"

已查阅官方文档但未解决,求排查此认证错误的方法。


解决方案

针对这个问题,从以下几个方向逐一排查:

1. 修复证书与本地访问的匹配问题

你的证书仅绑定了云实例公网IP 35.xx.xx.xx,但 elasticsearch-setup-passwords 通过 localhost 访问节点,SSL证书会因IP/域名不匹配触发验证失败。

解决步骤:

  • 修改 instances.yml,添加本地访问的IP和域名:
    instances:
    - name: "test-elasticsearch"
      ip:
      - "35.xx.xx.xx"
      - "127.0.0.1"
      - "localhost"
    
  • 重新生成证书,替换原有证书文件,重启Elasticsearch服务:
    sudo -u elasticsearch bin/elasticsearch-certutil cert --in instances.yml --out certs.zip
    unzip certs.zip -d /etc/elasticsearch/certs
    sudo chown -R elasticsearch:elasticsearch /etc/elasticsearch/certs
    sudo systemctl restart elasticsearch
    

2. 临时跳过SSL验证(仅用于测试)

如果需要快速确认问题根源,可临时添加跳过证书验证参数运行工具:

sudo -u elasticsearch bin/elasticsearch-setup-passwords auto --batch --url "https://localhost:9200" --insecure

注意:此方法仅限测试,生产环境禁止使用。

3. 检查服务状态与权限

  • 确认Elasticsearch服务正常运行:
    sudo systemctl status elasticsearch
    
  • 查看日志排查SSL或认证相关错误:
    grep -i "ssl\|auth" /mnt/elastic_data_disk/elasticsearch.log
    
  • 确保证书目录权限正确:
    sudo chown -R elasticsearch:elasticsearch /etc/elasticsearch/certs
    sudo chmod -R 700 /etc/elasticsearch/certs
    

4. 检查密钥库中的bootstrap密码

若Ansible剧本提前向密钥库写入过bootstrap.password,会导致工具验证失败。检查并清理:

sudo -u elasticsearch bin/elasticsearch-keystore list
# 若存在bootstrap.password则移除
sudo -u elasticsearch bin/elasticsearch-keystore remove bootstrap.password
sudo systemctl restart elasticsearch

内容的提问来源于stack exchange,提问作者KrisU-H

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 03:02:39