# python client cannot connect to Elasticsearch

**URL:** <https://forum.search-guard.com/t/python-client-cannot-connect-to-elasticsearch/396>\
**Category:** Search Guard\
**Created:** [February 21, 2017, 10:27pm UTC](https://forum.search-guard.com/t/python-client-cannot-connect-to-elasticsearch/396 "2017-02-21T22:27:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robert\_Chen](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@Robert\_Chen](https://forum.search-guard.com/u/Robert_Chen)\
**Post date:** [February 21, 2017, 10:27pm UTC](https://forum.search-guard.com/t/python-client-cannot-connect-to-elasticsearch/396/1 "2017-02-21T22:27:34Z")

</div>

test.py is like below, when I run it, it is always ConnectionError. curl is ok. (all keys are generated with example.sh, ELK and searchguard is 5.1 version)

from elasticsearch import Elasticsearch, RequestsHttpConnection  
import ssl

# SSL client authentication using client\_cert and client\_key

es = Elasticsearch(  
[‘10.8.8.246:9200’],  
http\_auth=(‘admin’, ‘admin’),  
port=9200,  
use\_ssl=True,  
ssl\_version=ssl.PROTOCOL\_TLSv1\_2,  
ca\_certs=‘./ca/chain-ca.pem’,  
client\_cert=‘./kirk.crtfull.pem.pem’,  
client\_key=‘./kirk.key.pem’  
)

print([es.info](http://es.info)())

[root@ip-10-8-8-246 example-pki-scripts]# python test.py  
Traceback (most recent call last):  
File “test.py”, line 21, in   
print([es.info](http://es.info)())  
File “/usr/local/lib/python2.7/site-packages/elasticsearch/client/utils.py”, line 73, in \_wrapped  
return func(\*args, params=params, \*\*kwargs)  
File “/usr/local/lib/python2.7/site-packages/elasticsearch/client/ **init**.py”, line 222, in info  
return self.transport.perform\_request(‘GET’, ‘/’, params=params)  
File “/usr/local/lib/python2.7/site-packages/elasticsearch/transport.py”, line 318, in perform\_request  
status, headers, data = connection.perform\_request(method, url, params, body, ignore=ignore, timeout=timeout)  
File “/usr/local/lib/python2.7/site-packages/elasticsearch/connection/http\_urllib3.py”, line 123, in perform\_request  
raise ConnectionError(‘N/A’, str(e), e)  
elasticsearch.exceptions.ConnectionError: ConnectionError((‘Connection failed.’, CannotSendRequest())) caused by: ConnectionError((‘Connection failed.’, CannotSendRequest()))

[root@ip-10-8-8-246 example-pki-scripts]# curl --insecure -E ./kirk-signed.pem --key ./kirk.key.pem [https://10.8.8.246:9200/\_cat/indices?v](https://10.8.8.246:9200/_cat/indices?v)  
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
green open mycompany-apache-2017.01.15 egQUvOtnT\_O8jiEuz06Luw 5 1 4 0 80.4kb 40.2kb

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [February 22, 2017, 3:36pm UTC](https://forum.search-guard.com/t/python-client-cannot-connect-to-elasticsearch/396/2 "2017-02-22T15:36:04Z")

</div>

this is know to work: [https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2](https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2)

Python (especially python 2) is a piece of .... regarding SSL/TLS support.  
So we recommend python 3 and these packages:

pip3 requests  
pip3 install cryptography  
pip3 install pyopenssl ndg-httpsclient pyasn1

Then do a "urllib3.contrib.pyopenssl.inject\_into\_urllib3()" and it works like magic

see [http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html](http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html)  
[elastalert and search guard · Issue #605 · Yelp/elastalert · GitHub](https://github.com/Yelp/elastalert/issues/605)

> **···**
>
> > Am 21.02.2017 um 23:27 schrieb Robert Chen \<robertchen117@gmail.com\>:
> > 
> > test.py is like below, when I run it, it is always ConnectionError. curl is ok. (all keys are generated with example.sh, ELK and searchguard is 5.1 version)
> > 
> > from elasticsearch import Elasticsearch, RequestsHttpConnection  
> > import ssl
> > 
> > # SSL client authentication using client\_cert and client\_key  
> > es = Elasticsearch(  
> > &nbsp;&nbsp;&nbsp;&nbsp;['10.8.8.246:9200'],  
> > &nbsp;&nbsp;&nbsp;&nbsp;http\_auth=('admin', 'admin'),  
> > &nbsp;&nbsp;&nbsp;&nbsp;port=9200,  
> > &nbsp;&nbsp;&nbsp;&nbsp;use\_ssl=True,  
> > &nbsp;&nbsp;&nbsp;&nbsp;ssl\_version=ssl.PROTOCOL\_TLSv1\_2,  
> > &nbsp;&nbsp;&nbsp;&nbsp;ca\_certs='./ca/chain-ca.pem',  
> > &nbsp;&nbsp;&nbsp;&nbsp;client\_cert='./kirk.crtfull.pem.pem',  
> > &nbsp;&nbsp;&nbsp;&nbsp;client\_key='./kirk.key.pem'  
> > )
> > 
> > print(es.info())
> > 
> > [root@ip-10-8-8-246 example-pki-scripts]# python test.py  
> > Traceback (most recent call last):  
> > &nbsp;&nbsp;File "test.py", line 21, in \<module\>  
> > &nbsp;&nbsp;&nbsp;&nbsp;print(es.info())  
> > &nbsp;&nbsp;File "/usr/local/lib/python2.7/site-packages/elasticsearch/client/utils.py", line 73, in \_wrapped  
> > &nbsp;&nbsp;&nbsp;&nbsp;return func(\*args, params=params, \*\*kwargs)  
> > &nbsp;&nbsp;File "/usr/local/lib/python2.7/site-packages/elasticsearch/client/\_\_init\_\_.py", line 222, in info  
> > &nbsp;&nbsp;&nbsp;&nbsp;return self.transport.perform\_request('GET', '/', params=params)  
> > &nbsp;&nbsp;File "/usr/local/lib/python2.7/site-packages/elasticsearch/transport.py", line 318, in perform\_request  
> > &nbsp;&nbsp;&nbsp;&nbsp;status, headers, data = connection.perform\_request(method, url, params, body, ignore=ignore, timeout=timeout)  
> > &nbsp;&nbsp;File "/usr/local/lib/python2.7/site-packages/elasticsearch/connection/http\_urllib3.py", line 123, in perform\_request  
> > &nbsp;&nbsp;&nbsp;&nbsp;raise ConnectionError('N/A', str(e), e)  
> > elasticsearch.exceptions.ConnectionError: ConnectionError(('Connection failed.', CannotSendRequest())) caused by: ConnectionError(('Connection failed.', CannotSendRequest()))
> > 
> > [root@ip-10-8-8-246 example-pki-scripts]# curl --insecure -E ./kirk-signed.pem --key ./kirk.key.pem [https://10.8.8.246:9200/\_cat/indices?v](https://10.8.8.246:9200/_cat/indices?v)  
> > health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
> > green open mycompany-apache-2017.01.15 egQUvOtnT\_O8jiEuz06Luw 5 1 4 0 80.4kb 40.2kb
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).

