# Problems galore to searchguard installation.

**URL:** <https://forum.search-guard.com/t/problems-galore-to-searchguard-installation/324>\
**Category:** Search Guard\
**Created:** [November 25, 2016, 5:52am UTC](https://forum.search-guard.com/t/problems-galore-to-searchguard-installation/324 "2016-11-25T05:52:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![a.pvcube](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@a.pvcube](https://forum.search-guard.com/u/a.pvcube)\
**Post date:** [November 25, 2016, 5:52am UTC](https://forum.search-guard.com/t/problems-galore-to-searchguard-installation/324/1 "2016-11-25T05:52:36Z")

</div>

OK…

What I thought was a simple one started out to be the most complex issue. If anyone has better documentation about a bare bones install that will be great as well.

Here is my installation

On Mac

Elastic Search 5.0.1 : Installed, running with no problem

kibana-5.0.1-darwin-x86\_64/bin : Installed running with no problem

What I want to do…

Basic authentication / Userid / password on http

Users / roles for indices on elasticsearch … .Simple as hell

I dont need any https; This is a demo box and i dont care about all the bells and whistles

Now the problem starts

Installed the search guard with this command

sudo bin/elasticsearch-plugin install -b com.floragunn:search-guard-5:5.0.1-8

→ Downloading com.floragunn:search-guard-5:5.0.1-8 from maven central

[=================================================] 100%

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

@ WARNING: plugin requires additional permissions @

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

- java.lang.RuntimePermission accessClassInPackage.sun.misc

- java.lang.RuntimePermission getClassLoader

- java.lang.RuntimePermission loadLibrary.\*

- java.lang.RuntimePermission setContextClassLoader

- java.lang.RuntimePermission shutdownHooks

- java.lang.reflect.ReflectPermission suppressAccessChecks

- java.security.SecurityPermission getProperty.ssl.KeyManagerFactory.algorithm

- java.util.PropertyPermission java.security.krb5.conf write

- java.util.PropertyPermission javax.security.auth.useSubjectCredsOnly write

- javax.security.auth.AuthPermission doAs

- javax.security.auth.AuthPermission modifyPrivateCredentials

- javax.security.auth.kerberos.ServicePermission \* accept

See [Permissions in the JDK](http://docs.oracle.com/javase/8/docs/technotes/guides/security/permissions.html)

for descriptions of what these permissions allow and the associated risks.

→ Installed search-guard-5

Then I add the the following to my elasticsearch.yml file

searchguard.ssl.transport.enabled: false

I get the following error and elasticsearch dies… Why is my elasticsearch dying… I just want the damn thing to start up…

**2016-11-24T21:39:53,036][WARN][o.e.c.l.LogConfigurator] ignoring unsupported logging configuration file [/usr/local/Cellar/elasticsearch/5.0.1/libexec/config/logging.yml], logging is configured via [/usr/local/Cellar/elasticsearch/5.0.1/libexec/config/log4j2.properties]**

**[2016-11-24T21:39:53,039][WARN][o.e.c.l.LogConfigurator] ignoring unsupported logging configuration file [/usr/local/Cellar/elasticsearch/5.0.1/libexec/config/shield/logging.yml], logging is configured via [/usr/local/Cellar/elasticsearch/5.0.1/libexec/config/shield/log4j2.properties]**

**[2016-11-24T21:39:53,176][INFO][o.e.n.Node] [] initializing …**

**[2016-11-24T21:39:53,238][INFO][o.e.e.NodeEnvironment] [JZLU7fg] using [1] data paths, mounts [[/ (/dev/disk1)]], net usable\_space [36.4gb], net total\_space [120gb], spins? [unknown], types [hfs]**

**[2016-11-24T21:39:53,238][INFO][o.e.e.NodeEnvironment] [JZLU7fg] heap size [1.9gb], compressed ordinary object pointers [true]**

**[2016-11-24T21:39:53,357][INFO][o.e.n.Node] [JZLU7fg] node name [JZLU7fg] derived from node ID; set [node.name] to override**

**[2016-11-24T21:39:53,359][INFO][o.e.n.Node] [JZLU7fg] version[5.0.1], pid[67642], build[080bb47/2016-11-11T22:08:49.812Z], OS[Mac OS X/10.11.6/x86\_64], JVM[Oracle Corporation/Java HotSpot™ 64-Bit Server VM/1.8.0\_102/25.102-b14]**

