> Am 26.06.2017 um 12:37 schrieb vinod hy <hy.vi...@gmail.com>:
>
> Hi All,
>
> I am using ELK in my development environment and i was able to set it up properly in windows environment. The complete ELK flow is working fine and i am able to see output in kibana. Now my requirement is to secure the ELK communication using SSL certificates. I have used x-pack for the same and i was able to achieve it. Since its not free, i am exploring searchguard and i am stuck.
>
Where are you stuck? What have you tried, what is not working? Can you send more details and logoutput?
> first of all please let me know if i can go ahead with searchguard. My application is an enterprise application. All the communication has to be made secure once the application goes to production environment.
Search Guard should be running well on Windows.
>
> which one do you recommend. x-pack or searchguard. is only cost the difference? or is there any other difference.
Depends on the features you need. For ore details about SG vs. X-Pack pls. contact us via mail or the contact form on the website (https://floragunn.com/contact/)
Pls. see also https://floragunn.com/search-guard-elasticsearch-faq/ and https://floragunn.com/searchguard-license-support/
>
> Regards,
>
> Vinod H Y
>
> --
> You received this message because you are subscribed to the Google Groups "Search Guard" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
> To post to this group, send email to search...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/d7424d9a-618f-47d0-95f0-253d0f380bee%40googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/qmHf_hLfIS0/unsubscribe.
To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.
To post to this group, send email to search...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/FA4E890E-BFCA-4E08-98DA-B7BCB6F0B720%40search-guard.com.
For more options, visit https://groups.google.com/d/optout.
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
> > To post to this group, send email to search...@googlegroups.com.
> > To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/d7424d9a-618f-47d0-95f0-253d0f380bee%40googlegroups.com.
> > For more options, visit https://groups.google.com/d/optout.
>
> --
> You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
> To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/qmHf_hLfIS0/unsubscribe.
> To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.
> To post to this group, send email to search...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/FA4E890E-BFCA-4E08-98DA-B7BCB6F0B720%40search-guard.com.
> For more options, visit https://groups.google.com/d/optout.
>
>
>
> --
> Regards,
>
> Vinod H Y
>
> --
> You received this message because you are subscribed to the Google Groups "Search Guard" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/CAFPV%3DJVGDJtOn5n6cLLGK7yJoz5%2BisPOrAr4njV8y-84coKb4Q%40mail.gmail.com.
> For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/qmHf_hLfIS0/unsubscribe.
To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.
To post to this group, send email to search...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/9AA196E3-79E1-4BDA-B434-B19F946F6B8A%40search-guard.com.
For more options, visit https://groups.google.com/d/optout.
> > > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
> > > To post to this group, send email to search...@googlegroups.com.
> > > To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/d7424d9a-618f-47d0-95f0-253d0f380bee%40googlegroups.com.
> > > For more options, visit https://groups.google.com/d/optout.
> >
> > --
> > You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
> > To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/qmHf_hLfIS0/unsubscribe.
> > To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.
> > To post to this group, send email to search...@googlegroups.com.
> > To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/FA4E890E-BFCA-4E08-98DA-B7BCB6F0B720%40search-guard.com.
> > For more options, visit https://groups.google.com/d/optout.
> >
> >
> >
> > --
> > Regards,
> >
> > Vinod H Y
> >
> > --
> > You received this message because you are subscribed to the Google Groups "Search Guard" group.
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
> > To post to this group, send email to search...@googlegroups.com.
> > To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/CAFPV%3DJVGDJtOn5n6cLLGK7yJoz5%2BisPOrAr4njV8y-84coKb4Q%40mail.gmail.com.
> > For more options, visit https://groups.google.com/d/optout.
>
> --
> You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
> To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/qmHf_hLfIS0/unsubscribe.
> To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.
> To post to this group, send email to search...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/9AA196E3-79E1-4BDA-B434-B19F946F6B8A%40search-guard.com.
> For more options, visit https://groups.google.com/d/optout.
>
>
>
> --
> Regards,
>
> Vinod H Y
>
> --
> You received this message because you are subscribed to the Google Groups "Search Guard" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/CAFPV%3DJW95FVkNwrJ0X2_Z4aF00XqXSyF5jZb5o2orG6cYsv39w%40mail.gmail.com.
> For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/qmHf_hLfIS0/unsubscribe.
To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.
To post to this group, send email to search...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/DEADFD4F-FB6B-4BF7-8C25-D74E0BFCC926%40search-guard.com.
For more options, visit https://groups.google.com/d/optout.
> > > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
> > > To post to this group, send email to search...@googlegroups.com.
> > > To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/d7424d9a-618f-47d0-95f0-253d0f380bee%40googlegroups.com.
> > > For more options, visit https://groups.google.com/d/optout.
> >
> > --
> > You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
> > To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/qmHf_hLfIS0/unsubscribe.
> > To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.
> > To post to this group, send email to search...@googlegroups.com.
> > To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/FA4E890E-BFCA-4E08-98DA-B7BCB6F0B720%40search-guard.com.
> > For more options, visit https://groups.google.com/d/optout.
> >
> >
> >
> > --
> > Regards,
> >
> > Vinod H Y
> >
> > --
> > You received this message because you are subscribed to the Google Groups "Search Guard" group.
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
> > To post to this group, send email to search...@googlegroups.com.
> > To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/CAFPV%3DJVGDJtOn5n6cLLGK7yJoz5%2BisPOrAr4njV8y-84coKb4Q%40mail.gmail.com.
> > For more options, visit https://groups.google.com/d/optout.
>
> --
> You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
> To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/qmHf_hLfIS0/unsubscribe.
> To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.
> To post to this group, send email to search...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/9AA196E3-79E1-4BDA-B434-B19F946F6B8A%40search-guard.com.