---

<div class="post-metadata">

**Author:** ![pixelrebel](https://avatars.discourse-cdn.com/v4/letter/p/45deac/32.png) [@pixelrebel](https://forum.search-guard.com/u/pixelrebel)\
**Post date:** [May 8, 2017, 11:58pm UTC](https://forum.search-guard.com/t/python-client-cannot-connect-to-elasticsearch/396/3 "2017-05-08T23:58:40Z")

</div>

Is there a workaround for users who are required to use python2?

> **···**
>
> On Wednesday, February 22, 2017 at 7:36:05 AM UTC-8, Search Guard wrote:
> 
> > this is know to work: [https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2](https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2)
> > 
> > Python (especially python 2) is a piece of … regarding SSL/TLS support.
> > 
> > So we recommend python 3 and these packages:
> > 
> > pip3 requests
> > 
> > pip3 install cryptography
> > 
> > pip3 install pyopenssl ndg-httpsclient pyasn1
> > 
> > Then do a “urllib3.contrib.pyopenssl.inject\_into\_urllib3()” and it works like magic
> > 
> > see [http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html](http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html)
> > 
> > [https://github.com/Yelp/elastalert/issues/605](https://github.com/Yelp/elastalert/issues/605)
> > 
> > > Am 21.02.2017 um 23:27 schrieb Robert Chen [robert...@gmail.com](mailto:robert...@gmail.com):
> > 
> > > test.py is like below, when I run it, it is always ConnectionError. curl is ok. (all keys are generated with example.sh, ELK and searchguard is 5.1 version)
> > 
> > > from elasticsearch import Elasticsearch, RequestsHttpConnection
> > 
> > > import ssl
> > 
> > > # SSL client authentication using client\_cert and client\_key
> > 
> > > es = Elasticsearch(
> > 
> > > ```
> > > ['10.8.8.246:9200'],
> > > 
> > > ```
> > 
> > > ```
> > > http_auth=('admin', 'admin'),
> > > 
> > > ```
> > 
> > > ```
> > > port=9200,
> > > 
> > > ```
> > 
> > > ```
> > > use_ssl=True,
> > > 
> > > ```
> > 
> > > ```
> > > ssl_version=ssl.PROTOCOL_TLSv1_2,
> > > 
> > > ```
> > 
> > > ```
> > > ca_certs='./ca/chain-ca.pem',
> > > 
> > > ```
> > 
> > > ```
> > > client_cert='./kirk.crtfull.pem.pem',
> > > 
> > > ```
> > 
> > > ```
> > > client_key='./kirk.key.pem'
> > > 
> > > ```
> > 
> > > )
> > 
> > > print([es.info](http://es.info)())
> > 
> > > [root@ip-10-8-8-246 example-pki-scripts]# python test.py
> > 
> > > Traceback (most recent call last):
> > 
> > > File “test.py”, line 21, in
> > 
> > > ```
> > > print([es.info](http://es.info)())
> > > 
> > > ```
> > 
> > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/client/utils.py”, line 73, in \_wrapped
> > 
> > > ```
> > > return func(*args, params=params, **kwargs)
> > > 
> > > ```
> > 
> > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/client/ **init**.py”, line 222, in info
> > 
> > > ```
> > > return self.transport.perform_request('GET', '/', params=params)
> > > 
> > > ```
> > 
> > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/transport.py”, line 318, in perform\_request
> > 
> > > ```
> > > status, headers, data = connection.perform_request(method, url, params, body, ignore=ignore, timeout=timeout)
> > > 
> > > ```
> > 
> > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/connection/http\_urllib3.py”, line 123, in perform\_request
> > 
> > > ```
> > > raise ConnectionError('N/A', str(e), e)
> > > 
> > > ```
> > 
> > > elasticsearch.exceptions.ConnectionError: ConnectionError((‘Connection failed.’, CannotSendRequest())) caused by: ConnectionError((‘Connection failed.’, CannotSendRequest()))
> > 
> > > [root@ip-10-8-8-246 example-pki-scripts]# curl --insecure -E ./kirk-signed.pem --key ./kirk.key.pem [https://10.8.8.246:9200/\_cat/indices?v](https://10.8.8.246:9200/_cat/indices?v)
> > 
> > > health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
> > 
> > > green open mycompany-apache-2017.01.15 egQUvOtnT\_O8jiEuz06Luw 5 1 4 0 80.4kb 40.2kb
> > 
> > > –  
> > > You received this message because you are subscribed to the Google Groups “Search Guard” group.
> > 
> > > To unsubscribe from this group and stop receiving emails from it, send an email to [search-guard...@googlegroups.com](mailto:search-guard...@googlegroups.com).
> > 
> > > To post to this group, send email to [search...@googlegroups.com](mailto:search...@googlegroups.com).
> > 
> > > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com](https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com).
> > 
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![pixelrebel](https://avatars.discourse-cdn.com/v4/letter/p/45deac/32.png) [@pixelrebel](https://forum.search-guard.com/u/pixelrebel)\
**Post date:** [May 12, 2017, 9:19pm UTC](https://forum.search-guard.com/t/python-client-cannot-connect-to-elasticsearch/396/4 "2017-05-12T21:19:29Z")