**[2016-11-24T21:39:54,085][WARN][o.e.b.ElasticsearchUncaughtExceptionHandler] [] uncaught exception in thread [main]**

**org.elasticsearch.bootstrap.StartupException: ElasticsearchException[Failed to load plugin class [com.floragunn.searchguard.SearchGuardPlugin]]; nested: InvocationTargetException; nested: IllegalStateException[searchguard.ssl.transport.enabled must be set to ‘true’];**

\*\* at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:116) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Elasticsearch.execute(Elasticsearch.java:103) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.cli.SettingCommand.execute(SettingCommand.java:54) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:96) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.cli.Command.main(Command.java:62) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:80) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:73) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

**Caused by: org.elasticsearch.ElasticsearchException: Failed to load plugin class [com.floragunn.searchguard.SearchGuardPlugin]**

\*\* at org.elasticsearch.plugins.PluginsService.loadPlugin(PluginsService.java:462) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.plugins.PluginsService.loadBundles(PluginsService.java:414) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.plugins.PluginsService.(PluginsService.java:144) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.node.Node.(Node.java:281) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.node.Node.(Node.java:220) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Bootstrap$5.(Bootstrap.java:191) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Bootstrap.setup(Bootstrap.java:191) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:286) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:112) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* … 6 more\*\*

**Caused by: java.lang.reflect.InvocationTargetException**

\*\* at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) ~[?:?]\*\*

\*\* at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62) ~[?:?]\*\*

\*\* at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45) ~[?:?]\*\*

\*\* at java.lang.reflect.Constructor.newInstance(Constructor.java:423) ~[?:1.8.0\_102]\*\*

\*\* at org.elasticsearch.plugins.PluginsService.loadPlugin(PluginsService.java:451) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.plugins.PluginsService.loadBundles(PluginsService.java:414) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.plugins.PluginsService.(PluginsService.java:144) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.node.Node.(Node.java:281) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.node.Node.(Node.java:220) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Bootstrap$5.(Bootstrap.java:191) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Bootstrap.setup(Bootstrap.java:191) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:286) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:112) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* … 6 more\*\*

**Caused by: java.lang.IllegalStateException: searchguard.ssl.transport.enabled must be set to ‘true’**

\*\* at com.floragunn.searchguard.SearchGuardPlugin.(SearchGuardPlugin.java:95) ~[?:?]\*\*

\*\* at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) ~[?:?]\*\*

\*\* at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62) ~[?:?]\*\*

\*\* at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45) ~[?:?]\*\*

\*\* at java.lang.reflect.Constructor.newInstance(Constructor.java:423) ~[?:1.8.0\_102]\*\*

\*\* at org.elasticsearch.plugins.PluginsService.loadPlugin(PluginsService.java:451) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.plugins.PluginsService.loadBundles(PluginsService.java:414) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.plugins.PluginsService.(PluginsService.java:144) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.node.Node.(Node.java:281) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.node.Node.(Node.java:220) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Bootstrap$5.(Bootstrap.java:191) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Bootstrap.setup(Bootstrap.java:191) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:286) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:112) ~[elasticsearch-5.0.1.jar:5.0.1]\*\*

\*\* … 6 more\*\*

Why is my elasticsearch dying ?? Why does this require SSL and what parameters must be configured…

I have my kibana and elasticsearch on the same box… I just want a simple auth dialog to show up to the end users that is it…

Thanks for your help…

---

<div class="post-metadata">

**Author:** ![a.pvcube](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@a.pvcube](https://forum.search-guard.com/u/a.pvcube)\
**Post date:** [November 25, 2016, 10:42am UTC](https://forum.search-guard.com/t/problems-galore-to-searchguard-installation/324/2 "2016-11-25T10:42:35Z")

</div>

OK. Here is an update.. Looks like no matter what I do I cannot initialize the searchguard index..

I have elastic search running. I have the script that does the initialization of the index with the following

bash ./sgadmin.sh -cd ../sgconfig/ -ks /usr/local/Cellar/elasticsearch/5.0.1/libexec/config/pvcubekeystore.jks -ts /usr/local/Cellar/elasticsearch/5.0.1/libexec/config/pvcubetruststore.jks -tspass pw -kspass pw -nhnv -icl

This keeps giving me the following error on the sgadmin window..

