# curl: (60) SSL certificate problem: unable to get local issuer certificate

**URL:** <https://forum.search-guard.com/t/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate/1246>\
**Category:** Search Guard\
**Created:** [December 11, 2018, 1:06pm UTC](https://forum.search-guard.com/t/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate/1246 "2018-12-11T13:06:39Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![patrick](https://avatars.discourse-cdn.com/v4/letter/p/b2d939/32.png) [@patrick](https://forum.search-guard.com/u/patrick)\
**Post date:** [December 11, 2018, 1:06pm UTC](https://forum.search-guard.com/t/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate/1246/1 "2018-12-11T13:06:39Z")

</div>

Elasticsearch - 5.6.13

Search Guard - search-guard-5:5.6.13-19.2

Java - openjdk version “1.8.0\_191”

Ubuntu 18.04

Certificates created on [TLS Certificate Generator - Search Guard](https://search-guard.com/tls-certificate-generator/) as localhost and install runs without error, do I need to add root cert elsewhere ?

curl -u admin:admin -XGET '[https://localhost:9300](https://localhost:9300)’curl: (60) SSL certificate problem: unable to get local issuer certificateMore details here: [https://curl.haxx.se/docs/sslcerts.html](https://curl.haxx.se/docs/sslcerts.html)curl failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentioned above

searchguard.ssl.transport.enabled: truesearchguard.ssl.transport.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.transport.keystore\_password: xxxxsearchguard.ssl.transport.truststore\_filepath: truststore.jkssearchguard.ssl.transport.truststore\_password: xxxxsearchguard.ssl.transport.enforce\_hostname\_verification: falsesearchguard.ssl.http.enabled: truesearchguard.ssl.http.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.http.keystore\_password: xxxxsearchguard.ssl.http.truststore\_filepath: truststore.jkssearchguard.ssl.http.truststore\_password: xxxxsearchguard.authcz.admin\_dn: - CN=sgadminsearchguard.ssl.http.clientauth\_mode: OPTIONAL

When asking questions, please provide the following information:

- Search Guard and Elasticsearch version

- Installed and used enterprise modules, if any

- JVM version and operating system version

- Search Guard configuration files

- Elasticsearch log messages on debug level

- Other installed Elasticsearch or Kibana plugins, if any

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [December 11, 2018, 1:22pm UTC](https://forum.search-guard.com/t/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate/1246/2 "2018-12-11T13:22:47Z")

</div>

Try

curl -k -u admin:admin -XGET ‘[https://localhost:9200](https://localhost:9200)’ (not recommended)

or

curl --cacert root-ca.pem -u admin:admin -XGET ‘[https://localhost:9200](https://localhost:9200)’ (recommended)

(Note: The http/s port is normally 9200 and not 9300. 9300 is the port where the nodes talsk to each other with a binary TCP based protocol, called transport protocol)

---

<div class="post-metadata">

**Author:** ![patrick](https://avatars.discourse-cdn.com/v4/letter/p/b2d939/32.png) [@patrick](https://forum.search-guard.com/u/patrick)\
**Post date:** [December 11, 2018, 9:02pm UTC](https://forum.search-guard.com/t/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate/1246/3 "2018-12-11T21:02:39Z")

</div>

This works - curl --cacert root-ca.pem -u admin:admin -XGET ‘[https://localhost:9200](https://localhost:9200/)’

So it works without specifying the cacert do I install it somewhere or change from keystore cert config to pem ?