</div>

I’m actually having a heck of a time trying to get the elasticsearch python module to work on a search-guarded cluster. I’ve tried both python2 and python3 without luck.

I can’t get either http basic auth, nor peer certs to work. I can get both methods to work with curl and logstash, but not with the python module. I’ve tried the above suggested methods, but nothing seems to work. Is there a working example I can use?

searchguard:  
dynamic:  
authc:  
basic\_internal\_auth\_domain:  
enabled: true  
order: 2  
http\_authenticator:  
type: basic  
challenge: true  
authentication\_backend:  
type: intern  
clientcert\_auth\_domain:  
enabled: true  
order: 1  
http\_authenticator:  
type: clientcert  
config:  
username\_attribute: cn #optional, if omitted DN becomes username  
challenge: false  
authentication\_backend:  
type: noop

``

> **···**
>
> On Monday, May 8, 2017 at 4:58:41 PM UTC-7, pixelrebel wrote:
> 
> > Is there a workaround for users who are required to use python2?
> 
> > On Wednesday, February 22, 2017 at 7:36:05 AM UTC-8, Search Guard wrote:
> > 
> > > this is know to work: [https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2](https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2)
> > > 
> > > Python (especially python 2) is a piece of … regarding SSL/TLS support.
> > > 
> > > So we recommend python 3 and these packages:
> > > 
> > > pip3 requests
> > > 
> > > pip3 install cryptography
> > > 
> > > pip3 install pyopenssl ndg-httpsclient pyasn1
> > > 
> > > Then do a “urllib3.contrib.pyopenssl.inject\_into\_urllib3()” and it works like magic
> > > 
> > > see [http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html](http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html)
> > > 
> > > [https://github.com/Yelp/elastalert/issues/605](https://github.com/Yelp/elastalert/issues/605)
> > > 
> > > > Am 21.02.2017 um 23:27 schrieb Robert Chen [robert...@gmail.com](mailto:robert...@gmail.com):
> > > 
> > > > test.py is like below, when I run it, it is always ConnectionError. curl is ok. (all keys are generated with example.sh, ELK and searchguard is 5.1 version)
> > > 
> > > > from elasticsearch import Elasticsearch, RequestsHttpConnection
> > > 
> > > > import ssl
> > > 
> > > > # SSL client authentication using client\_cert and client\_key
> > > 
> > > > es = Elasticsearch(
> > > 
> > > > ```
> > > > ['10.8.8.246:9200'],
> > > > 
> > > > ```
> > > 
> > > > ```
> > > > http_auth=('admin', 'admin'),
> > > > 
> > > > ```
> > > 
> > > > ```
> > > > port=9200,
> > > > 
> > > > ```
> > > 
> > > > ```
> > > > use_ssl=True,
> > > > 
> > > > ```
> > > 
> > > > ```
> > > > ssl_version=ssl.PROTOCOL_TLSv1_2,
> > > > 
> > > > ```
> > > 
> > > > ```
> > > > ca_certs='./ca/chain-ca.pem',
> > > > 
> > > > ```
> > > 
> > > > ```
> > > > client_cert='./kirk.crtfull.pem.pem',
> > > > 
> > > > ```
> > > 
> > > > ```
> > > > client_key='./kirk.key.pem'
> > > > 
> > > > ```
> > > 
> > > > )
> > > 
> > > > print([es.info](http://es.info)())
> > > 
> > > > [root@ip-10-8-8-246 example-pki-scripts]# python test.py
> > > 
> > > > Traceback (most recent call last):
> > > 
> > > > File “test.py”, line 21, in
> > > 
> > > > ```
> > > > print([es.info](http://es.info)())
> > > > 
> > > > ```
> > > 
> > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/client/utils.py”, line 73, in \_wrapped
> > > 
> > > > ```
> > > > return func(*args, params=params, **kwargs)
> > > > 
> > > > ```
> > > 
> > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/client/ **init**.py”, line 222, in info
> > > 
> > > > ```
> > > > return self.transport.perform_request('GET', '/', params=params)
> > > > 
> > > > ```
> > > 
> > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/transport.py”, line 318, in perform\_request
> > > 
> > > > ```
> > > > status, headers, data = connection.perform_request(method, url, params, body, ignore=ignore, timeout=timeout)
> > > > 
> > > > ```
> > > 
> > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/connection/http\_urllib3.py”, line 123, in perform\_request
> > > 
> > > > ```
> > > > raise ConnectionError('N/A', str(e), e)
> > > > 
> > > > ```
> > > 
> > > > elasticsearch.exceptions.ConnectionError: ConnectionError((‘Connection failed.’, CannotSendRequest())) caused by: ConnectionError((‘Connection failed.’, CannotSendRequest()))
> > > 
> > > > [root@ip-10-8-8-246 example-pki-scripts]# curl --insecure -E ./kirk-signed.pem --key ./kirk.key.pem [https://10.8.8.246:9200/\_cat/indices?v](https://10.8.8.246:9200/_cat/indices?v)
> > > 
> > > > health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
> > > 
> > > > green open mycompany-apache-2017.01.15 egQUvOtnT\_O8jiEuz06Luw 5 1 4 0 80.4kb 40.2kb
> > > 
> > > > –  
> > > > You received this message because you are subscribed to the Google Groups “Search Guard” group.
> > > 
> > > > To unsubscribe from this group and stop receiving emails from it, send an email to [search-guard...@googlegroups.com](mailto:search-guard...@googlegroups.com).
> > > 
> > > > To post to this group, send email to [search...@googlegroups.com](mailto:search...@googlegroups.com).
> > > 
> > > > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com](https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com).
> > > 
> > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![astuart](https://avatars.discourse-cdn.com/v4/letter/a/a3d4f5/32.png) [@astuart](https://forum.search-guard.com/u/astuart)\
**Post date:** [May 19, 2017, 4:41pm UTC](https://forum.search-guard.com/t/python-client-cannot-connect-to-elasticsearch/396/5 "2017-05-19T16:41:30Z")