Cannot retrieve cluster state due to None of the configured nodes are available: [{#transport#-1}{YmjJ-xkgQSaDVGnngOS5UA}{127.0.0.1}{127.0.0.1:9300}]. This is not an error, will keep on trying …

On the other hand my elasticsearch window keeps giving me excptions and keeps giving me garbage…

My elasticsearch.yml file looks like this

# Enable SSL via Search Guard SSL plugin

# Enable HTTPS

searchguard.ssl.http.enabled: true

searchguard.ssl.http.keystore\_filepath: pvcubekeystore.jks

searchguard.ssl.http.keystore\_password: pw

searchguard.ssl.http.truststore\_filepath: pvcubetruststore.jks

searchguard.ssl.http.truststore\_password: pw

# Enable SSL between ES nodes

searchguard.ssl.transport.enabled: true

searchguard.ssl.transport.keystore\_filepath: pvcubekeystore.jks

searchguard.ssl.transport.keystore\_password: pw

searchguard.ssl.transport.truststore\_filepath: pvcubetruststore.jks

searchguard.ssl.transport.truststore\_password: pw

searchguard.ssl.transport.enforce\_hostname\_verification: false

# for Search Guard

#searchguard.authcz.admin\_dn:

searchguard.authcz.admin\_dn:

- cn=kirk, ou=client, o=client, l=Test, c=DE

# - “cn=kirk, ou=client, o=client, l=Your\_Location, c=US”

# - “cn=Let’s Encrypt Authority X30, o=Let’s Encrypt,c=US”.

I have tried all the three vairants of the admin\_dn and none of them is useful…

[2016-11-25T02:35:05,438][INFO][o.e.n.Node] [JZLU7fg] node name [JZLU7fg] derived from node ID; set [node.name] to override

[2016-11-25T02:35:05,441][INFO][o.e.n.Node] [JZLU7fg] version[5.0.1], pid[73012], build[080bb47/2016-11-11T22:08:49.812Z], OS[Mac OS X/10.11.6/x86\_64], JVM[Oracle Corporation/Java HotSpot™ 64-Bit Server VM/1.8.0\_102/25.102-b14]

[2016-11-25T02:35:06,111][INFO][c.f.s.SearchGuardPlugin] Node [JZLU7fg] is a transportClient: false/tribeNode: false/tribeNodeClient: false

[2016-11-25T02:35:06,111][INFO][c.f.s.SearchGuardPlugin] FLS/DLS module not available

[2016-11-25T02:35:06,113][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [aggs-matrix-stats]

[2016-11-25T02:35:06,113][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [ingest-common]

[2016-11-25T02:35:06,113][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [lang-expression]

[2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [lang-groovy]

[2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [lang-mustache]

[2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [lang-painless]

[2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [percolator]

[2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [reindex]

[2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [transport-netty3]

[2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [transport-netty4]

[2016-11-25T02:35:06,115][INFO][o.e.p.PluginsService] [JZLU7fg] loaded plugin [search-guard-5]

[2016-11-25T02:35:06,579][INFO][c.f.s.s.SearchGuardKeyStore] Open SSL not available (this is not an error, we simply fallback to built-in JDK SSL) because of java.lang.ClassNotFoundException: org.apache.tomcat.jni.SSL

[2016-11-25T02:35:06,579][INFO][c.f.s.s.SearchGuardKeyStore] Open SSL not available (this is not an error, we simply fallback to built-in JDK SSL) because of java.lang.ClassNotFoundException: org.apache.tomcat.jni.SSL

[2016-11-25T02:35:06,884][INFO][c.f.s.s.SearchGuardKeyStore] Config directory is /usr/local/Cellar/elasticsearch/5.0.1/libexec/config/, from there the key- and truststore files are resolved relatively

[2016-11-25T02:35:06,903][INFO][c.f.s.s.SearchGuardKeyStore] HTTPS client auth mode OPTIONAL

[2016-11-25T02:35:06,907][INFO][c.f.s.s.SearchGuardKeyStore] AES-256 not supported, max key length for AES is 128 bit.. That is not an issue, it just limits possible encryption strength. To enable AES 256 install ‘Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files’

[2016-11-25T02:35:06,908][INFO][c.f.s.s.SearchGuardKeyStore] sslTransportClientProvider:JDK with ciphers [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256]

[2016-11-25T02:35:06,908][INFO][c.f.s.s.SearchGuardKeyStore] sslTransportServerProvider:JDK with ciphers [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256]

[2016-11-25T02:35:06,908][INFO][c.f.s.s.SearchGuardKeyStore] sslHTTPProvider:JDK with ciphers [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256]

[2016-11-25T02:35:06,908][INFO][c.f.s.s.SearchGuardKeyStore] sslTransport protocols [TLSv1.2, TLSv1.1]

[2016-11-25T02:35:06,908][INFO][c.f.s.s.SearchGuardKeyStore] sslHTTP protocols [TLSv1.2, TLSv1.1]

