# Search Guard not initialized (SG11). See https://github.com/floragunncom/search-guard-docs/blob/mast

**URL:** <https://forum.search-guard.com/t/search-guard-not-initialized-sg11-see-https-github-com-floragunncom-search-guard-docs-blob-mast/948>\
**Category:** Search Guard\
**Created:** [June 13, 2018, 8:52am UTC](https://forum.search-guard.com/t/search-guard-not-initialized-sg11-see-https-github-com-floragunncom-search-guard-docs-blob-mast/948 "2018-06-13T08:52:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sheik\_Syed\_Ali](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Sheik\_Syed\_Ali](https://forum.search-guard.com/u/Sheik_Syed_Ali)\
**Post date:** [June 13, 2018, 8:52am UTC](https://forum.search-guard.com/t/search-guard-not-initialized-sg11-see-https-github-com-floragunncom-search-guard-docs-blob-mast/948/1 "2018-06-13T08:52:09Z")

</div>

Hi,

- Search Guard (5.6.4-18) and Elasticsearch (5.6.4)
- Using Search guard community edition
- Oracle JVM 1.8.0
- No Kibana and other plugins

I m generating the certificates using offline Search Guard tools which are provided by Search Guard. Please find the below information used for generating certificates.

> ca:  
> root:  
> dn: [CN=root.ca.searchblox.com](http://CN=root.ca.searchblox.com),OU=CA,O=SearchBlox Com, Inc.,DC=searchblox,DC=com  
> keysize: 2048  
> validityDays: 3650  
> pkPassword: auto  
> file: root-ca.pem  
> nodes:
> 
> - name: searchblox-node-1  
> dn: [CN=root.ca.searchblox.com](http://CN=root.ca.searchblox.com),OU=CA,O=SearchBlox Com, Inc.,DC=searchblox,DC=com  
> clients:
> - name: sheik  
> dn: [CN=sheik.example.com](http://CN=sheik.example.com),OU=Ops,O=Sheik Com, Inc.,DC=example,DC=com
> - name: kirk  
> dn: [CN=kirk.example.com](http://CN=kirk.example.com),OU=Ops,O=Example Com, Inc.,DC=example,DC=com  
> admin: true

Herewith I have attached the generated certificates which are generated by Search Guard Tools.

Find the elasticsearch.yml config below

> cluster.name: searchblox  
> node.name: searchblox-node-1  
> indices.fielddata.cache.size: 40%  
> http.enabled: true  
> elasticfence.disabled: false  
> elasticfence.root.password: searchblox  
> index.refresh\_interval: 4s  
> ######## Start Search Guard Demo Configuration ########  
> searchguard.ssl.transport.pemcert\_filepath: searchblox-node-1.pem  
> searchguard.ssl.transport.pemkey\_filepath: searchblox-node-1.key  
> searchguard.ssl.transport.pemtrustedcas\_filepath: root-ca.pem  
> searchguard.ssl.transport.enforce\_hostname\_verification: false  
> searchguard.ssl.http.enabled: true  
> searchguard.ssl.http.pemcert\_filepath: searchblox-node-1.pem  
> searchguard.ssl.http.pemkey\_filepath: searchblox-node-1.key  
> searchguard.ssl.http.pemtrustedcas\_filepath: root-ca.pem  
> searchguard.authcz.admin\_dn:
> 
> - CN=kirk,OU=client,O=client,L=test, C=de  
> searchguard.nodes\_dn:
> - ‘[CN=root.ca.searchblox.com](http://CN=root.ca.searchblox.com),OU=CA,O=SearchBlox Com, Inc.,DC=searchblox,DC=com’  
> ######## End Search Guard Demo Configuration ########

After the above configuration, I started the product I tried to approach the [https://localhost:9200/\_cat/indices](https://localhost:9200/_cat/indices) url. I got the “Search Guard not initialized (SG11). See [https://github.com/floragunncom/search-guard-docs/blob/master/sgadmin.md](https://github.com/floragunncom/search-guard-docs/blob/master/sgadmin.md)” the message

I tried to initiate Search Guard using sgadmin script, I received the below error.

> Command: **sh sgadmin.sh -cd …/sgconfig -key …/…/kirk.key -cert …/…/kirk.pem -cacert …/…/root-ca.pem -icl -nhnv --diagnose --accept-red-cluster -ff**