> **···**
>
> On Wednesday, December 12, 2018 at 12:06:39 AM UTC+11, pat…@amatc.com.au wrote:
> 
> > Elasticsearch - 5.6.13
> 
> > Search Guard - search-guard-5:5.6.13-19.2
> 
> > Java - openjdk version “1.8.0\_191”
> 
> > Ubuntu 18.04
> 
> > 
> 
> > 
> 
> > Certificates created on [https://search-guard.com/tls-certificate-generator/](https://search-guard.com/tls-certificate-generator/) as localhost and install runs without error, do I need to add root cert elsewhere ?
> 
> > 
> 
> > 
> 
> > curl -u admin:admin -XGET '[https://localhost:9300](https://localhost:9300)’curl: (60) SSL certificate problem: unable to get local issuer certificateMore details here: [https://curl.haxx.se/docs/sslcerts.html](https://curl.haxx.se/docs/sslcerts.html)curl failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentioned above
> 
> > 
> 
> > 
> 
> > searchguard.ssl.transport.enabled: truesearchguard.ssl.transport.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.transport.keystore\_password: xxxxsearchguard.ssl.transport.truststore\_filepath: truststore.jkssearchguard.ssl.transport.truststore\_password: xxxxsearchguard.ssl.transport.enforce\_hostname\_verification: falsesearchguard.ssl.http.enabled: truesearchguard.ssl.http.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.http.keystore\_password: xxxxsearchguard.ssl.http.truststore\_filepath: truststore.jkssearchguard.ssl.http.truststore\_password: xxxxsearchguard.authcz.admin\_dn: - CN=sgadminsearchguard.ssl.http.clientauth\_mode: OPTIONAL
> 
> > 
> 
> > When asking questions, please provide the following information:
> 
> > - Search Guard and Elasticsearch version
> 
> > - Installed and used enterprise modules, if any
> 
> > - JVM version and operating system version
> 
> > - Search Guard configuration files
> 
> > - Elasticsearch log messages on debug level
> 
> > - Other installed Elasticsearch or Kibana plugins, if any

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [December 11, 2018, 10:07pm UTC](https://forum.search-guard.com/t/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate/1246/4 "2018-12-11T22:07:09Z")

</div>

Sorry, but i don't understand ...

> **···**
>
> > Am 11.12.2018 um 22:02 schrieb patrick@amatc.com.au:
> > 
> > This works - curl --cacert root-ca.pem -u admin:admin -XGET '[https://localhost:9200](https://localhost:9200)'
> > 
> > So it works without specifying the cacert do I install it somewhere or change from keystore cert config to pem ?
> > 
> > On Wednesday, December 12, 2018 at 12:06:39 AM UTC+11, pat...@amatc.com.au wrote:  
> > Elasticsearch - 5.6.13  
> > Search Guard - search-guard-5:5.6.13-19.2  
> > Java - openjdk version "1.8.0\_191"  
> > Ubuntu 18.04
> > 
> > Certificates created on [TLS Certificate Generator - Search Guard](https://search-guard.com/tls-certificate-generator/) as localhost and install runs without error, do I need to add root cert elsewhere ?
> > 
> > curl -u admin:admin -XGET '[https://localhost:9300](https://localhost:9300)’curl: (60) SSL certificate problem: unable to get local issuer certificateMore details here: [https://curl.haxx.se/docs/sslcerts.htmlcurl](https://curl.haxx.se/docs/sslcerts.htmlcurl) failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentioned above
> > 
> > searchguard.ssl.transport.enabled: truesearchguard.ssl.transport.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.transport.keystore\_password: xxxxsearchguard.ssl.transport.truststore\_filepath: truststore.jkssearchguard.ssl.transport.truststore\_password: xxxxsearchguard.ssl.transport.enforce\_hostname\_verification: falsesearchguard.ssl.http.enabled: truesearchguard.ssl.http.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.http.keystore\_password: xxxxsearchguard.ssl.http.truststore\_filepath: truststore.jkssearchguard.ssl.http.truststore\_password: xxxxsearchguard.authcz.admin\_dn: - CN=sgadminsearchguard.ssl.http.clientauth\_mode: OPTIONAL
> > 
> > When asking questions, please provide the following information:
> > 
> > \* Search Guard and Elasticsearch version  
> > \* Installed and used enterprise modules, if any  
> > \* JVM version and operating system version  
> > \* Search Guard configuration files  
> > \* Elasticsearch log messages on debug level  
> > \* Other installed Elasticsearch or Kibana plugins, if any
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard Community Forum" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/8fc51c9f-71f9-4b11-ae0d-110eb3d8b0e5%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/8fc51c9f-71f9-4b11-ae0d-110eb3d8b0e5%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).