[2016-11-25T02:35:07,426][INFO][c.f.s.c.ConfigurationModule] FLS/DLS valve not bound (noop)

[2016-11-25T02:35:07,427][INFO][c.f.s.a.AuditLogModule] Auditlog not available

[2016-11-25T02:35:07,996][INFO][o.e.n.Node] [JZLU7fg] initialized

[2016-11-25T02:35:07,997][INFO][o.e.n.Node] [JZLU7fg] starting …

[2016-11-25T02:35:08,122][INFO][o.e.t.TransportService] [JZLU7fg] publish\_address {127.0.0.1:9300}, bound\_addresses {127.0.0.1:9300}

[2016-11-25T02:35:08,129][INFO][c.f.s.a.c.TransportConfigUpdateAction] [JZLU7fg] Check if searchguard index exists …

[2016-11-25T02:35:08,135][DEBUG][o.e.a.a.i.e.i.TransportIndicesExistsAction] [JZLU7fg] no known master node, scheduling a retry

[2016-11-25T02:35:11,223][INFO][o.e.c.s.ClusterService] [JZLU7fg] new\_master {JZLU7fg}{JZLU7fgvRBKsGT\_au9uV-g}{LypLY54ZQxy0PzHspGs2fQ}{127.0.0.1}{127.0.0.1:9300}, reason: zen-disco-elected-as-master ([0] nodes joined)

[2016-11-25T02:35:11,240][INFO][o.e.h.HttpServer] [JZLU7fg] publish\_address {127.0.0.1:9200}, bound\_addresses {127.0.0.1:9200}

[2016-11-25T02:35:11,240][INFO][o.e.n.Node] [JZLU7fg] started

[2016-11-25T02:35:11,707][INFO][c.f.s.a.c.TransportConfigUpdateAction] [JZLU7fg] searchguard index does not exist yet, so no need to load config on node startup. Use sgadmin to initialize cluster

[2016-11-25T02:35:11,707][INFO][o.e.g.GatewayService] [JZLU7fg] recovered [19] indices into cluster\_state

[2016-11-25T02:35:13,023][INFO][o.e.c.r.a.AllocationService] [JZLU7fg] Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[movies][3], [movies][4]] …]).

[2016-11-25T02:35:43,955][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x1cc1ce37, L:0.0.0.0/0.0.0.0:9300 ! R:/127.0.0.1:61381]], closing connection

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain

```
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]

at java.lang.Thread.run(Thread.java:745) [?:1.8.0_102]

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]

at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]

at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]

at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]

at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0_102]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]

at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]

at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]

at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0_102]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

[2016-11-25T02:35:48,740][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x74b98930, L:0.0.0.0/0.0.0.0:9300 ! R:/127.0.0.1:61382]], closing connection

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain

```
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]

at java.lang.Thread.run(Thread.java:745) [?:1.8.0_102]

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]

at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]

at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]

at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]

at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0_102]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]

at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]

at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]

at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0_102]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

[2016-11-25T02:35:53,780][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x1927c0ec, L:0.0.0.0/0.0.0.0:9300 ! R:/127.0.0.1:61383]], closing connection

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain

```
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]

at java.lang.Thread.run(Thread.java:745) [?:1.8.0_102]

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]

at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]

at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]

at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]

at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0_102]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]

at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]

at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]

at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0_102]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

[2016-11-25T02:35:58,811][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x5a7c1f79, L:0.0.0.0/0.0.0.0:9300 ! R:/127.0.0.1:61384]], closing connection

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain

```
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]

at java.lang.Thread.run(Thread.java:745) [?:1.8.0_102]

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]

at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]

at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]

at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]

at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0_102]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]

at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]

at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]

at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0_102]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

[2016-11-25T02:36:03,842][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0xa296aa24, L:0.0.0.0/0.0.0.0:9300 ! R:/127.0.0.1:61385]], closing connection

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain

```
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]

at java.lang.Thread.run(Thread.java:745) [?:1.8.0_102]

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]

at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]

at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]

at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]

at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0_102]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]

at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]

at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]

at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0_102]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

[2016-11-25T02:36:08,871][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0xc659f4c6, L:0.0.0.0/0.0.0.0:9300 ! R:/127.0.0.1:61387]], closing connection

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain

```
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]

at java.lang.Thread.run(Thread.java:745) [?:1.8.0_102]

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]

at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]

at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]

at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]

at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0_102]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]

at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]

at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]

at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0_102]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