> Error message:  
> WARNING: JAVA\_HOME not set, will use /usr/bin/java  
> Search Guard Admin v5  
> Will connect to localhost:9300 … done  
> 1256 [main] INFO c.f.s.SearchGuardPlugin - Clustername: elasticsearch
> 
> ### LICENSE NOTICE Search Guard
> 
> If you use one or more of the following features in production  
> make sure you have a valid Search Guard license  
> (See [Security and Alerting for Elasticsearch and Kibana | Search Guard](https://floragunn.com/searchguard-validate-license))
> 
> - Kibana Multitenancy
> - LDAP authentication/authorization
> - Active Directory authentication/authorization
> - REST Management API
> - JSON Web Token (JWT) authentication/authorization
> - Kerberos authentication/authorization
> - Document- and Fieldlevel Security (DLS/FLS)
> - Auditlogging  
> In case of any doubt mail to [sales@floragunn.com](mailto:sales@floragunn.com)  
> ###################################  
> 1284 [main] INFO c.f.s.SearchGuardPlugin - Node [_client_] is a transportClient: true/tribeNode: false/tribeNodeClient: false  
> 1285 [main] INFO c.f.s.SearchGuardPlugin - FLS/DLS module not available  
> 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - Open SSL not available (this is not an error, we simply fallback to built-in JDK SSL) because of java.lang.ClassNotFoundException: io.netty.internal.tcnative.SSL  
> 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.version: 1.8.0\_151  
> 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vendor: Oracle Corporation  
> 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.specification.version: 1.8  
> 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.specification.vendor: Oracle Corporation  
> 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.specification.name: Java Virtual Machine Specification  
> 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.name: Java HotSpot™ 64-Bit Server VM  
> 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.vendor: Oracle Corporation  
> 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.specification.version: 1.8  
> 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.specification.vendor: Oracle Corporation  
> 1318 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.specification.name: Java Platform API Specification  
> 1318 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - os.name: Mac OS X  
> 1318 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - os.arch: x86\_64  
> 1318 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - os.version: 10.13.2  
> 1463 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - JVM supports the following 57 ciphers for https [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDH\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDH\_ECDSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDH\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DHE\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DHE\_DSS\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_EMPTY\_RENEGOTIATION\_INFO\_SCSV, TLS\_DH\_anon\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DH\_anon\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_anon\_WITH\_AES\_128\_CBC\_SHA, TLS\_DH\_anon\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_anon\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DH\_anon\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_RSA\_WITH\_DES\_CBC\_SHA, SSL\_DHE\_RSA\_WITH\_DES\_CBC\_SHA, SSL\_DHE\_DSS\_WITH\_DES\_CBC\_SHA, SSL\_DH\_anon\_WITH\_DES\_CBC\_SHA, SSL\_RSA\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DHE\_RSA\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DHE\_DSS\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DH\_anon\_EXPORT\_WITH\_DES40\_CBC\_SHA, TLS\_RSA\_WITH\_NULL\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_NULL\_SHA, TLS\_ECDHE\_RSA\_WITH\_NULL\_SHA, SSL\_RSA\_WITH\_NULL\_SHA, TLS\_ECDH\_ECDSA\_WITH\_NULL\_SHA, TLS\_ECDH\_RSA\_WITH\_NULL\_SHA, TLS\_ECDH\_anon\_WITH\_NULL\_SHA, SSL\_RSA\_WITH\_NULL\_MD5, TLS\_KRB5\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_KRB5\_WITH\_3DES\_EDE\_CBC\_MD5, TLS\_KRB5\_WITH\_DES\_CBC\_SHA, TLS\_KRB5\_WITH\_DES\_CBC\_MD5, TLS\_KRB5\_EXPORT\_WITH\_DES\_CBC\_40\_SHA, TLS\_KRB5\_EXPORT\_WITH\_DES\_CBC\_40\_MD5]  
> 1466 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - JVM supports the following 57 ciphers for transport [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDH\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDH\_ECDSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDH\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DHE\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DHE\_DSS\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_EMPTY\_RENEGOTIATION\_INFO\_SCSV, TLS\_DH\_anon\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DH\_anon\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_anon\_WITH\_AES\_128\_CBC\_SHA, TLS\_DH\_anon\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_anon\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DH\_anon\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_RSA\_WITH\_DES\_CBC\_SHA, SSL\_DHE\_RSA\_WITH\_DES\_CBC\_SHA, SSL\_DHE\_DSS\_WITH\_DES\_CBC\_SHA, SSL\_DH\_anon\_WITH\_DES\_CBC\_SHA, SSL\_RSA\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DHE\_RSA\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DHE\_DSS\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DH\_anon\_EXPORT\_WITH\_DES40\_CBC\_SHA, TLS\_RSA\_WITH\_NULL\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_NULL\_SHA, TLS\_ECDHE\_RSA\_WITH\_NULL\_SHA, SSL\_RSA\_WITH\_NULL\_SHA, TLS\_ECDH\_ECDSA\_WITH\_NULL\_SHA, TLS\_ECDH\_RSA\_WITH\_NULL\_SHA, TLS\_ECDH\_anon\_WITH\_NULL\_SHA, SSL\_RSA\_WITH\_NULL\_MD5, TLS\_KRB5\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_KRB5\_WITH\_3DES\_EDE\_CBC\_MD5, TLS\_KRB5\_WITH\_DES\_CBC\_SHA, TLS\_KRB5\_WITH\_DES\_CBC\_MD5, TLS\_KRB5\_EXPORT\_WITH\_DES\_CBC\_40\_SHA, TLS\_KRB5\_EXPORT\_WITH\_DES\_CBC\_40\_MD5]  