</div>

bump

> **···**
>
> On Friday, May 12, 2017 at 5:19:30 PM UTC-4, pixelrebel wrote:
> 
> > I’m actually having a heck of a time trying to get the elasticsearch python module to work on a search-guarded cluster. I’ve tried both python2 and python3 without luck.
> > 
> > I can’t get either http basic auth, nor peer certs to work. I can get both methods to work with curl and logstash, but not with the python module. I’ve tried the above suggested methods, but nothing seems to work. Is there a working example I can use?
> > 
> > searchguard:  
> > dynamic:  
> > authc:  
> > basic\_internal\_auth\_domain:  
> > enabled: true  
> > order: 2  
> > http\_authenticator:  
> > type: basic  
> > challenge: true  
> > authentication\_backend:  
> > type: intern  
> > clientcert\_auth\_domain:  
> > enabled: true  
> > order: 1  
> > http\_authenticator:  
> > type: clientcert  
> > config:  
> > username\_attribute: cn #optional, if omitted DN becomes username  
> > challenge: false  
> > authentication\_backend:  
> > type: noop
> 
> > ``
> 
> > 
> 
> > On Monday, May 8, 2017 at 4:58:41 PM UTC-7, pixelrebel wrote:
> > 
> > > Is there a workaround for users who are required to use python2?
> 
> > > On Wednesday, February 22, 2017 at 7:36:05 AM UTC-8, Search Guard wrote:
> > > 
> > > > this is know to work: [https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2](https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2)
> > > > 
> > > > Python (especially python 2) is a piece of … regarding SSL/TLS support.
> > > > 
> > > > So we recommend python 3 and these packages:
> > > > 
> > > > pip3 requests
> > > > 
> > > > pip3 install cryptography
> > > > 
> > > > pip3 install pyopenssl ndg-httpsclient pyasn1
> > > > 
> > > > Then do a “urllib3.contrib.pyopenssl.inject\_into\_urllib3()” and it works like magic
> > > > 
> > > > see [http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html](http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html)
> > > > 
> > > > [https://github.com/Yelp/elastalert/issues/605](https://github.com/Yelp/elastalert/issues/605)
> > > > 
> > > > > Am 21.02.2017 um 23:27 schrieb Robert Chen [robert...@gmail.com](mailto:robert...@gmail.com):
> > > > 
> > > > > test.py is like below, when I run it, it is always ConnectionError. curl is ok. (all keys are generated with example.sh, ELK and searchguard is 5.1 version)
> > > > 
> > > > > from elasticsearch import Elasticsearch, RequestsHttpConnection
> > > > 
> > > > > import ssl
> > > > 
> > > > > # SSL client authentication using client\_cert and client\_key
> > > > 
> > > > > es = Elasticsearch(
> > > > 
> > > > > ```
> > > > > ['10.8.8.246:9200'],
> > > > > 
> > > > > ```
> > > > 
> > > > > ```
> > > > > http_auth=('admin', 'admin'),
> > > > > 
> > > > > ```
> > > > 
> > > > > ```
> > > > > port=9200,
> > > > > 
> > > > > ```
> > > > 
> > > > > ```
> > > > > use_ssl=True,
> > > > > 
> > > > > ```
> > > > 
> > > > > ```
> > > > > ssl_version=ssl.PROTOCOL_TLSv1_2,
> > > > > 
> > > > > ```
> > > > 
> > > > > ```
> > > > > ca_certs='./ca/chain-ca.pem',
> > > > > 
> > > > > ```
> > > > 
> > > > > ```
> > > > > client_cert='./kirk.crtfull.pem.pem',
> > > > > 
> > > > > ```
> > > > 
> > > > > ```
> > > > > client_key='./kirk.key.pem'
> > > > > 
> > > > > ```
> > > > 
> > > > > )
> > > > 
> > > > > print([es.info](http://es.info)())
> > > > 
> > > > > [root@ip-10-8-8-246 example-pki-scripts]# python test.py
> > > > 
> > > > > Traceback (most recent call last):
> > > > 
> > > > > File “test.py”, line 21, in
> > > > 
> > > > > ```
> > > > > print([es.info](http://es.info)())
> > > > > 
> > > > > ```
> > > > 
> > > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/client/utils.py”, line 73, in \_wrapped
> > > > 
> > > > > ```
> > > > > return func(*args, params=params, **kwargs)
> > > > > 
> > > > > ```
> > > > 
> > > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/client/ **init**.py”, line 222, in info
> > > > 
> > > > > ```
> > > > > return self.transport.perform_request('GET', '/', params=params)
> > > > > 
> > > > > ```
> > > > 
> > > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/transport.py”, line 318, in perform\_request
> > > > 
> > > > > ```
> > > > > status, headers, data = connection.perform_request(method, url, params, body, ignore=ignore, timeout=timeout)
> > > > > 
> > > > > ```
> > > > 
> > > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/connection/http\_urllib3.py”, line 123, in perform\_request
> > > > 
> > > > > ```
> > > > > raise ConnectionError('N/A', str(e), e)
> > > > > 
> > > > > ```
> > > > 
> > > > > elasticsearch.exceptions.ConnectionError: ConnectionError((‘Connection failed.’, CannotSendRequest())) caused by: ConnectionError((‘Connection failed.’, CannotSendRequest()))
> > > > 
> > > > > [root@ip-10-8-8-246 example-pki-scripts]# curl --insecure -E ./kirk-signed.pem --key ./kirk.key.pem [https://10.8.8.246:9200/\_cat/indices?v](https://10.8.8.246:9200/_cat/indices?v)
> > > > 
> > > > > health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
> > > > 
> > > > > green open mycompany-apache-2017.01.15 egQUvOtnT\_O8jiEuz06Luw 5 1 4 0 80.4kb 40.2kb
> > > > 
> > > > > –  
> > > > > You received this message because you are subscribed to the Google Groups “Search Guard” group.
> > > > 
> > > > > To unsubscribe from this group and stop receiving emails from it, send an email to [search-guard...@googlegroups.com](mailto:search-guard...@googlegroups.com).
> > > > 
> > > > > To post to this group, send email to [search...@googlegroups.com](mailto:search...@googlegroups.com).
> > > > 
> > > > > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com](https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com).
> > > > 
> > > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [May 19, 2017, 7:14pm UTC](https://forum.search-guard.com/t/python-client-cannot-connect-to-elasticsearch/396/6 "2017-05-19T19:14:06Z")