---

<div class="post-metadata">

**Author:** ![patrick](https://avatars.discourse-cdn.com/v4/letter/p/b2d939/32.png) [@patrick](https://forum.search-guard.com/u/patrick)\
**Post date:** [December 11, 2018, 10:17pm UTC](https://forum.search-guard.com/t/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate/1246/5 "2018-12-11T22:17:10Z")

</div>

I mean to install the root cert so that the other certs are trusted, I have done this using:

cp root-ca.crt /usr/local/share/ca-certificates/

sudo update-ca-certificates

I still get error for local issuer certificate

> **···**
>
> On Wednesday, December 12, 2018 at 12:06:39 AM UTC+11, pat…@amatc.com.au wrote:
> 
> > Elasticsearch - 5.6.13
> 
> > Search Guard - search-guard-5:5.6.13-19.2
> 
> > Java - openjdk version “1.8.0\_191”
> 
> > Ubuntu 18.04
> 
> > 
> 
> > 
> 
> > Certificates created on [https://search-guard.com/tls-certificate-generator/](https://search-guard.com/tls-certificate-generator/) as localhost and install runs without error, do I need to add root cert elsewhere ?
> 
> > 
> 
> > 
> 
> > curl -u admin:admin -XGET '[https://localhost:9300](https://localhost:9300)’curl: (60) SSL certificate problem: unable to get local issuer certificateMore details here: [https://curl.haxx.se/docs/sslcerts.html](https://curl.haxx.se/docs/sslcerts.html)curl failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentioned above
> 
> > 
> 
> > 
> 
> > searchguard.ssl.transport.enabled: truesearchguard.ssl.transport.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.transport.keystore\_password: xxxxsearchguard.ssl.transport.truststore\_filepath: truststore.jkssearchguard.ssl.transport.truststore\_password: xxxxsearchguard.ssl.transport.enforce\_hostname\_verification: falsesearchguard.ssl.http.enabled: truesearchguard.ssl.http.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.http.keystore\_password: xxxxsearchguard.ssl.http.truststore\_filepath: truststore.jkssearchguard.ssl.http.truststore\_password: xxxxsearchguard.authcz.admin\_dn: - CN=sgadminsearchguard.ssl.http.clientauth\_mode: OPTIONAL
> 
> > 
> 
> > When asking questions, please provide the following information:
> 
> > - Search Guard and Elasticsearch version
> 
> > - Installed and used enterprise modules, if any
> 
> > - JVM version and operating system version
> 
> > - Search Guard configuration files
> 
> > - Elasticsearch log messages on debug level
> 
> > - Other installed Elasticsearch or Kibana plugins, if any

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [December 11, 2018, 10:21pm UTC](https://forum.search-guard.com/t/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate/1246/6 "2018-12-11T22:21:03Z")

</div>

Not sure if curl/php picks up the certs in /usr/local/share/ca-certificates/

Especially curl is tricky, maybe its compiled against NSS. You can check this with curl -V

For php question is the same, guess it depends on against which SSL library it was compiled

But thats not really Search Guard related 😉

On Tuesday, 11 December 2018 23:17:10 UTC+1:

> **···**
>
> > I mean to install the root cert so that the other certs are trusted, I have done this using:
> 
> > cp root-ca.crt /usr/local/share/ca-certificates/
> 
> > sudo update-ca-certificates
> 
> > 
> 
> > I still get error for local issuer certificate
> 
> > On Wednesday, December 12, 2018 at 12:06:39 AM UTC+11, pat…@amatc.com.au wrote:
> > 
> > > Elasticsearch - 5.6.13
> 
> > > Search Guard - search-guard-5:5.6.13-19.2
> 
> > > Java - openjdk version “1.8.0\_191”
> 
> > > Ubuntu 18.04
> 
> > >
> 
> > >
> 
> > > Certificates created on [https://search-guard.com/tls-certificate-generator/](https://search-guard.com/tls-certificate-generator/) as localhost and install runs without error, do I need to add root cert elsewhere ?
> 
> > >
> 
> > >
> 
> > > curl -u admin:admin -XGET '[https://localhost:9300](https://localhost:9300)’curl: (60) SSL certificate problem: unable to get local issuer certificateMore details here: [https://curl.haxx.se/docs/sslcerts.html](https://curl.haxx.se/docs/sslcerts.html)curl failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentioned above
> 
> > >
> 
> > >
> 
> > > searchguard.ssl.transport.enabled: truesearchguard.ssl.transport.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.transport.keystore\_password: xxxxsearchguard.ssl.transport.truststore\_filepath: truststore.jkssearchguard.ssl.transport.truststore\_password: xxxxsearchguard.ssl.transport.enforce\_hostname\_verification: falsesearchguard.ssl.http.enabled: truesearchguard.ssl.http.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.http.keystore\_password: xxxxsearchguard.ssl.http.truststore\_filepath: truststore.jkssearchguard.ssl.http.truststore\_password: xxxxsearchguard.authcz.admin\_dn: - CN=sgadminsearchguard.ssl.http.clientauth\_mode: OPTIONAL
> 
> > >
> 
> > > When asking questions, please provide the following information:
> 
> > > - Search Guard and Elasticsearch version
> 
> > > - Installed and used enterprise modules, if any
> 
> > > - JVM version and operating system version
> 
> > > - Search Guard configuration files
> 
> > > - Elasticsearch log messages on debug level
> 
> > > - Other installed Elasticsearch or Kibana plugins, if any

---

<div class="post-metadata">

**Author:** ![patrick](https://avatars.discourse-cdn.com/v4/letter/p/b2d939/32.png) [@patrick](https://forum.search-guard.com/u/patrick)\
**Post date:** [December 11, 2018, 10:26pm UTC](https://forum.search-guard.com/t/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate/1246/7 "2018-12-11T22:26:02Z")

</div>

Then how to get trusted certificates for search guard ?

> **···**
>
> On Wednesday, December 12, 2018 at 12:06:39 AM UTC+11, pat…@amatc.com.au wrote:
> 
> > Elasticsearch - 5.6.13
> 
> > Search Guard - search-guard-5:5.6.13-19.2
> 
> > Java - openjdk version “1.8.0\_191”
> 
> > Ubuntu 18.04
> 
> > 
> 
> > 
> 
> > Certificates created on [https://search-guard.com/tls-certificate-generator/](https://search-guard.com/tls-certificate-generator/) as localhost and install runs without error, do I need to add root cert elsewhere ?
> 
> > 
> 
> > 
> 
> > curl -u admin:admin -XGET '[https://localhost:9300](https://localhost:9300)’curl: (60) SSL certificate problem: unable to get local issuer certificateMore details here: [https://curl.haxx.se/docs/sslcerts.html](https://curl.haxx.se/docs/sslcerts.html)curl failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentioned above
> 
> > 
> 
> > 
> 
> > searchguard.ssl.transport.enabled: truesearchguard.ssl.transport.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.transport.keystore\_password: xxxxsearchguard.ssl.transport.truststore\_filepath: truststore.jkssearchguard.ssl.transport.truststore\_password: xxxxsearchguard.ssl.transport.enforce\_hostname\_verification: falsesearchguard.ssl.http.enabled: truesearchguard.ssl.http.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.http.keystore\_password: xxxxsearchguard.ssl.http.truststore\_filepath: truststore.jkssearchguard.ssl.http.truststore\_password: xxxxsearchguard.authcz.admin\_dn: - CN=sgadminsearchguard.ssl.http.clientauth\_mode: OPTIONAL
> 
> > 
> 
> > When asking questions, please provide the following information:
> 
> > - Search Guard and Elasticsearch version
> 
> > - Installed and used enterprise modules, if any
> 
> > - JVM version and operating system version
> 
> > - Search Guard configuration files
> 
> > - Elasticsearch log messages on debug level
> 
> > - Other installed Elasticsearch or Kibana plugins, if any

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [December 11, 2018, 10:37pm UTC](https://forum.search-guard.com/t/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate/1246/8 "2018-12-11T22:37:36Z")

</div>

If you need "offical" ssl certs you need to buy them (Verisign etc) or use letsencrypt.  
But all the SSL stuff is really not Search Guard specific.