> 1467 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - Config directory is /Users/sheik/SearchBloxDev/gitsourcce/build/libs/exploded/searchblox-9.0.war/WEB-INF/lib/tools/, from there the key- and truststore files are resolved relatively  
> 1587 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - AES-256 not supported, max key length for AES is 128 bit… That is not an issue, it just limits possible encryption strength. To enable AES 256 install ‘Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files’  
> 1587 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslTransportClientProvider:JDK with ciphers [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256]  
> 1587 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslTransportServerProvider:JDK with ciphers [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256]  
> 1587 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslHTTPProvider:null with ciphers   
> 1588 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslTransport protocols [TLSv1.2, TLSv1.1]  
> 1588 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslHTTP protocols [TLSv1.2, TLSv1.1]  
> 1589 [main] INFO o.e.p.PluginsService - no modules loaded  
> 1590 [main] INFO o.e.p.PluginsService - loaded plugin [com.floragunn.searchguard.SearchGuardPlugin]  
> 1591 [main] INFO o.e.p.PluginsService - loaded plugin [org.elasticsearch.transport.Netty4Plugin]  
> 3166 [main] INFO o.e.c.t.TransportClientNodesService - failed to get node info for {#transport#-1}{uCZ8UuIqQXWIujCL59Fw8w}{localhost}{127.0.0.1:9300}, disconnecting…  
> org.elasticsearch.transport.RemoteTransportException: [searchblox-node-1][127.0.0.1:9300][cluster:monitor/nodes/liveness]  
> Caused by: org.elasticsearch.ElasticsearchSecurityException: Cannot authenticate null  
> at com.floragunn.searchguard.transport.SearchGuardRequestHandler.messageReceivedDecorate(SearchGuardRequestHandler.java:176) ~[search-guard-5-5.6.4-18.jar:?]  
> at com.floragunn.searchguard.ssl.transport.SearchGuardSSLRequestHandler.messageReceived(SearchGuardSSLRequestHandler.java:140) ~[search-guard-ssl-5.6.4-23.jar:5.6.4-23]  
> at com.floragunn.searchguard.SearchGuardPlugin$4$1.messageReceived(SearchGuardPlugin.java:423) ~[search-guard-5-5.6.4-18.jar:?]  
> at org.elasticsearch.transport.RequestHandlerRegistry.processMessageReceived(RequestHandlerRegistry.java:69) ~[elasticsearch-5.6.4.jar:5.6.4]  
> at org.elasticsearch.transport.TcpTransport$RequestHandler.doRun(TcpTransport.java:1553) ~[elasticsearch-5.6.4.jar:5.6.4]  
> at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) ~[elasticsearch-5.6.4.jar:5.6.4]  
> at org.elasticsearch.common.util.concurrent.EsExecutors$1.execute(EsExecutors.java:110) ~[elasticsearch-5.6.4.jar:5.6.4]  
> at org.elasticsearch.transport.TcpTransport.handleRequest(TcpTransport.java:1510) ~[elasticsearch-5.6.4.jar:5.6.4]  
> at org.elasticsearch.transport.TcpTransport.messageReceived(TcpTransport.java:1393) ~[elasticsearch-5.6.4.jar:5.6.4]  
> at org.elasticsearch.transport.netty4.Netty4MessageChannelHandler.channelRead(Netty4MessageChannelHandler.java:74) ~[transport-netty4-client-5.6.4.jar:5.6.4]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.handler.codec.ByteToMessageDecoder.fireChannelRead(ByteToMessageDecoder.java:310) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.handler.codec.ByteToMessageDecoder.fireChannelRead(ByteToMessageDecoder.java:297) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:413) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:265) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.ChannelInboundHandlerAdapter.channelRead(ChannelInboundHandlerAdapter.java:86) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.handler.logging.LoggingHandler.channelRead(LoggingHandler.java:241) ~[netty-handler-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1273) ~[netty-handler-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:1084) ~[netty-handler-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.handler.codec.ByteToMessageDecoder.decodeRemovalReentryProtection(ByteToMessageDecoder.java:489) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:428) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:265) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:134) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:644) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.nio.NioEventLoop.processSelectedKeysOptimized(NioEventLoop.java:579) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:496) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:458) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:858) ~[netty-common-4.1.13.Final.jar:4.1.13.Final]  
> at java.lang.Thread.run(Thread.java:748) ~[?:1.8.0\_151]  
> Failfast is activated  
> Diagnostic trace written to: /Users/sheik/SearchBloxDev/gitsourcce/build/libs/exploded/searchblox-9.0.war/WEB-INF/lib/tools/sgadmin\_diag\_trace\_2018-Jun-13\_14-20-23.txt  
> Contacting elasticsearch cluster ‘elasticsearch’ …  
> ERR: Cannot retrieve cluster state due to: None of the configured nodes are available: [{#transport#-1}{uCZ8UuIqQXWIujCL59Fw8w}{localhost}{127.0.0.1:9300}].  
> Root cause: NoNodeAvailableException[None of the configured nodes are available: [{#transport#-1}{uCZ8UuIqQXWIujCL59Fw8w}{localhost}{127.0.0.1:9300}]] (org.elasticsearch.client.transport.NoNodeAvailableException/org.elasticsearch.client.transport.NoNodeAvailableException)
> - Try running sgadmin.sh with -icl (but no -cl) and -nhnv (If thats works you need to check your clustername as well as hostnames in your SSL certificates)
> - Make also sure that your keystore or cert is a client certificate (not a node certificate) and configured properly in elasticsearch.yml
> - If this is not working, try running sgadmin.sh with --diagnose and see diagnose trace log file)
> - Add --accept-red-cluster to allow sgadmin to operate on a red cluster.