[2016-11-25T02:36:13,901][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x1595addf, L:0.0.0.0/0.0.0.0:9300 ! R:/127.0.0.1:61390]], closing connection

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain

```
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]

at java.lang.Thread.run(Thread.java:745) [?:1.8.0_102]

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]

at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]

at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]

at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]

at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0_102]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]

at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]

at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]

at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0_102]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

[2016-11-25T02:36:18,932][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x205a5050, L:0.0.0.0/0.0.0.0:9300 ! R:/127.0.0.1:61392]], closing connection

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain

```
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]

at java.lang.Thread.run(Thread.java:745) [?:1.8.0_102]

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]

at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]

at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]

at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]

at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0_102]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]

at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]

at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]

at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0_102]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

[2016-11-25T02:36:23,968][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0xf268b46a, L:0.0.0.0/0.0.0.0:9300 ! R:/127.0.0.1:61395]], closing connection

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain

```
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]

at java.lang.Thread.run(Thread.java:745) [?:1.8.0_102]

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]

at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]

at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]

at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]

at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0_102]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]

at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]

at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]

at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0_102]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

[2016-11-25T02:36:29,002][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x2b4c0e2d, L:0.0.0.0/0.0.0.0:9300 ! R:/127.0.0.1:61396]], closing connection

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain

```
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]

at java.lang.Thread.run(Thread.java:745) [?:1.8.0_102]

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]

at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]

at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]

at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]

at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0_102]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]

at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]

at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]

at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0_102]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

[2016-11-25T02:36:34,035][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x440ecd04, L:0.0.0.0/0.0.0.0:9300 ! R:/127.0.0.1:61398]], closing connection

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain

```
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]

at java.lang.Thread.run(Thread.java:745) [?:1.8.0_102]

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]

at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]

at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]

at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]

at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0_102]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]

at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]

at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]

at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0_102]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

[2016-11-25T02:36:39,073][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x364846f9, L:0.0.0.0/0.0.0.0:9300 ! R:/127.0.0.1:61399]], closing connection

io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain

```
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]

at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]

at java.lang.Thread.run(Thread.java:745) [?:1.8.0_102]

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]

at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]

at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]

at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]

at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0_102]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

Caused by: javax.net.ssl.SSLHandshakeException: null cert chain

```
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]

at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]

at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]

at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]

at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]

at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]

at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]

at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0_102]

at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]

at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]

at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]

at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]

at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]

... 15 more

```

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [November 25, 2016, 2:24pm UTC](https://forum.search-guard.com/t/problems-galore-to-searchguard-installation/324/3 "2016-11-25T14:24:39Z")

</div>

Search Guard requires TLS on the transport level and it cannot be disabled:

> **[Security and Alerting for Elasticsearch and Kibana | Search Guard](https://search-guard.com/)**
>
> Search Guard is an Open Source security plugin for Elasticsearch, Kibana and the entire ELK stack. Search Guard offers encryption, authentication, authorization, audit logging, compliance as well as alerting and anomaly detection features.

Please refer also to the documentation:

“Search Guard requires TLS on the transport level in order to operate correctly. We provide a brief configuration example for the TLS layer here. If you need more in-depth information, please refer to the [https://github.com/floragunncom/search-guard-ssl-docs](https://github.com/floragunncom/search-guard-ssl-docs)”

You will find a step-by-step installation guide here:

[https://github.com/floragunncom/search-guard-ssl-docs/blob/master/quickstart.md](https://github.com/floragunncom/search-guard-ssl-docs/blob/master/quickstart.md)

You can use the example PKI script, or our certificate generator if you just need sample certificates:

> **[Security and Alerting for Elasticsearch and Kibana | Search Guard](https://search-guard.com/)**
>
> Search Guard is an Open Source security plugin for Elasticsearch, Kibana and the entire ELK stack. Search Guard offers encryption, authentication, authorization, audit logging, compliance as well as alerting and anomaly detection features.

If you use the cert generator, the README also contains the searchguard.authcz.admin\_dn entry that you can copy and paste to your elasticsearch.yml file.