</div>

maybe this helps:

[https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2](https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2)  
[https://github.com/floragunncom/search-guard/issues/196](https://github.com/floragunncom/search-guard/issues/196)

> **···**
>
> > Am 19.05.2017 um 18:41 schrieb astuart@fkinls.com:
> > 
> > bump
> > 
> > On Friday, May 12, 2017 at 5:19:30 PM UTC-4, pixelrebel wrote:  
> > I'm actually having a heck of a time trying to get the elasticsearch python module to work on a search-guarded cluster. I've tried both python2 and python3 without luck.
> > 
> > I can't get either http basic auth, nor peer certs to work. I can get both methods to work with curl and logstash, but not with the python module. I've tried the above suggested methods, but nothing seems to work. Is there a working example I can use?
> > 
> > searchguard:  
> > &nbsp;&nbsp;dynamic:  
> > &nbsp;&nbsp;&nbsp;&nbsp;authc:  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;basic\_internal\_auth\_domain:  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;enabled: true  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;order: 2  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;http\_authenticator:  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;type: basic  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;challenge: true  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;authentication\_backend:  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;type: intern  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;clientcert\_auth\_domain:  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;enabled: true  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;order: 1  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;http\_authenticator:  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;type: clientcert  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;config:  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;username\_attribute: cn #optional, if omitted DN becomes username  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;challenge: false  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;authentication\_backend:  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;type: noop
> > 
> > On Monday, May 8, 2017 at 4:58:41 PM UTC-7, pixelrebel wrote:  
> > Is there a workaround for users who are required to use python2?
> > 
> > On Wednesday, February 22, 2017 at 7:36:05 AM UTC-8, Search Guard wrote:  
> > this is know to work: [https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2](https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2)
> > 
> > Python (especially python 2) is a piece of .... regarding SSL/TLS support.  
> > So we recommend python 3 and these packages:
> > 
> > pip3 requests  
> > pip3 install cryptography  
> > pip3 install pyopenssl ndg-httpsclient pyasn1
> > 
> > Then do a "urllib3.contrib.pyopenssl.inject\_into\_urllib3()" and it works like magic
> > 
> > see [http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html](http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html)  
> > [elastalert and search guard · Issue #605 · Yelp/elastalert · GitHub](https://github.com/Yelp/elastalert/issues/605)
> > 
> > \> Am 21.02.2017 um 23:27 schrieb Robert Chen \<robert...@gmail.com\>:  
> > \>  
> > \> test.py is like below, when I run it, it is always ConnectionError. curl is ok. (all keys are generated with example.sh, ELK and searchguard is 5.1 version)  
> > \>  
> > \> from elasticsearch import Elasticsearch, RequestsHttpConnection  
> > \> import ssl  
> > \>  
> > \> # SSL client authentication using client\_cert and client\_key  
> > \> es = Elasticsearch(  
> > \> ['10.8.8.246:9200'],  
> > \> http\_auth=('admin', 'admin'),  
> > \> port=9200,  
> > \> use\_ssl=True,  
> > \> ssl\_version=ssl.PROTOCOL\_TLSv1\_2,  
> > \> ca\_certs='./ca/chain-ca.pem',  
> > \> client\_cert='./kirk.crtfull.pem.pem',  
> > \> client\_key='./kirk.key.pem'  
> > \> )  
> > \>  
> > \> print(es.info())  
> > \>  
> > \>  
> > \> [root@ip-10-8-8-246 example-pki-scripts]# python test.py  
> > \> Traceback (most recent call last):  
> > \> File "test.py", line 21, in \<module\>  
> > \> print(es.info())  
> > \> File "/usr/local/lib/python2.7/site-packages/elasticsearch/client/utils.py", line 73, in \_wrapped  
> > \> return func(\*args, params=params, \*\*kwargs)  
> > \> File "/usr/local/lib/python2.7/site-packages/elasticsearch/client/\_\_init\_\_.py", line 222, in info  
> > \> return self.transport.perform\_request('GET', '/', params=params)  
> > \> File "/usr/local/lib/python2.7/site-packages/elasticsearch/transport.py", line 318, in perform\_request  
> > \> status, headers, data = connection.perform\_request(method, url, params, body, ignore=ignore, timeout=timeout)  
> > \> File "/usr/local/lib/python2.7/site-packages/elasticsearch/connection/http\_urllib3.py", line 123, in perform\_request  
> > \> raise ConnectionError('N/A', str(e), e)  
> > \> elasticsearch.exceptions.ConnectionError: ConnectionError(('Connection failed.', CannotSendRequest())) caused by: ConnectionError(('Connection failed.', CannotSendRequest()))  
> > \>  
> > \> [root@ip-10-8-8-246 example-pki-scripts]# curl --insecure -E ./kirk-signed.pem --key ./kirk.key.pem [https://10.8.8.246:9200/\_cat/indices?v](https://10.8.8.246:9200/_cat/indices?v)  
> > \> health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
> > \> green open mycompany-apache-2017.01.15 egQUvOtnT\_O8jiEuz06Luw 5 1 4 0 80.4kb 40.2kb  
> > \>  
> > \>  
> > \> --  
> > \> You received this message because you are subscribed to the Google Groups "Search Guard" group.  
> > \> To unsubscribe from this group and stop receiving emails from it, send an email to search-guard...@googlegroups.com.  
> > \> To post to this group, send email to search...@googlegroups.com.  
> > \> To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com%5C).  
> > \> For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/32614206-9dbe-4b13-b3b4-a43c14ec7aa9%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/32614206-9dbe-4b13-b3b4-a43c14ec7aa9%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).