Please help me to resolve this situation.

Best,

-Sheik

[kirk.key](https://forum.search-guard.com/uploads/short-url/g0wwDNRQ7pznxEroVj0Pa4OsRbp.key) (1.66 KB)

[kirk.pem](https://forum.search-guard.com/uploads/short-url/2TVcjrz2r3x5F3U1Ent0axi3xq1.pem) (1.57 KB)

[searchblox-node-1.pem](https://forum.search-guard.com/uploads/short-url/utn3nELZh6Ldy20efx4q3sNgUMu.pem) (1.62 KB)

[searchblox-node-1.key](https://forum.search-guard.com/uploads/short-url/95Jk18sRdqyVNgYwTxQbV3afp3G.key) (1.66 KB)

[root-ca.key](https://forum.search-guard.com/uploads/short-url/qnBiukYbVKhfNw66ZGkGdHkpG5V.key) (1.76 KB)

[root-ca.pem](https://forum.search-guard.com/uploads/short-url/yorE8wPyqwGfb0r1buSr6saKUjz.pem) (1.36 KB)

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [June 13, 2018, 9:26am UTC](https://forum.search-guard.com/t/search-guard-not-initialized-sg11-see-https-github-com-floragunncom-search-guard-docs-blob-mast/948/2 "2018-06-13T09:26:08Z")

</div>

Seems your elasticsearch.yml is not correct, should look like

searchguard.nodes\_dn:  
- 'CN=root.ca.searchblox.com,OU=CA,O=SearchBlox Com\, Inc.,DC=searchblox,DC=com'  
searchguard.authcz.admin\_dn:  
- 'CN=kirk.example.com,OU=Ops,O=Example Com\, Inc.,DC=example,DC=com'

The entry:

> searchguard.authcz.admin\_dn:  
> &nbsp;&nbsp;- CN=kirk,OU=client,O=client,L=test, C=de

seems to be a leftover from the demo installation?