Kibana configuration is covered here:

[https://github.com/floragunncom/search-guard-docs/blob/master/kibana.md](https://github.com/floragunncom/search-guard-docs/blob/master/kibana.md)

> **···**
>
> On Friday, 25 November 2016 11:42:35 UTC+1, [a.pvcube@gmail.com](mailto:a.pvcube@gmail.com) wrote:
> 
> > OK. Here is an update… Looks like no matter what I do I cannot initialize the searchguard index…
> 
> > I have elastic search running. I have the script that does the initialization of the index with the following
> 
> > 
> 
> > bash ./sgadmin.sh -cd …/sgconfig/ -ks /usr/local/Cellar/elasticsearch/5.0.1/libexec/config/pvcubekeystore.jks -ts /usr/local/Cellar/elasticsearch/5.0.1/libexec/config/pvcubetruststore.jks -tspass pw -kspass pw -nhnv -icl
> 
> > 
> 
> > This keeps giving me the following error on the sgadmin window…
> 
> > Cannot retrieve cluster state due to None of the configured nodes are available: [{#transport#-1}{YmjJ-xkgQSaDVGnngOS5UA}{127.0.0.1}{127.0.0.1:9300}]. This is not an error, will keep on trying …
> 
> > 
> 
> > 
> 
> > On the other hand my elasticsearch window keeps giving me excptions and keeps giving me garbage…
> 
> > 
> 
> > My elasticsearch.yml file looks like this
> 
> > 
> 
> > # Enable SSL via Search Guard SSL plugin
> 
> > # Enable HTTPS
> 
> > searchguard.ssl.http.enabled: true
> 
> > searchguard.ssl.http.keystore\_filepath: pvcubekeystore.jks
> 
> > searchguard.ssl.http.keystore\_password: pw
> 
> > searchguard.ssl.http.truststore\_filepath: pvcubetruststore.jks
> 
> > searchguard.ssl.http.truststore\_password: pw
> 
> > 
> 
> > # Enable SSL between ES nodes
> 
> > searchguard.ssl.transport.enabled: true
> 
> > searchguard.ssl.transport.keystore\_filepath: pvcubekeystore.jks
> 
> > searchguard.ssl.transport.keystore\_password: pw
> 
> > searchguard.ssl.transport.truststore\_filepath: pvcubetruststore.jks
> 
> > searchguard.ssl.transport.truststore\_password: pw
> 
> > searchguard.ssl.transport.enforce\_hostname\_verification: false
> 
> > # for Search Guard
> 
> > #searchguard.authcz.admin\_dn:
> 
> > searchguard.authcz.admin\_dn:
> 
> > - cn=kirk, ou=client, o=client, l=Test, c=DE
> 
> > # - “cn=kirk, ou=client, o=client, l=Your\_Location, c=US”
> 
> > # - “cn=Let’s Encrypt Authority X30, o=Let’s Encrypt,c=US”.
> 
> > 
> 
> > I have tried all the three vairants of the admin\_dn and none of them is useful…
> 
> > 
> 
> > 
> 
> > [2016-11-25T02:35:05,438][INFO][o.e.n.Node] [JZLU7fg] node name [JZLU7fg] derived from node ID; set [[node.name](http://node.name)] to override
> 
> > [2016-11-25T02:35:05,441][INFO][o.e.n.Node] [JZLU7fg] version[5.0.1], pid[73012], build[080bb47/2016-11-11T22:08:49.812Z], OS[Mac OS X/10.11.6/x86\_64], JVM[Oracle Corporation/Java HotSpot™ 64-Bit Server VM/1.8.0\_102/25.102-b14]
> 
> > [2016-11-25T02:35:06,111][INFO][c.f.s.SearchGuardPlugin] Node [JZLU7fg] is a transportClient: false/tribeNode: false/tribeNodeClient: false
> 
> > [2016-11-25T02:35:06,111][INFO][c.f.s.SearchGuardPlugin] FLS/DLS module not available
> 
> > [2016-11-25T02:35:06,113][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [aggs-matrix-stats]
> 
> > [2016-11-25T02:35:06,113][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [ingest-common]
> 
> > [2016-11-25T02:35:06,113][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [lang-expression]
> 
> > [2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [lang-groovy]
> 
> > [2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [lang-mustache]
> 
> > [2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [lang-painless]
> 
> > [2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [percolator]
> 
> > [2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [reindex]
> 
> > [2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [transport-netty3]
> 
> > [2016-11-25T02:35:06,114][INFO][o.e.p.PluginsService] [JZLU7fg] loaded module [transport-netty4]
> 
> > [2016-11-25T02:35:06,115][INFO][o.e.p.PluginsService] [JZLU7fg] loaded plugin [search-guard-5]
> 
> > [2016-11-25T02:35:06,579][INFO][c.f.s.s.SearchGuardKeyStore] Open SSL not available (this is not an error, we simply fallback to built-in JDK SSL) because of java.lang.ClassNotFoundException: org.apache.tomcat.jni.SSL
> 
> > [2016-11-25T02:35:06,579][INFO][c.f.s.s.SearchGuardKeyStore] Open SSL not available (this is not an error, we simply fallback to built-in JDK SSL) because of java.lang.ClassNotFoundException: org.apache.tomcat.jni.SSL
> 
> > [2016-11-25T02:35:06,884][INFO][c.f.s.s.SearchGuardKeyStore] Config directory is /usr/local/Cellar/elasticsearch/5.0.1/libexec/config/, from there the key- and truststore files are resolved relatively
> 
> > [2016-11-25T02:35:06,903][INFO][c.f.s.s.SearchGuardKeyStore] HTTPS client auth mode OPTIONAL
