sgconfig certificate type heuristics

6 views
Skip to first unread message

Fabien Wernli

unread,
Jan 18, 2019, 10:10:06 AM1/18/19
to Search Guard Community Forum
I'm facing this issue:

ERR: You try to connect with a TLS node certificate instead of an admin client certificate

I'm certain this is not a node cert I'm using, so I'm guessing there is a bug.
What are the certificate type detection heuristics?

Cheers

Fabien Wernli

unread,
Jan 18, 2019, 10:17:57 AM1/18/19
to Search Guard Community Forum
does the searchguard.authcz.admin_dn need to be the same on all nodes?
maybe that's the issue I'm facing?

SG

unread,
Jan 18, 2019, 10:40:17 AM1/18/19
to search...@googlegroups.com
yes, needs to be identical on all nodes

(elasticsearch.yml should be generally be the same on all nodes with a few exceptions like node.name and certificates etc ...)

> Am 18.01.2019 um 16:17 schrieb Fabien Wernli <swis...@gmail.com>:
>
> does the searchguard.authcz.admin_dn need to be the same on all nodes?
> maybe that's the issue I'm facing?
>
> --
> You received this message because you are subscribed to the Google Groups "Search Guard Community Forum" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to search-guard...@googlegroups.com.
> To post to this group, send email to search...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/b66b3af2-58b2-4ad0-9d47-a723ae830742%40googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.

Reply all
Reply to author
Forward
0 new messages