> **···**
>
> > Am 13.06.2018 um 10:52 schrieb sheik.syedali@searchblox.com:
> > 
> > Hi,  
> > &nbsp;&nbsp;• Search Guard (5.6.4-18) and Elasticsearch (5.6.4)  
> > &nbsp;&nbsp;• Using Search guard community edition  
> > &nbsp;&nbsp;• Oracle JVM 1.8.0  
> > &nbsp;&nbsp;• No Kibana and other plugins  
> > I m generating the certificates using offline Search Guard tools which are provided by Search Guard. Please find the below information used for generating certificates.
> > 
> > ca:  
> > &nbsp;&nbsp;&nbsp;root:  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;dn: CN=root.ca.searchblox.com,OU=CA,O=SearchBlox Com\, Inc.,DC=searchblox,DC=com  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;keysize: 2048  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;validityDays: 3650  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;pkPassword: auto  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;file: root-ca.pem  
> > nodes:  
> > &nbsp;&nbsp;- name: searchblox-node-1  
> > &nbsp;&nbsp;&nbsp;&nbsp;dn: CN=root.ca.searchblox.com,OU=CA,O=SearchBlox Com\, Inc.,DC=searchblox,DC=com  
> > clients:  
> > &nbsp;&nbsp;- name: sheik  
> > &nbsp;&nbsp;&nbsp;&nbsp;dn: CN=sheik.example.com,OU=Ops,O=Sheik Com\, Inc.,DC=example,DC=com  
> > &nbsp;&nbsp;- name: kirk  
> > &nbsp;&nbsp;&nbsp;&nbsp;dn: CN=kirk.example.com,OU=Ops,O=Example Com\, Inc.,DC=example,DC=com  
> > &nbsp;&nbsp;&nbsp;&nbsp;admin: true
> > 
> > Herewith I have attached the generated certificates which are generated by Search Guard Tools.
> > 
> > Find the elasticsearch.yml config below
> > 
> > cluster.name: searchblox  
> > node.name: searchblox-node-1  
> > indices.fielddata.cache.size: 40%  
> > http.enabled: true  
> > elasticfence.disabled: false  
> > elasticfence.root.password: searchblox  
> > index.refresh\_interval: 4s  
> > ######## Start Search Guard Demo Configuration ########  
> > searchguard.ssl.transport.pemcert\_filepath: searchblox-node-1.pem  
> > searchguard.ssl.transport.pemkey\_filepath: searchblox-node-1.key  
> > searchguard.ssl.transport.pemtrustedcas\_filepath: root-ca.pem  
> > searchguard.ssl.transport.enforce\_hostname\_verification: false  
> > searchguard.ssl.http.enabled: true  
> > searchguard.ssl.http.pemcert\_filepath: searchblox-node-1.pem  
> > searchguard.ssl.http.pemkey\_filepath: searchblox-node-1.key  
> > searchguard.ssl.http.pemtrustedcas\_filepath: root-ca.pem  
> > searchguard.authcz.admin\_dn:  
> > &nbsp;&nbsp;- CN=kirk,OU=client,O=client,L=test, C=de  
> > searchguard.nodes\_dn:  
> > &nbsp;&nbsp;- 'CN=root.ca.searchblox.com,OU=CA,O=SearchBlox Com\, Inc.,DC=searchblox,DC=com'  
> > ######## End Search Guard Demo Configuration ########
> > 
> > After the above configuration, I started the product I tried to approach the [https://localhost:9200/\_cat/indices](https://localhost:9200/_cat/indices) url. I got the "Search Guard not initialized (SG11). See [https://github.com/floragunncom/search-guard-docs/blob/master/sgadmin.md&quot](https://github.com/floragunncom/search-guard-docs/blob/master/sgadmin.md&quot); the message
> > 
> > I tried to initiate Search Guard using sgadmin script, I received the below error.
> > 
> > Command: sh sgadmin.sh -cd ../sgconfig -key ../../kirk.key -cert ../../kirk.pem -cacert ../../root-ca.pem -icl -nhnv --diagnose --accept-red-cluster -ff
> > 
> > Error message:  
> > WARNING: JAVA\_HOME not set, will use /usr/bin/java  
> > Search Guard Admin v5  
> > Will connect to localhost:9300 ... done  
> > 1256 [main] INFO c.f.s.SearchGuardPlugin - Clustername: elasticsearch  
> > ### LICENSE NOTICE Search Guard ###  
> > If you use one or more of the following features in production  
> > make sure you have a valid Search Guard license  
> > (See [Security and Alerting for Elasticsearch and Kibana | Search Guard](https://floragunn.com/searchguard-validate-license%5C))  
> > \* Kibana Multitenancy  
> > \* LDAP authentication/authorization  
> > \* Active Directory authentication/authorization  
> > \* REST Management API  
> > \* JSON Web Token (JWT) authentication/authorization  
> > \* Kerberos authentication/authorization  
> > \* Document- and Fieldlevel Security (DLS/FLS)  
> > \* Auditlogging  
> > In case of any doubt mail to \<sales@floragunn.com\>  
> > ###################################  
> > 1284 [main] INFO c.f.s.SearchGuardPlugin - Node [\_client\_] is a transportClient: true/tribeNode: false/tribeNodeClient: false  
> > 1285 [main] INFO c.f.s.SearchGuardPlugin - FLS/DLS module not available  
> > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - Open SSL not available (this is not an error, we simply fallback to built-in JDK SSL) because of java.lang.ClassNotFoundException: io.netty.internal.tcnative.SSL  
> > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.version: 1.8.0\_151  
> > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vendor: Oracle Corporation  
> > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.specification.version: 1.8  
> > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.specification.vendor: Oracle Corporation  
> > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.specification.name: Java Virtual Machine Specification  
> > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.name: Java HotSpot(TM) 64-Bit Server VM  
> > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.vendor: Oracle Corporation  
> > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.specification.version: 1.8  
> > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.specification.vendor: Oracle Corporation  
> > 1318 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.specification.name: Java Platform API Specification  
> > 1318 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - os.name: Mac OS X  
> > 1318 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - os.arch: x86\_64  
> > 1318 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - os.version: 10.13.2  
> > 1463 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - JVM supports the following 57 ciphers for https [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDH\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDH\_ECDSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDH\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DHE\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DHE\_DSS\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_EMPTY\_RENEGOTIATION\_INFO\_SCSV, TLS\_DH\_anon\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DH\_anon\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_anon\_WITH\_AES\_128\_CBC\_SHA, TLS\_DH\_anon\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_anon\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DH\_anon\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_RSA\_WITH\_DES\_CBC\_SHA, SSL\_DHE\_RSA\_WITH\_DES\_CBC\_SHA, SSL\_DHE\_DSS\_WITH\_DES\_CBC\_SHA, SSL\_DH\_anon\_WITH\_DES\_CBC\_SHA, SSL\_RSA\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DHE\_RSA\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DHE\_DSS\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DH\_anon\_EXPORT\_WITH\_DES40\_CBC\_SHA, TLS\_RSA\_WITH\_NULL\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_NULL\_SHA, TLS\_ECDHE\_RSA\_WITH\_NULL\_SHA, SSL\_RSA\_WITH\_NULL\_SHA, TLS\_ECDH\_ECDSA\_WITH\_NULL\_SHA, TLS\_ECDH\_RSA\_WITH\_NULL\_SHA, TLS\_ECDH\_anon\_WITH\_NULL\_SHA, SSL\_RSA\_WITH\_NULL\_MD5, TLS\_KRB5\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_KRB5\_WITH\_3DES\_EDE\_CBC\_MD5, TLS\_KRB5\_WITH\_DES\_CBC\_SHA, TLS\_KRB5\_WITH\_DES\_CBC\_MD5, TLS\_KRB5\_EXPORT\_WITH\_DES\_CBC\_40\_SHA, TLS\_KRB5\_EXPORT\_WITH\_DES\_CBC\_40\_MD5]  