> 
> > [2016-11-25T02:35:06,907][INFO][c.f.s.s.SearchGuardKeyStore] AES-256 not supported, max key length for AES is 128 bit… That is not an issue, it just limits possible encryption strength. To enable AES 256 install ‘Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files’
> 
> > [2016-11-25T02:35:06,908][INFO][c.f.s.s.SearchGuardKeyStore] sslTransportClientProvider:JDK with ciphers [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256]
> 
> > [2016-11-25T02:35:06,908][INFO][c.f.s.s.SearchGuardKeyStore] sslTransportServerProvider:JDK with ciphers [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256]
> 
> > [2016-11-25T02:35:06,908][INFO][c.f.s.s.SearchGuardKeyStore] sslHTTPProvider:JDK with ciphers [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256]
> 
> > [2016-11-25T02:35:06,908][INFO][c.f.s.s.SearchGuardKeyStore] sslTransport protocols [TLSv1.2, TLSv1.1]
> 
> > [2016-11-25T02:35:06,908][INFO][c.f.s.s.SearchGuardKeyStore] sslHTTP protocols [TLSv1.2, TLSv1.1]
> 
> > [2016-11-25T02:35:07,426][INFO][c.f.s.c.ConfigurationModule] FLS/DLS valve not bound (noop)
> 
> > [2016-11-25T02:35:07,427][INFO][c.f.s.a.AuditLogModule] Auditlog not available
> 
> > [2016-11-25T02:35:07,996][INFO][o.e.n.Node] [JZLU7fg] initialized
> 
> > [2016-11-25T02:35:07,997][INFO][o.e.n.Node] [JZLU7fg] starting …
> 
> > [2016-11-25T02:35:08,122][INFO][o.e.t.TransportService] [JZLU7fg] publish\_address {[127.0.0.1:9300](http://127.0.0.1:9300)}, bound\_addresses {[127.0.0.1:9300](http://127.0.0.1:9300)}
> 
> > [2016-11-25T02:35:08,129][INFO][c.f.s.a.c.TransportConfigUpdateAction] [JZLU7fg] Check if searchguard index exists …
> 
> > [2016-11-25T02:35:08,135][DEBUG][o.e.a.a.i.e.i.TransportIndicesExistsAction] [JZLU7fg] no known master node, scheduling a retry
> 
> > [2016-11-25T02:35:11,223][INFO][o.e.c.s.ClusterService] [JZLU7fg] new\_master {JZLU7fg}{JZLU7fgvRBKsGT\_au9uV-g}{LypLY54ZQxy0PzHspGs2fQ}{127.0.0.1}{[127.0.0.1:9300](http://127.0.0.1:9300)}, reason: zen-disco-elected-as-master ([0] nodes joined)
> 
> > [2016-11-25T02:35:11,240][INFO][o.e.h.HttpServer] [JZLU7fg] publish\_address {[127.0.0.1:9200](http://127.0.0.1:9200)}, bound\_addresses {[127.0.0.1:9200](http://127.0.0.1:9200)}
> 
> > [2016-11-25T02:35:11,240][INFO][o.e.n.Node] [JZLU7fg] started
> 
> > [2016-11-25T02:35:11,707][INFO][c.f.s.a.c.TransportConfigUpdateAction] [JZLU7fg] searchguard index does not exist yet, so no need to load config on node startup. Use sgadmin to initialize cluster
> 
> > [2016-11-25T02:35:11,707][INFO][o.e.g.GatewayService] [JZLU7fg] recovered [19] indices into cluster\_state
> 
> > [2016-11-25T02:35:13,023][INFO][o.e.c.r.a.AllocationService] [JZLU7fg] Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[movies][3], [movies][4]] …]).
> 
> > [2016-11-25T02:35:43,955][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x1cc1ce37, L:[0.0.0.0/0.0.0.0:9300](http://0.0.0.0/0.0.0.0:9300) ! R:/127.0.0.1:61381]], closing connection
> 
> > io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]
> 
> > at java.lang.Thread.run(Thread.java:745) [?:1.8.0\_102]
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]
> 
> > at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0\_102]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]
> 
> > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_102]
> 
> > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > [2016-11-25T02:35:48,740][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x74b98930, L:[0.0.0.0/0.0.0.0:9300](http://0.0.0.0/0.0.0.0:9300) ! R:/127.0.0.1:61382]], closing connection
> 
> > io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]
> 
> > at java.lang.Thread.run(Thread.java:745) [?:1.8.0\_102]
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]
> 
> > at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0\_102]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]
> 
> > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_102]
> 
> > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > [2016-11-25T02:35:53,780][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x1927c0ec, L:[0.0.0.0/0.0.0.0:9300](http://0.0.0.0/0.0.0.0:9300) ! R:/127.0.0.1:61383]], closing connection
> 
> > io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]
> 
> > at java.lang.Thread.run(Thread.java:745) [?:1.8.0\_102]
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]
> 
> > at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0\_102]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]
> 
> > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_102]
> 
> > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > [2016-11-25T02:35:58,811][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x5a7c1f79, L:[0.0.0.0/0.0.0.0:9300](http://0.0.0.0/0.0.0.0:9300) ! R:/127.0.0.1:61384]], closing connection