> For more options, visit https://groups.google.com/d/optout.
>
>
>
> --
> Regards,
>
> Vinod H Y
>
> --
> You received this message because you are subscribed to the Google Groups "Search Guard" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/CAFPV%3DJW95FVkNwrJ0X2_Z4aF00XqXSyF5jZb5o2orG6cYsv39w%40mail.gmail.com.
> For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/qmHf_hLfIS0/unsubscribe.
To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.
To post to this group, send email to search...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/D10A0A71-8791-408A-AC6A-FBA3D13245CA%40search-guard.com.
For more options, visit https://groups.google.com/d/optout.
Search Guard not initialized (SG11). See https://github.com/floragunncom/search-guard-docs/blob/master/sgadmin.md
In elasticsearch.log, i can see the below trace,
[2017-06-29T14:55:36,436][INFO ][c.f.s.c.IndexBaseConfigurationRepository] searchguard index does not exist yet, so no need to load config on node startup. Use sgadmin to initialize cluster
Issue 2:
So the issue 1 is because i have not run sgadmin command. But when i run the sgadmin command as suggested by you in your mail, i get
Cannot retrieve cluster state due to: None of the configured nodes are available: [{#transport#-1}{t_vvrQHFTruDXPcUgf3i-Q}{localhost}{127.0.0.1:9300}]. This is not an error, will keep on trying ...
* Try running sgadmin.sh with -icl and -nhnv (If thats works you need to check your clustername as well as hostnames in your SSL certificates)
* If this is not working, try running sgadmin.sh with --diagnose and see diagnose trace log file)
15:00:52.735 [elasticsearch[_client_][transport_client_boss][T#3]] ERROR com.floragunn.searchguard.ssl.transport.SearchGuardSSLNettyTransport - SSL Problem General SSLEngine problem
javax.net.ssl.SSLHandshakeException: General SSLEngine problem.
Caused by: java.security.cert.CertificateException: No subject alternative DNS name matching localhost found.
Then i ran sgadmin command in diagnose mode. I am attaching the diagnose logs with the mail.
Elasticsearch.yml file changes:
searchguard.authcz.admin_dn:
- CN=AAEINBLR02717D
searchguard.ssl.transport.keystore_filepath: D:\Softwares\ELK\elasticsearch-5.4.0\elasticsearch-5.4.0\config\CN=AAEINBLR02717D-keystore.jks
searchguard.ssl.transport.keystore_password: 36375fb609b4231e4363
searchguard.ssl.transport.truststore_filepath: D:\Softwares\ELK\elasticsearch-5.4.0\elasticsearch-5.4.0\config\truststore.jks
searchguard.ssl.transport.truststore_password: 76822cd1a1fe2a1c4b45
Certificates readme file:
Passwords:
CA password: bda758dae3227ae72becb830d096d2f2af518bd5
Truststore password: 76822cd1a1fe2a1c4b45
Admin keystore password: d6cc7eda4de8bfc52430
Demouser keystore password: 77e68e3cce628545ccee
Host: AAEINBLR02717D
AAEINBLR02717D keystore password: 36375fb609b4231e4363
searchguard.authcz.admin_dn:
- CN=sgadmin
sgadmin command:
sgadmin.bat -cd ..\sgconfig -ts D:\Softwares\ELK\elasticsearch-5.4.0\elasticsearch-5.4.0\config\truststore.jks -tspass 76821a1fe2a1c4b45 -ks D:\Softwares\ELK\elasticsearch-5.4.0\elasticsearch-5.4.0\config\CN=AAEINBLR02717D-keystore.jks -kspass 36375fb609b4231e4363 -nhnv --diagnose
Note:
I have manually copied the required truststore and keystore files as mentioned in the above paths in the elasticsearch config folder from the main certificate folder which i recieved from searchguard TLS generator link.
Please help me in understanding the issue here.
Regards,
Vinod H Y
> > > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
> > > To post to this group, send email to search...@googlegroups.com.
> > > To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/d7424d9a-618f-47d0-95f0-253d0f380bee%40googlegroups.com.
> > > For more options, visit https://groups.google.com/d/optout.
> >
> > --
> > You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
> > To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/qmHf_hLfIS0/unsubscribe.
> > To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.
> > To post to this group, send email to search...@googlegroups.com.
> > To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/FA4E890E-BFCA-4E08-98DA-B7BCB6F0B720%40search-guard.com.
> > For more options, visit https://groups.google.com/d/optout.
> >
> >
> >
> > --
> > Regards,
> >
> > Vinod H Y
> >
> > --
> > You received this message because you are subscribed to the Google Groups "Search Guard" group.
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
> > To post to this group, send email to search...@googlegroups.com.
> > To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/CAFPV%3DJVGDJtOn5n6cLLGK7yJoz5%2BisPOrAr4njV8y-84coKb4Q%40mail.gmail.com.
> > For more options, visit https://groups.google.com/d/optout.
>
> --
> You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
> To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/qmHf_hLfIS0/unsubscribe.
> To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.
> To post to this group, send email to search...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/9AA196E3-79E1-4BDA-B434-B19F946F6B8A%40search-guard.com.
> For more options, visit https://groups.google.com/d/optout.
>
>
>
> --
> Regards,
>
> Vinod H Y
>
> --
> You received this message because you are subscribed to the Google Groups "Search Guard" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/CAFPV%3DJW95FVkNwrJ0X2_Z4aF00XqXSyF5jZb5o2orG6cYsv39w%40mail.gmail.com.
> For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to a topic in the Google Groups "Search Guard" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/qmHf_hLfIS0/unsubscribe.
To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.
To post to this group, send email to search...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/D10A0A71-8791-408A-AC6A-FBA3D13245CA%40search-guard.com.
For more options, visit https://groups.google.com/d/optout.