> > 1466 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - JVM supports the following 57 ciphers for transport [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDH\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDH\_ECDSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDH\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DHE\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DHE\_DSS\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_EMPTY\_RENEGOTIATION\_INFO\_SCSV, TLS\_DH\_anon\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DH\_anon\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_anon\_WITH\_AES\_128\_CBC\_SHA, TLS\_DH\_anon\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_anon\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DH\_anon\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_RSA\_WITH\_DES\_CBC\_SHA, SSL\_DHE\_RSA\_WITH\_DES\_CBC\_SHA, SSL\_DHE\_DSS\_WITH\_DES\_CBC\_SHA, SSL\_DH\_anon\_WITH\_DES\_CBC\_SHA, SSL\_RSA\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DHE\_RSA\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DHE\_DSS\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DH\_anon\_EXPORT\_WITH\_DES40\_CBC\_SHA, TLS\_RSA\_WITH\_NULL\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_NULL\_SHA, TLS\_ECDHE\_RSA\_WITH\_NULL\_SHA, SSL\_RSA\_WITH\_NULL\_SHA, TLS\_ECDH\_ECDSA\_WITH\_NULL\_SHA, TLS\_ECDH\_RSA\_WITH\_NULL\_SHA, TLS\_ECDH\_anon\_WITH\_NULL\_SHA, SSL\_RSA\_WITH\_NULL\_MD5, TLS\_KRB5\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_KRB5\_WITH\_3DES\_EDE\_CBC\_MD5, TLS\_KRB5\_WITH\_DES\_CBC\_SHA, TLS\_KRB5\_WITH\_DES\_CBC\_MD5, TLS\_KRB5\_EXPORT\_WITH\_DES\_CBC\_40\_SHA, TLS\_KRB5\_EXPORT\_WITH\_DES\_CBC\_40\_MD5]  
> > 1467 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - Config directory is /Users/sheik/SearchBloxDev/gitsourcce/build/libs/exploded/searchblox-9.0.war/WEB-INF/lib/tools/, from there the key- and truststore files are resolved relatively  
> > 1587 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - AES-256 not supported, max key length for AES is 128 bit.. That is not an issue, it just limits possible encryption strength. To enable AES 256 install 'Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files'  
> > 1587 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslTransportClientProvider:JDK with ciphers [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256]  
> > 1587 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslTransportServerProvider:JDK with ciphers [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256]  
> > 1587 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslHTTPProvider:null with ciphers   
> > 1588 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslTransport protocols [TLSv1.2, TLSv1.1]  
> > 1588 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslHTTP protocols [TLSv1.2, TLSv1.1]  
> > 1589 [main] INFO o.e.p.PluginsService - no modules loaded  
> > 1590 [main] INFO o.e.p.PluginsService - loaded plugin [com.floragunn.searchguard.SearchGuardPlugin]  
> > 1591 [main] INFO o.e.p.PluginsService - loaded plugin [org.elasticsearch.transport.Netty4Plugin]  
> > 3166 [main] INFO o.e.c.t.TransportClientNodesService - failed to get node info for {#transport#-1}{uCZ8UuIqQXWIujCL59Fw8w}{localhost}{127.0.0.1:9300}, disconnecting...  
> > org.elasticsearch.transport.RemoteTransportException: [searchblox-node-1][127.0.0.1:9300][cluster:monitor/nodes/liveness]  
> > Caused by: org.elasticsearch.ElasticsearchSecurityException: Cannot authenticate null  
> > &nbsp;&nbsp;at com.floragunn.searchguard.transport.SearchGuardRequestHandler.messageReceivedDecorate(SearchGuardRequestHandler.java:176) ~[search-guard-5-5.6.4-18.jar:?]  
> > &nbsp;&nbsp;at com.floragunn.searchguard.ssl.transport.SearchGuardSSLRequestHandler.messageReceived(SearchGuardSSLRequestHandler.java:140) ~[search-guard-ssl-5.6.4-23.jar:5.6.4-23]  
> > &nbsp;&nbsp;at com.floragunn.searchguard.SearchGuardPlugin$4$1.messageReceived(SearchGuardPlugin.java:423) ~[search-guard-5-5.6.4-18.jar:?]  
> > &nbsp;&nbsp;at org.elasticsearch.transport.RequestHandlerRegistry.processMessageReceived(RequestHandlerRegistry.java:69) ~[elasticsearch-5.6.4.jar:5.6.4]  
> > &nbsp;&nbsp;at org.elasticsearch.transport.TcpTransport$RequestHandler.doRun(TcpTransport.java:1553) ~[elasticsearch-5.6.4.jar:5.6.4]  
> > &nbsp;&nbsp;at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) ~[elasticsearch-5.6.4.jar:5.6.4]  
> > &nbsp;&nbsp;at org.elasticsearch.common.util.concurrent.EsExecutors$1.execute(EsExecutors.java:110) ~[elasticsearch-5.6.4.jar:5.6.4]  
> > &nbsp;&nbsp;at org.elasticsearch.transport.TcpTransport.handleRequest(TcpTransport.java:1510) ~[elasticsearch-5.6.4.jar:5.6.4]  
> > &nbsp;&nbsp;at org.elasticsearch.transport.TcpTransport.messageReceived(TcpTransport.java:1393) ~[elasticsearch-5.6.4.jar:5.6.4]  
> > &nbsp;&nbsp;at org.elasticsearch.transport.netty4.Netty4MessageChannelHandler.channelRead(Netty4MessageChannelHandler.java:74) ~[transport-netty4-client-5.6.4.jar:5.6.4]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.handler.codec.ByteToMessageDecoder.fireChannelRead(ByteToMessageDecoder.java:310) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.handler.codec.ByteToMessageDecoder.fireChannelRead(ByteToMessageDecoder.java:297) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:413) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:265) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.ChannelInboundHandlerAdapter.channelRead(ChannelInboundHandlerAdapter.java:86) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.handler.logging.LoggingHandler.channelRead(LoggingHandler.java:241) ~[netty-handler-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1273) ~[netty-handler-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:1084) ~[netty-handler-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.handler.codec.ByteToMessageDecoder.decodeRemovalReentryProtection(ByteToMessageDecoder.java:489) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:428) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:265) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1334) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:926) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:134) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:644) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.nio.NioEventLoop.processSelectedKeysOptimized(NioEventLoop.java:579) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:496) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:458) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:858) ~[netty-common-4.1.13.Final.jar:4.1.13.Final]  
> > &nbsp;&nbsp;at java.lang.Thread.run(Thread.java:748) ~[?:1.8.0\_151]  
> > Failfast is activated  
> > Diagnostic trace written to: /Users/sheik/SearchBloxDev/gitsourcce/build/libs/exploded/searchblox-9.0.war/WEB-INF/lib/tools/sgadmin\_diag\_trace\_2018-Jun-13\_14-20-23.txt  
> > Contacting elasticsearch cluster 'elasticsearch' ...  
> > ERR: Cannot retrieve cluster state due to: None of the configured nodes are available: [{#transport#-1}{uCZ8UuIqQXWIujCL59Fw8w}{localhost}{127.0.0.1:9300}].  
> > &nbsp;&nbsp;Root cause: NoNodeAvailableException[None of the configured nodes are available: [{#transport#-1}{uCZ8UuIqQXWIujCL59Fw8w}{localhost}{127.0.0.1:9300}]] (org.elasticsearch.client.transport.NoNodeAvailableException/org.elasticsearch.client.transport.NoNodeAvailableException)  
> > &nbsp;&nbsp;&nbsp;\* Try running sgadmin.sh with -icl (but no -cl) and -nhnv (If thats works you need to check your clustername as well as hostnames in your SSL certificates)  
> > &nbsp;&nbsp;&nbsp;\* Make also sure that your keystore or cert is a client certificate (not a node certificate) and configured properly in elasticsearch.yml  
> > &nbsp;&nbsp;&nbsp;\* If this is not working, try running sgadmin.sh with --diagnose and see diagnose trace log file)  
> > &nbsp;&nbsp;&nbsp;\* Add --accept-red-cluster to allow sgadmin to operate on a red cluster.
> > 
> > Please help me to resolve this situation.
> > 
> > Best,  
> > -Sheik
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard Community Forum" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/935d670a-66f4-4adc-af7f-dc6b1978ec27%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/935d670a-66f4-4adc-af7f-dc6b1978ec27%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).  
> > \<kirk.key\>\<kirk.pem\>\<searchblox-node-1.pem\>\<searchblox-node-1.key\>\<root-ca.key\>\<root-ca.pem\>

