# Cannot use SHA512 certificate with Searchguard

**URL:** <https://forum.search-guard.com/t/cannot-use-sha512-certificate-with-searchguard/1170>\
**Category:** Search Guard\
**Created:** [October 24, 2018, 3:30pm UTC](https://forum.search-guard.com/t/cannot-use-sha512-certificate-with-searchguard/1170 "2018-10-24T15:30:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marcos\_Tenrero\_Moran](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@Marcos\_Tenrero\_Moran](https://forum.search-guard.com/u/Marcos_Tenrero_Moran)\
**Post date:** [October 24, 2018, 3:30pm UTC](https://forum.search-guard.com/t/cannot-use-sha512-certificate-with-searchguard/1170/1 "2018-10-24T15:30:21Z")

</div>

Hello I’m trying to configure my Elasticsearch 6.4.0 instances with TLS / SSL security with SearchGuard.

I’ve generated my CSR and my key with SHA512. Then the CA signed the certificate.

But, when starting ES I get the following error:

Caused by: javax.net.ssl.SSLException: Server key

at sun.security.ssl.Handshaker.throwSSLException(Handshaker.java:1434) ~[?:?]

at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:1037) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:970) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:967) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_191]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1459) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1364) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1272) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]

… 19 more

Caused by: java.security.SignatureException: Signature length not correct: got 512 but was expecting 256

at sun.security.rsa.RSASignature.engineVerify(RSASignature.java:189) ~[?:?]

at java.security.Signature$Delegate.engineVerify(Signature.java:1222) ~[?:1.8.0\_191]

at java.security.Signature.verify(Signature.java:655) ~[?:1.8.0\_191]

at sun.security.ssl.HandshakeMessage$ECDH\_ServerKeyExchange.(HandshakeMessage.java:1120) ~[?:?]

at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:300) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:1037) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:970) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:967) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_191]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1459) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1364) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1272) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]

… 19 more

Anyone know to use 512bits certificates?

Thank you

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [October 25, 2018, 11:48am UTC](https://forum.search-guard.com/t/cannot-use-sha512-certificate-with-searchguard/1170/2 "2018-10-25T11:48:46Z")

</div>

how did you generate the CSR?

> **···**
>
> On Wednesday, 24 October 2018 17:30:21 UTC+2, Marcos Tenrero Morán wrote:
> 
> > Hello I’m trying to configure my Elasticsearch 6.4.0 instances with TLS / SSL security with SearchGuard.
> 
> > I’ve generated my CSR and my key with SHA512. Then the CA signed the certificate.
> 
> > But, when starting ES I get the following error:
> 
> > 
> 
> > Caused by: javax.net.ssl.SSLException: Server key
> 
> > at sun.security.ssl.Handshaker.throwSSLException(Handshaker.java:1434) ~[?:?]
> 
> > at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:304) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:1037) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:970) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:967) ~[?:?]
> 
> > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_191]
> 
> > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1459) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1364) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1272) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]
> 
> > … 19 more
> 
> > Caused by: java.security.SignatureException: Signature length not correct: got 512 but was expecting 256
> 
> > at sun.security.rsa.RSASignature.engineVerify(RSASignature.java:189) ~[?:?]
> 
> > at java.security.Signature$Delegate.engineVerify(Signature.java:1222) ~[?:1.8.0\_191]
> 
> > at java.security.Signature.verify(Signature.java:655) ~[?:1.8.0\_191]
> 
> > at sun.security.ssl.HandshakeMessage$ECDH\_ServerKeyExchange.(HandshakeMessage.java:1120) ~[?:?]
> 
> > at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:300) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:1037) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:970) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:967) ~[?:?]
> 
> > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_191]
> 
> > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1459) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1364) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1272) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]
> 
> > … 19 more
> 
> > 
> 
> > Anyone know to use 512bits certificates?
> 
> > 
> 
> > Thank you

---

<div class="post-metadata">

**Author:** ![Marcos\_Tenrero\_Moran](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@Marcos\_Tenrero\_Moran](https://forum.search-guard.com/u/Marcos_Tenrero_Moran)\
**Post date:** [October 25, 2018, 11:50am UTC](https://forum.search-guard.com/t/cannot-use-sha512-certificate-with-searchguard/1170/3 "2018-10-25T11:50:42Z")

</div>

With the following openssl command:

openssl req   
-newkey rsa:2048 -nodes -keyout domain.key \

-out domain.csr

> **···**
>
> El jueves, 25 de octubre de 2018, 13:48:46 (UTC+2), Search Guard escribió:
> 
> > how did you generate the CSR?
> > 
> > On Wednesday, 24 October 2018 17:30:21 UTC+2, Marcos Tenrero Morán wrote:
> > 
> > > Hello I’m trying to configure my Elasticsearch 6.4.0 instances with TLS / SSL security with SearchGuard.
> 
> > > I’ve generated my CSR and my key with SHA512. Then the CA signed the certificate.
> 
> > > But, when starting ES I get the following error:
> 
> > >
> 
> > > Caused by: javax.net.ssl.SSLException: Server key
> 
> > > at sun.security.ssl.Handshaker.throwSSLException(Handshaker.java:1434) ~[?:?]
> 
> > > at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:304) ~[?:?]
> 
> > > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:1037) ~[?:?]
> 
> > > at sun.security.ssl.Handshaker$1.run(Handshaker.java:970) ~[?:?]
> 
> > > at sun.security.ssl.Handshaker$1.run(Handshaker.java:967) ~[?:?]
> 
> > > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_191]
> 
> > > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1459) ~[?:?]
> 
> > > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1364) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]
> 
> > > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1272) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]
> 
> > > … 19 more
> 
> > > Caused by: java.security.SignatureException: Signature length not correct: got 512 but was expecting 256
> 
> > > at sun.security.rsa.RSASignature.engineVerify(RSASignature.java:189) ~[?:?]
> 
> > > at java.security.Signature$Delegate.engineVerify(Signature.java:1222) ~[?:1.8.0\_191]
> 
> > > at java.security.Signature.verify(Signature.java:655) ~[?:1.8.0\_191]
> 
> > > at sun.security.ssl.HandshakeMessage$ECDH\_ServerKeyExchange.(HandshakeMessage.java:1120) ~[?:?]
> 
> > > at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:300) ~[?:?]
> 
> > > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:1037) ~[?:?]
> 
> > > at sun.security.ssl.Handshaker$1.run(Handshaker.java:970) ~[?:?]
> 
> > > at sun.security.ssl.Handshaker$1.run(Handshaker.java:967) ~[?:?]
> 
> > > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_191]
> 
> > > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1459) ~[?:?]
> 
> > > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1364) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]
> 
> > > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1272) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]
> 
> > > … 19 more
> 
> > >
> 
> > > Anyone know to use 512bits certificates?
> 
> > >
> 
> > > Thank you

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [October 25, 2018, 2:40pm UTC](https://forum.search-guard.com/t/cannot-use-sha512-certificate-with-searchguard/1170/4 "2018-10-25T14:40:35Z")

</div>

this works well for me

openssl req -x509 -newkey rsa:2048 -nodes -keyout domain.key -out domain.pem -days 365 -sha512

So i can confirm that SG with ES 6.4.0 is working with SHA512 digest

> **···**
>
> On Thursday, 25 October 2018 13:50:42 UTC+2, Marcos Tenrero Morán wrote:
> 
> > With the following openssl command:
> 
> > openssl req   
> > -newkey rsa:2048 -nodes -keyout domain.key \
> 
> > -out domain.csr
> 
> > El jueves, 25 de octubre de 2018, 13:48:46 (UTC+2), Search Guard escribió:
> > 
> > > how did you generate the CSR?
> > > 
> > > On Wednesday, 24 October 2018 17:30:21 UTC+2, Marcos Tenrero Morán wrote:
> > > 
> > > > Hello I’m trying to configure my Elasticsearch 6.4.0 instances with TLS / SSL security with SearchGuard.
> 
> > > > I’ve generated my CSR and my key with SHA512. Then the CA signed the certificate.
> 
> > > > But, when starting ES I get the following error:
> 
> > > >
> 
> > > > Caused by: javax.net.ssl.SSLException: Server key
> 
> > > > at sun.security.ssl.Handshaker.throwSSLException(Handshaker.java:1434) ~[?:?]
> 
> > > > at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:304) ~[?:?]
> 
> > > > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:1037) ~[?:?]
> 
> > > > at sun.security.ssl.Handshaker$1.run(Handshaker.java:970) ~[?:?]
> 
> > > > at sun.security.ssl.Handshaker$1.run(Handshaker.java:967) ~[?:?]
> 
> > > > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_191]
> 
> > > > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1459) ~[?:?]
> 
> > > > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1364) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]
> 
> > > > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1272) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]
> 
> > > > … 19 more
> 
> > > > Caused by: java.security.SignatureException: Signature length not correct: got 512 but was expecting 256
> 
> > > > at sun.security.rsa.RSASignature.engineVerify(RSASignature.java:189) ~[?:?]
> 
> > > > at java.security.Signature$Delegate.engineVerify(Signature.java:1222) ~[?:1.8.0\_191]
> 
> > > > at java.security.Signature.verify(Signature.java:655) ~[?:1.8.0\_191]
> 
> > > > at sun.security.ssl.HandshakeMessage$ECDH\_ServerKeyExchange.(HandshakeMessage.java:1120) ~[?:?]
> 
> > > > at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:300) ~[?:?]
> 
> > > > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:1037) ~[?:?]
> 
> > > > at sun.security.ssl.Handshaker$1.run(Handshaker.java:970) ~[?:?]
> 
> > > > at sun.security.ssl.Handshaker$1.run(Handshaker.java:967) ~[?:?]
> 
> > > > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_191]
> 
> > > > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1459) ~[?:?]
> 
> > > > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1364) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]
> 
> > > > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1272) ~[netty-handler-4.1.16.Final.jar:4.1.16.Final]
> 
> > > > … 19 more
> 
> > > >
> 
> > > > Anyone know to use 512bits certificates?
> 
> > > >
> 
> > > > Thank you