> **···**
>
> > Am 11.12.2018 um 23:26 schrieb patrick@amatc.com.au:
> > 
> > Then how to get trusted certificates for search guard ?
> > 
> > On Wednesday, December 12, 2018 at 12:06:39 AM UTC+11, pat...@amatc.com.au wrote:  
> > Elasticsearch - 5.6.13  
> > Search Guard - search-guard-5:5.6.13-19.2  
> > Java - openjdk version "1.8.0\_191"  
> > Ubuntu 18.04
> > 
> > Certificates created on [TLS Certificate Generator - Search Guard](https://search-guard.com/tls-certificate-generator/) as localhost and install runs without error, do I need to add root cert elsewhere ?
> > 
> > curl -u admin:admin -XGET '[https://localhost:9300](https://localhost:9300)’curl: (60) SSL certificate problem: unable to get local issuer certificateMore details here: [https://curl.haxx.se/docs/sslcerts.htmlcurl](https://curl.haxx.se/docs/sslcerts.htmlcurl) failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentioned above
> > 
> > searchguard.ssl.transport.enabled: truesearchguard.ssl.transport.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.transport.keystore\_password: xxxxsearchguard.ssl.transport.truststore\_filepath: truststore.jkssearchguard.ssl.transport.truststore\_password: xxxxsearchguard.ssl.transport.enforce\_hostname\_verification: falsesearchguard.ssl.http.enabled: truesearchguard.ssl.http.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.http.keystore\_password: xxxxsearchguard.ssl.http.truststore\_filepath: truststore.jkssearchguard.ssl.http.truststore\_password: xxxxsearchguard.authcz.admin\_dn: - CN=sgadminsearchguard.ssl.http.clientauth\_mode: OPTIONAL
> > 
> > When asking questions, please provide the following information:
> > 
> > \* Search Guard and Elasticsearch version  
> > \* Installed and used enterprise modules, if any  
> > \* JVM version and operating system version  
> > \* Search Guard configuration files  
> > \* Elasticsearch log messages on debug level  
> > \* Other installed Elasticsearch or Kibana plugins, if any
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard Community Forum" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/c6f033d1-9525-4741-a2d9-522eb819ae66%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/c6f033d1-9525-4741-a2d9-522eb819ae66%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).

---

<div class="post-metadata">

**Author:** ![patrick](https://avatars.discourse-cdn.com/v4/letter/p/b2d939/32.png) [@patrick](https://forum.search-guard.com/u/patrick)\
**Post date:** [December 11, 2018, 10:42pm UTC](https://forum.search-guard.com/t/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate/1246/9 "2018-12-11T22:42:39Z")

</div>

I think it is because I can’t connect when ssl enabled.