---

<div class="post-metadata">

**Author:** ![pixelrebel](https://avatars.discourse-cdn.com/v4/letter/p/45deac/32.png) [@pixelrebel](https://forum.search-guard.com/u/pixelrebel)\
**Post date:** [May 22, 2017, 4:40pm UTC](https://forum.search-guard.com/t/python-client-cannot-connect-to-elasticsearch/396/7 "2017-05-22T16:40:58Z")

</div>

Is there an example for python2? Installing SG on my cluster broke my stackstorm pack. Stackstorm unfortunately only runs on python2.

> **···**
>
> On Friday, May 19, 2017 at 12:14:01 PM UTC-7, Search Guard wrote:
> 
> > maybe this helps:
> > 
> > [https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2](https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2)
> > 
> > [https://github.com/floragunncom/search-guard/issues/196](https://github.com/floragunncom/search-guard/issues/196)
> > 
> > > Am 19.05.2017 um 18:41 schrieb [ast...@fkinls.com](mailto:ast...@fkinls.com):
> > 
> > > bump
> > 
> > > On Friday, May 12, 2017 at 5:19:30 PM UTC-4, pixelrebel wrote:
> > 
> > > I’m actually having a heck of a time trying to get the elasticsearch python module to work on a search-guarded cluster. I’ve tried both python2 and python3 without luck.
> > 
> > > I can’t get either http basic auth, nor peer certs to work. I can get both methods to work with curl and logstash, but not with the python module. I’ve tried the above suggested methods, but nothing seems to work. Is there a working example I can use?
> > 
> > > searchguard:
> > 
> > > dynamic:
> > 
> > > ```
> > > authc:
> > > 
> > > ```
> > 
> > > ```
> > > basic_internal_auth_domain:
> > > enabled: true
> > > 
> > > ```
> > 
> > > ```
> > > order: 2
> > > 
> > > ```
> > 
> > > ```
> > > http_authenticator:
> > > 
> > > ```
> > 
> > > ```
> > > type: basic
> > > 
> > > ```
> > 
> > > ```
> > > challenge: true
> > > 
> > > ```
> > 
> > > ```
> > > authentication_backend:
> > > 
> > > ```
> > 
> > > ```
> > > type: intern
> > > 
> > > ```
> > 
> > > ```
> > > clientcert_auth_domain:
> > > 
> > > ```
> > 
> > > ```
> > > enabled: true
> > > 
> > > ```
> > 
> > > ```
> > > order: 1
> > > 
> > > ```
> > 
> > > ```
> > > http_authenticator:
> > > 
> > > ```
> > 
> > > ```
> > > type: clientcert
> > > 
> > > ```
> > 
> > > ```
> > > config:
> > > 
> > > ```
> > 
> > > ```
> > > username_attribute: cn #optional, if omitted DN becomes username
> > > 
> > > ```
> > 
> > > ```
> > > challenge: false
> > > 
> > > ```
> > 
> > > ```
> > > authentication_backend:
> > > 
> > > ```
> > 
> > > ```
> > > type: noop
> > > 
> > > ```
> > 
> > > On Monday, May 8, 2017 at 4:58:41 PM UTC-7, pixelrebel wrote:
> > 
> > > Is there a workaround for users who are required to use python2?
> > 
> > > On Wednesday, February 22, 2017 at 7:36:05 AM UTC-8, Search Guard wrote:
> > 
> > > this is know to work: [https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2](https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2)
> > 
> > > Python (especially python 2) is a piece of … regarding SSL/TLS support.  
> > > So we recommend python 3 and these packages:
> > > 
> > > pip3 requests  
> > > pip3 install cryptography  
> > > pip3 install pyopenssl ndg-httpsclient pyasn1
> > > 
> > > Then do a “urllib3.contrib.pyopenssl.inject\_into\_urllib3()” and it works like magic
> > > 
> > > see [http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html](http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html)
> > 
> > > [https://github.com/Yelp/elastalert/issues/605](https://github.com/Yelp/elastalert/issues/605)
> > 
> > > > Am 21.02.2017 um 23:27 schrieb Robert Chen [robert...@gmail.com](mailto:robert...@gmail.com):
> > > > 
> > > > test.py is like below, when I run it, it is always ConnectionError. curl is ok. (all keys are generated with example.sh, ELK and searchguard is 5.1 version)
> > > > 