> 
> > io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]
> 
> > at java.lang.Thread.run(Thread.java:745) [?:1.8.0\_102]
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]
> 
> > at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0\_102]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]
> 
> > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_102]
> 
> > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > [2016-11-25T02:36:03,842][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0xa296aa24, L:[0.0.0.0/0.0.0.0:9300](http://0.0.0.0/0.0.0.0:9300) ! R:/127.0.0.1:61385]], closing connection
> 
> > io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]
> 
> > at java.lang.Thread.run(Thread.java:745) [?:1.8.0\_102]
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]
> 
> > at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0\_102]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]
> 
> > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_102]
> 
> > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > [2016-11-25T02:36:08,871][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0xc659f4c6, L:[0.0.0.0/0.0.0.0:9300](http://0.0.0.0/0.0.0.0:9300) ! R:/127.0.0.1:61387]], closing connection
> 
> > io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]
> 
> > at java.lang.Thread.run(Thread.java:745) [?:1.8.0\_102]
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]
> 
> > at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0\_102]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]
> 
> > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_102]
> 
> > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > [2016-11-25T02:36:13,901][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x1595addf, L:[0.0.0.0/0.0.0.0:9300](http://0.0.0.0/0.0.0.0:9300) ! R:/127.0.0.1:61390]], closing connection
> 
> > io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:467) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:437) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:873) [netty-common-4.1.5.Final.jar:4.1.5.Final]
> 
> > at java.lang.Thread.run(Thread.java:745) [?:1.8.0\_102]
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Handshaker.checkThrown(Handshaker.java:1431) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.checkTaskThrown(SSLEngineImpl.java:535) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:813) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781) ~[?:?]
> 
> > at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[?:1.8.0\_102]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1094) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:966) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > Caused by: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at sun.security.ssl.Alerts.getSSLException(Alerts.java:192) ~[?:?]
> 
> > at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:304) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:292) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.clientCertificate(ServerHandshaker.java:1865) ~[?:?]
> 
> > at sun.security.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:230) ~[?:?]
> 
> > at sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:919) ~[?:?]
> 
> > at sun.security.ssl.Handshaker$1.run(Handshaker.java:916) ~[?:?]
> 
> > at java.security.AccessController.doPrivileged(Native Method) ~[?:1.8.0\_102]
> 
> > at sun.security.ssl.Handshaker$DelegatedTask.run(Handshaker.java:1369) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.runDelegatedTasks(SslHandler.java:1120) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1005) ~[?:?]
> 
> > at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:900) ~[?:?]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:411) ~[?:?]
> 
> > … 15 more
> 
> > [2016-11-25T02:36:18,932][WARN][c.f.s.s.t.SearchGuardSSLNettyTransport] [JZLU7fg] exception caught on transport layer [[id: 0x205a5050, L:[0.0.0.0/0.0.0.0:9300](http://0.0.0.0/0.0.0.0:9300) ! R:/127.0.0.1:61392]], closing connection
> 
> > io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: null cert chain
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:442) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:248) ~[netty-codec-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:350) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:372) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:358) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:129) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:610) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:513) [netty-transport-4.1.5.Final.jar:4.1.5.Final]
> 
> > at io.n
> 
> > …