> **···**
>
> On Wednesday, December 12, 2018 at 12:06:39 AM UTC+11, pat…@amatc.com.au wrote:
> 
> > Elasticsearch - 5.6.13
> 
> > Search Guard - search-guard-5:5.6.13-19.2
> 
> > Java - openjdk version “1.8.0\_191”
> 
> > Ubuntu 18.04
> 
> > 
> 
> > 
> 
> > Certificates created on [https://search-guard.com/tls-certificate-generator/](https://search-guard.com/tls-certificate-generator/) as localhost and install runs without error, do I need to add root cert elsewhere ?
> 
> > 
> 
> > 
> 
> > curl -u admin:admin -XGET '[https://localhost:9300](https://localhost:9300)’curl: (60) SSL certificate problem: unable to get local issuer certificateMore details here: [https://curl.haxx.se/docs/sslcerts.html](https://curl.haxx.se/docs/sslcerts.html)curl failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentioned above
> 
> > 
> 
> > 
> 
> > searchguard.ssl.transport.enabled: truesearchguard.ssl.transport.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.transport.keystore\_password: xxxxsearchguard.ssl.transport.truststore\_filepath: truststore.jkssearchguard.ssl.transport.truststore\_password: xxxxsearchguard.ssl.transport.enforce\_hostname\_verification: falsesearchguard.ssl.http.enabled: truesearchguard.ssl.http.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.http.keystore\_password: xxxxsearchguard.ssl.http.truststore\_filepath: truststore.jkssearchguard.ssl.http.truststore\_password: xxxxsearchguard.authcz.admin\_dn: - CN=sgadminsearchguard.ssl.http.clientauth\_mode: OPTIONAL
> 
> > 
> 
> > When asking questions, please provide the following information:
> 
> > - Search Guard and Elasticsearch version
> 
> > - Installed and used enterprise modules, if any
> 
> > - JVM version and operating system version
> 
> > - Search Guard configuration files
> 
> > - Elasticsearch log messages on debug level
> 
> > - Other installed Elasticsearch or Kibana plugins, if any

---

<div class="post-metadata">

**Author:** ![patrick](https://avatars.discourse-cdn.com/v4/letter/p/b2d939/32.png) [@patrick](https://forum.search-guard.com/u/patrick)\
**Post date:** [December 11, 2018, 10:48pm UTC](https://forum.search-guard.com/t/curl-60-ssl-certificate-problem-unable-to-get-local-issuer-certificate/1246/10 "2018-12-11T22:48:46Z")

</div>

I fixed it, I added pem in php.ini under curl.cainfo = /etc/ssl/cacert.pem

I downloaded the [curl - Extract CA Certs from Mozilla](https://curl.haxx.se/docs/caextract.html)

I added the root-ca.pem created by the certificate generator at the end of the file i downloaded and uploaded it to /etc/ssl/ directory.

🙂

> **···**
>
> On Wednesday, December 12, 2018 at 12:06:39 AM UTC+11, pat…@amatc.com.au wrote:
> 
> > Elasticsearch - 5.6.13
> 
> > Search Guard - search-guard-5:5.6.13-19.2
> 
> > Java - openjdk version “1.8.0\_191”
> 
> > Ubuntu 18.04
> 
> > 
> 
> > 
> 
> > Certificates created on [https://search-guard.com/tls-certificate-generator/](https://search-guard.com/tls-certificate-generator/) as localhost and install runs without error, do I need to add root cert elsewhere ?
> 
> > 
> 
> > 
> 
> > curl -u admin:admin -XGET '[https://localhost:9300](https://localhost:9300)’curl: (60) SSL certificate problem: unable to get local issuer certificateMore details here: [https://curl.haxx.se/docs/sslcerts.html](https://curl.haxx.se/docs/sslcerts.html)curl failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentioned above
> 
> > 
> 
> > 
> 
> > searchguard.ssl.transport.enabled: truesearchguard.ssl.transport.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.transport.keystore\_password: xxxxsearchguard.ssl.transport.truststore\_filepath: truststore.jkssearchguard.ssl.transport.truststore\_password: xxxxsearchguard.ssl.transport.enforce\_hostname\_verification: falsesearchguard.ssl.http.enabled: truesearchguard.ssl.http.keystore\_filepath: CN=localhost-keystore.jkssearchguard.ssl.http.keystore\_password: xxxxsearchguard.ssl.http.truststore\_filepath: truststore.jkssearchguard.ssl.http.truststore\_password: xxxxsearchguard.authcz.admin\_dn: - CN=sgadminsearchguard.ssl.http.clientauth\_mode: OPTIONAL
> 
> > 
> 
> > When asking questions, please provide the following information:
> 
> > - Search Guard and Elasticsearch version
> 
> > - Installed and used enterprise modules, if any
> 
> > - JVM version and operating system version
> 
> > - Search Guard configuration files
> 
> > - Elasticsearch log messages on debug level
> 
> > - Other installed Elasticsearch or Kibana plugins, if any