> > > > from elasticsearch import Elasticsearch, RequestsHttpConnection  
> > > > import ssl
> > > > 
> > > > # SSL client authentication using client\_cert and client\_key
> > > > 
> > > > es = Elasticsearch(  
> > > > [‘10.8.8.246:9200’],  
> > > > http\_auth=(‘admin’, ‘admin’),  
> > > > port=9200,  
> > > > use\_ssl=True,  
> > > > ssl\_version=ssl.PROTOCOL\_TLSv1\_2,  
> > > > ca\_certs=‘./ca/chain-ca.pem’,  
> > > > client\_cert=‘./kirk.crtfull.pem.pem’,  
> > > > client\_key=‘./kirk.key.pem’  
> > > > )
> > > > 
> > > > print([es.info](http://es.info)())
> > > > 
> > > > [root@ip-10-8-8-246 example-pki-scripts]# python test.py  
> > > > Traceback (most recent call last):  
> > > > File “test.py”, line 21, in   
> > > > print([es.info](http://es.info)())  
> > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/client/utils.py”, line 73, in \_wrapped  
> > > > return func(\*args, params=params, \*\*kwargs)  
> > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/client/ **init**.py”, line 222, in info  
> > > > return self.transport.perform\_request(‘GET’, ‘/’, params=params)  
> > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/transport.py”, line 318, in perform\_request  
> > > > status, headers, data = connection.perform\_request(method, url, params, body, ignore=ignore, timeout=timeout)  
> > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/connection/http\_urllib3.py”, line 123, in perform\_request  
> > > > raise ConnectionError(‘N/A’, str(e), e)  
> > > > elasticsearch.exceptions.ConnectionError: ConnectionError((‘Connection failed.’, CannotSendRequest())) caused by: ConnectionError((‘Connection failed.’, CannotSendRequest()))
> > > > 
> > > > [root@ip-10-8-8-246 example-pki-scripts]# curl --insecure -E ./kirk-signed.pem --key ./kirk.key.pem [https://10.8.8.246:9200/\_cat/indices?v](https://10.8.8.246:9200/_cat/indices?v)
> > 
> > > > health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
> > > > green open mycompany-apache-2017.01.15 egQUvOtnT\_O8jiEuz06Luw 5 1 4 0 80.4kb 40.2kb
> > > > 
> > > > –  
> > > > You received this message because you are subscribed to the Google Groups “Search Guard” group.  
> > > > To unsubscribe from this group and stop receiving emails from it, send an email to [search-guard...@googlegroups.com](mailto:search-guard...@googlegroups.com).  
> > > > To post to this group, send email to [search...@googlegroups.com](mailto:search...@googlegroups.com).  
> > > > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com](https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com).  
> > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > 
> > > –  
> > > You received this message because you are subscribed to the Google Groups “Search Guard” group.
> > 
> > > To unsubscribe from this group and stop receiving emails from it, send an email to [search-guard...@googlegroups.com](mailto:search-guard...@googlegroups.com).
> > 
> > > To post to this group, send email to [search...@googlegroups.com](mailto:search...@googlegroups.com).
> > 
> > > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/32614206-9dbe-4b13-b3b4-a43c14ec7aa9%40googlegroups.com](https://groups.google.com/d/msgid/search-guard/32614206-9dbe-4b13-b3b4-a43c14ec7aa9%40googlegroups.com).
> > 
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![pixelrebel](https://avatars.discourse-cdn.com/v4/letter/p/45deac/32.png) [@pixelrebel](https://forum.search-guard.com/u/pixelrebel)\
**Post date:** [May 22, 2017, 5:00pm UTC](https://forum.search-guard.com/t/python-client-cannot-connect-to-elasticsearch/396/8 "2017-05-22T17:00:47Z")

</div>

Okay I actually have this working in python2! Thanks for those examples.

The crucial argument is `connection_class=RequestsHttpConnection` That seemed to kick the elasticsearch module in the butt.

Thanks!

> **···**
>
> On Friday, May 19, 2017 at 12:14:01 PM UTC-7, Search Guard wrote:
> 
> > maybe this helps:
> > 
> > [https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2](https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2)
> > 
> > [https://github.com/floragunncom/search-guard/issues/196](https://github.com/floragunncom/search-guard/issues/196)
> > 
> > > Am 19.05.2017 um 18:41 schrieb [ast...@fkinls.com](mailto:ast...@fkinls.com):
> > 
> > > bump
> > 
> > > On Friday, May 12, 2017 at 5:19:30 PM UTC-4, pixelrebel wrote:
> > 
> > > I’m actually having a heck of a time trying to get the elasticsearch python module to work on a search-guarded cluster. I’ve tried both python2 and python3 without luck.
> > 
> > > I can’t get either http basic auth, nor peer certs to work. I can get both methods to work with curl and logstash, but not with the python module. I’ve tried the above suggested methods, but nothing seems to work. Is there a working example I can use?
> > 
> > > searchguard:
> > 
> > > dynamic:
> > 
> > > ```
> > > authc:
> > > 
> > > ```
> > 
> > > ```
> > > basic_internal_auth_domain:
> > > enabled: true
> > > 
> > > ```
> > 
> > > ```
> > > order: 2
> > > 
> > > ```
> > 
> > > ```
> > > http_authenticator:
> > > 
> > > ```
> > 
> > > ```
> > > type: basic
> > > 
> > > ```
> > 
> > > ```
> > > challenge: true
> > > 
> > > ```
> > 
> > > ```
> > > authentication_backend:
> > > 
> > > ```
> > 
> > > ```
> > > type: intern
> > > 
> > > ```
> > 
> > > ```
> > > clientcert_auth_domain:
> > > 
> > > ```
> > 
> > > ```
> > > enabled: true
> > > 
> > > ```
> > 
> > > ```
> > > order: 1
> > > 
> > > ```
> > 
> > > ```
> > > http_authenticator:
> > > 
> > > ```
> > 
> > > ```
> > > type: clientcert
> > > 
> > > ```
> > 
> > > ```
> > > config:
> > > 
> > > ```
> > 
> > > ```
> > > username_attribute: cn #optional, if omitted DN becomes username
> > > 
> > > ```
> > 
> > > ```
> > > challenge: false
> > > 
> > > ```
> > 
> > > ```
> > > authentication_backend:
> > > 
> > > ```
> > 
> > > ```
> > > type: noop
> > > 
> > > ```
> > 
> > > On Monday, May 8, 2017 at 4:58:41 PM UTC-7, pixelrebel wrote:
> > 
> > > Is there a workaround for users who are required to use python2?
> > 
> > > On Wednesday, February 22, 2017 at 7:36:05 AM UTC-8, Search Guard wrote:
> > 
> > > this is know to work: [https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2](https://gist.github.com/floragunncom/9319a994ae09df64b2a173128f745ed2)
> > 
> > > Python (especially python 2) is a piece of … regarding SSL/TLS support.  
> > > So we recommend python 3 and these packages:
> > > 
> > > pip3 requests  
> > > pip3 install cryptography  
> > > pip3 install pyopenssl ndg-httpsclient pyasn1
> > > 
> > > Then do a “urllib3.contrib.pyopenssl.inject\_into\_urllib3()” and it works like magic
> > > 
> > > see [http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html](http://urllib3.readthedocs.io/en/latest/reference/urllib3.contrib.html)
> > 
> > > [https://github.com/Yelp/elastalert/issues/605](https://github.com/Yelp/elastalert/issues/605)
> > 
> > > > Am 21.02.2017 um 23:27 schrieb Robert Chen [robert...@gmail.com](mailto:robert...@gmail.com):
> > > > 
> > > > test.py is like below, when I run it, it is always ConnectionError. curl is ok. (all keys are generated with example.sh, ELK and searchguard is 5.1 version)
> > > > 
> > > > from elasticsearch import Elasticsearch, RequestsHttpConnection  
> > > > import ssl
> > > > 
> > > > # SSL client authentication using client\_cert and client\_key
> > > > 
> > > > es = Elasticsearch(  
> > > > [‘10.8.8.246:9200’],  
> > > > http\_auth=(‘admin’, ‘admin’),  
> > > > port=9200,  
> > > > use\_ssl=True,  
> > > > ssl\_version=ssl.PROTOCOL\_TLSv1\_2,  
> > > > ca\_certs=‘./ca/chain-ca.pem’,  
> > > > client\_cert=‘./kirk.crtfull.pem.pem’,  
> > > > client\_key=‘./kirk.key.pem’  
> > > > )
> > > > 
> > > > print([es.info](http://es.info)())
> > > > 
> > > > [root@ip-10-8-8-246 example-pki-scripts]# python test.py  
> > > > Traceback (most recent call last):  
> > > > File “test.py”, line 21, in   
> > > > print([es.info](http://es.info)())  
> > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/client/utils.py”, line 73, in \_wrapped  
> > > > return func(\*args, params=params, \*\*kwargs)  
> > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/client/ **init**.py”, line 222, in info  
> > > > return self.transport.perform\_request(‘GET’, ‘/’, params=params)  
> > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/transport.py”, line 318, in perform\_request  
> > > > status, headers, data = connection.perform\_request(method, url, params, body, ignore=ignore, timeout=timeout)  
> > > > File “/usr/local/lib/python2.7/site-packages/elasticsearch/connection/http\_urllib3.py”, line 123, in perform\_request  
> > > > raise ConnectionError(‘N/A’, str(e), e)  
> > > > elasticsearch.exceptions.ConnectionError: ConnectionError((‘Connection failed.’, CannotSendRequest())) caused by: ConnectionError((‘Connection failed.’, CannotSendRequest()))
> > > > 
> > > > [root@ip-10-8-8-246 example-pki-scripts]# curl --insecure -E ./kirk-signed.pem --key ./kirk.key.pem [https://10.8.8.246:9200/\_cat/indices?v](https://10.8.8.246:9200/_cat/indices?v)
> > 
> > > > health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
> > > > green open mycompany-apache-2017.01.15 egQUvOtnT\_O8jiEuz06Luw 5 1 4 0 80.4kb 40.2kb
> > > > 
> > > > –  
> > > > You received this message because you are subscribed to the Google Groups “Search Guard” group.  
> > > > To unsubscribe from this group and stop receiving emails from it, send an email to [search-guard...@googlegroups.com](mailto:search-guard...@googlegroups.com).  
> > > > To post to this group, send email to [search...@googlegroups.com](mailto:search...@googlegroups.com).  
> > > > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com](https://groups.google.com/d/msgid/search-guard/98601f16-827c-4377-96e5-f599c696fd86%40googlegroups.com).  
> > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > 
> > > –  
> > > You received this message because you are subscribed to the Google Groups “Search Guard” group.
> > 
> > > To unsubscribe from this group and stop receiving emails from it, send an email to [search-guard...@googlegroups.com](mailto:search-guard...@googlegroups.com).
> > 
> > > To post to this group, send email to [search...@googlegroups.com](mailto:search...@googlegroups.com).
> > 
> > > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/32614206-9dbe-4b13-b3b4-a43c14ec7aa9%40googlegroups.com](https://groups.google.com/d/msgid/search-guard/32614206-9dbe-4b13-b3b4-a43c14ec7aa9%40googlegroups.com).
> > 
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