---

<div class="post-metadata">

**Author:** ![Sheik\_Syed\_Ali](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Sheik\_Syed\_Ali](https://forum.search-guard.com/u/Sheik_Syed_Ali)\
**Post date:** [June 13, 2018, 9:56am UTC](https://forum.search-guard.com/t/search-guard-not-initialized-sg11-see-https-github-com-floragunncom-search-guard-docs-blob-mast/948/3 "2018-06-13T09:56:15Z")

</div>

Thanks for your quick reply. It works now.

> **···**
>
> On Wed, Jun 13, 2018 at 2:56 PM, SG [info@search-guard.com](mailto:info@search-guard.com) wrote:
> 
> > > Am 13.06.2018 um 10:52 schrieb [sheik.syedali@searchblox.com](mailto:sheik.syedali@searchblox.com):
> > 
> > > 
> > 
> > > Hi,
> > 
> > > ```
> > > • Search Guard (5.6.4-18) and Elasticsearch (5.6.4)
> > > 
> > > ```
> > 
> > > ```
> > > • Using Search guard community edition
> > > 
> > > ```
> > 
> > > ```
> > > • Oracle JVM 1.8.0
> > > 
> > > ```
> > 
> > > ```
> > > • No Kibana and other plugins
> > > 
> > > ```
> > 
> > > I m generating the certificates using offline Search Guard tools which are provided by Search Guard. Please find the below information used for generating certificates.
> > 
> > > 
> > 
> > > ca:
> > 
> > > root:
> > 
> > > ```
> > > dn: CN=[root.ca.searchblox.com](http://root.ca.searchblox.com),OU=CA,O=SearchBlox Com\, Inc.,DC=searchblox,DC=com
> > > 
> > > ```
> > 
> > > ```
> > > keysize: 2048
> > > 
> > > ```
> > 
> > > ```
> > > validityDays: 3650
> > > 
> > > ```
> > 
> > > ```
> > > pkPassword: auto
> > > 
> > > ```
> > 
> > > ```
> > > file: root-ca.pem
> > > 
> > > ```
> > 
> > > nodes:
> > 
> > > - name: searchblox-node-1
> > 
> > > ```
> > > dn: CN=[root.ca.searchblox.com](http://root.ca.searchblox.com),OU=CA,O=SearchBlox Com\, Inc.,DC=searchblox,DC=com
> > > 
> > > ```
> > 
> > > clients:
> > 
> > > - name: sheik
> > 
> > > ```
> > > dn: CN=[sheik.example.com](http://sheik.example.com),OU=Ops,O=Sheik Com\, Inc.,DC=example,DC=com
> > > 
> > > ```
> > 
> > > - name: kirk
> > 
> > > ```
> > > dn: CN=[kirk.example.com](http://kirk.example.com),OU=Ops,O=Example Com\, Inc.,DC=example,DC=com
> > > 
> > > ```
> > 
> > > ```
> > > admin: true
> > > 
> > > ```
> > 
> > > 
> > 
> > > Herewith I have attached the generated certificates which are generated by Search Guard Tools.
> > 
> > > 
> > 
> > > 
> > 
> > > Find the elasticsearch.yml config below
> > 
> > > 
> > 
> > > [cluster.name](http://cluster.name): searchblox
> > 
> > > [node.name](http://node.name): searchblox-node-1
> > 
> > > indices.fielddata.cache.size: 40%
> > 
> > > http.enabled: true
> > 
> > > elasticfence.disabled: false
> > 
> > > elasticfence.root.password: searchblox
> > 
> > > index.refresh\_interval: 4s
> > 
> > > ######## Start Search Guard Demo Configuration ########
> > 
> > > searchguard.ssl.transport.pemcert\_filepath: searchblox-node-1.pem
> > 
> > > searchguard.ssl.transport.pemkey\_filepath: searchblox-node-1.key
> > 
> > > searchguard.ssl.transport.pemtrustedcas\_filepath: root-ca.pem
> > 
> > > searchguard.ssl.transport.enforce\_hostname\_verification: false
> > 
> > > searchguard.ssl.http.enabled: true
> > 
> > > searchguard.ssl.http.pemcert\_filepath: searchblox-node-1.pem
> > 
> > > searchguard.ssl.http.pemkey\_filepath: searchblox-node-1.key
> > 
> > > searchguard.ssl.http.pemtrustedcas\_filepath: root-ca.pem
> > 
> > > searchguard.authcz.admin\_dn:
> > 
> > > - CN=kirk,OU=client,O=client,L=test, C=de
> > 
> > > searchguard.nodes\_dn:
> > 
> > > - ‘CN=[root.ca.searchblox.com](http://root.ca.searchblox.com),OU=CA,O=SearchBlox Com, Inc.,DC=searchblox,DC=com’
> > 
> > > ######## End Search Guard Demo Configuration ########
> > 
> > > 
> > 
> > > After the above configuration, I started the product I tried to approach the [https://localhost:9200/\_cat/indices](https://localhost:9200/_cat/indices) url. I got the “Search Guard not initialized (SG11). See [https://github.com/floragunncom/search-guard-docs/blob/master/sgadmin.md](https://github.com/floragunncom/search-guard-docs/blob/master/sgadmin.md)” the message
> > 
> > > 
> > 
> > > I tried to initiate Search Guard using sgadmin script, I received the below error.
> > 
> > > 
> > 
> > > Command: sh sgadmin.sh -cd …/sgconfig -key …/…/kirk.key -cert …/…/kirk.pem -cacert …/…/root-ca.pem -icl -nhnv --diagnose --accept-red-cluster -ff
> > 
> > > 
> > 
> > > 
> > 
> > > Error message:
> > 
> > > WARNING: JAVA\_HOME not set, will use /usr/bin/java
> > 
> > > Search Guard Admin v5
> > 
> > > Will connect to localhost:9300 … done
> > 
> > > 1256 [main] INFO c.f.s.SearchGuardPlugin - Clustername: elasticsearch
> > 
> > > ### LICENSE NOTICE Search Guard
> > 
> > > If you use one or more of the following features in production
> > 
> > > make sure you have a valid Search Guard license
> > 
> > > (See [https://floragunn.com/searchguard-validate-license](https://floragunn.com/searchguard-validate-license))
> > 
> > > - Kibana Multitenancy
> > 
> > > - LDAP authentication/authorization
> > 
> > > - Active Directory authentication/authorization
> > 
> > > - REST Management API
> > 
> > > - JSON Web Token (JWT) authentication/authorization
> > 
> > > - Kerberos authentication/authorization
> > 
> > > - Document- and Fieldlevel Security (DLS/FLS)
> > 
> > > - Auditlogging
> > 
> > > In case of any doubt mail to [sales@floragunn.com](mailto:sales@floragunn.com)
> > 
> > > ###################################
> > 
> > > 1284 [main] INFO c.f.s.SearchGuardPlugin - Node [_client_] is a transportClient: true/tribeNode: false/tribeNodeClient: false
> > 
> > > 1285 [main] INFO c.f.s.SearchGuardPlugin - FLS/DLS module not available
> > 
> > > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - Open SSL not available (this is not an error, we simply fallback to built-in JDK SSL) because of java.lang.ClassNotFoundException: io.netty.internal.tcnative.SSL
> > 
> > > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.version: 1.8.0\_151
> > 
> > > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vendor: Oracle Corporation
> > 
> > > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.specification.version: 1.8
> > 
> > > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.specification.vendor: Oracle Corporation
> > 
> > > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - [java.vm.specification.name](http://java.vm.specification.name): Java Virtual Machine Specification
> > 
> > > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - [java.vm.name](http://java.vm.name): Java HotSpot™ 64-Bit Server VM
> > 
> > > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.vm.vendor: Oracle Corporation
> > 
> > > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.specification.version: 1.8
> > 
> > > 1317 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - java.specification.vendor: Oracle Corporation
> > 
> > > 1318 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - [java.specification.name](http://java.specification.name): Java Platform API Specification
> > 
> > > 1318 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - [os.name](http://os.name): Mac OS X
> > 
> > > 1318 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - os.arch: x86\_64
> > 
> > > 1318 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - os.version: 10.13.2
> > 
> > > 1463 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - JVM supports the following 57 ciphers for https [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDH\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDH\_ECDSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDH\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DHE\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DHE\_DSS\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_EMPTY\_RENEGOTIATION\_INFO\_SCSV, TLS\_DH\_anon\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DH\_anon\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_anon\_WITH\_AES\_128\_CBC\_SHA, TLS\_DH\_anon\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_anon\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DH\_anon\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_RSA\_WITH\_DES\_CBC\_SHA, SSL\_DHE\_RSA\_WITH\_DES\_CBC\_SHA, SSL\_DHE\_DSS\_WITH\_DES\_CBC\_SHA, SSL\_DH\_anon\_WITH\_DES\_CBC\_SHA, SSL\_RSA\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DHE\_RSA\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DHE\_DSS\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DH\_anon\_EXPORT\_WITH\_DES40\_CBC\_SHA, TLS\_RSA\_WITH\_NULL\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_NULL\_SHA, TLS\_ECDHE\_RSA\_WITH\_NULL\_SHA, SSL\_RSA\_WITH\_NULL\_SHA, TLS\_ECDH\_ECDSA\_WITH\_NULL\_SHA, TLS\_ECDH\_RSA\_WITH\_NULL\_SHA, TLS\_ECDH\_anon\_WITH\_NULL\_SHA, SSL\_RSA\_WITH\_NULL\_MD5, TLS\_KRB5\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_KRB5\_WITH\_3DES\_EDE\_CBC\_MD5, TLS\_KRB5\_WITH\_DES\_CBC\_SHA, TLS\_KRB5\_WITH\_DES\_CBC\_MD5, TLS\_KRB5\_EXPORT\_WITH\_DES\_CBC\_40\_SHA, TLS\_KRB5\_EXPORT\_WITH\_DES\_CBC\_40\_MD5]
> > 
> > > 1466 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - JVM supports the following 57 ciphers for transport [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDH\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDH\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDH\_ECDSA\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_ECDH\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DHE\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DHE\_DSS\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_EMPTY\_RENEGOTIATION\_INFO\_SCSV, TLS\_DH\_anon\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DH\_anon\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDH\_anon\_WITH\_AES\_128\_CBC\_SHA, TLS\_DH\_anon\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDH\_anon\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_DH\_anon\_WITH\_3DES\_EDE\_CBC\_SHA, SSL\_RSA\_WITH\_DES\_CBC\_SHA, SSL\_DHE\_RSA\_WITH\_DES\_CBC\_SHA, SSL\_DHE\_DSS\_WITH\_DES\_CBC\_SHA, SSL\_DH\_anon\_WITH\_DES\_CBC\_SHA, SSL\_RSA\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DHE\_RSA\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DHE\_DSS\_EXPORT\_WITH\_DES40\_CBC\_SHA, SSL\_DH\_anon\_EXPORT\_WITH\_DES40\_CBC\_SHA, TLS\_RSA\_WITH\_NULL\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_NULL\_SHA, TLS\_ECDHE\_RSA\_WITH\_NULL\_SHA, SSL\_RSA\_WITH\_NULL\_SHA, TLS\_ECDH\_ECDSA\_WITH\_NULL\_SHA, TLS\_ECDH\_RSA\_WITH\_NULL\_SHA, TLS\_ECDH\_anon\_WITH\_NULL\_SHA, SSL\_RSA\_WITH\_NULL\_MD5, TLS\_KRB5\_WITH\_3DES\_EDE\_CBC\_SHA, TLS\_KRB5\_WITH\_3DES\_EDE\_CBC\_MD5, TLS\_KRB5\_WITH\_DES\_CBC\_SHA, TLS\_KRB5\_WITH\_DES\_CBC\_MD5, TLS\_KRB5\_EXPORT\_WITH\_DES\_CBC\_40\_SHA, TLS\_KRB5\_EXPORT\_WITH\_DES\_CBC\_40\_MD5]
> > 
> > > 1467 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - Config directory is /Users/sheik/SearchBloxDev/gitsourcce/build/libs/exploded/searchblox-9.0.war/WEB-INF/lib/tools/, from there the key- and truststore files are resolved relatively
> > 
> > > 1587 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - AES-256 not supported, max key length for AES is 128 bit… That is not an issue, it just limits possible encryption strength. To enable AES 256 install ‘Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files’
> > 
> > > 1587 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslTransportClientProvider:JDK with ciphers [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256]
> > 
> > > 1587 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslTransportServerProvider:JDK with ciphers [TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_CBC\_SHA256, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA, TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256, TLS\_DHE\_DSS\_WITH\_AES\_128\_GCM\_SHA256]
> > 
> > > 1587 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslHTTPProvider:null with ciphers
> > 
> > > 1588 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslTransport protocols [TLSv1.2, TLSv1.1]
> > 
> > > 1588 [main] INFO c.f.s.s.DefaultSearchGuardKeyStore - sslHTTP protocols [TLSv1.2, TLSv1.1]
> > 
> > > 1589 [main] INFO o.e.p.PluginsService - no modules loaded
> > 
> > > 1590 [main] INFO o.e.p.PluginsService - loaded plugin [com.floragunn.searchguard.SearchGuardPlugin]
> > 
> > > 1591 [main] INFO o.e.p.PluginsService - loaded plugin [org.elasticsearch.transport.Netty4Plugin]
> > 
> > > 3166 [main] INFO o.e.c.t.TransportClientNodesService - failed to get node info for {#transport#-1}{uCZ8UuIqQXWIujCL59Fw8w}{localhost}{[127.0.0.1:9300](http://127.0.0.1:9300)}, disconnecting…
> > 
> > > org.elasticsearch.transport.RemoteTransportException: [searchblox-node-1][[127.0.0.1](http://127.0.0.1):9300][cluster:monitor/nodes/liveness]
> > 
> > > Caused by: org.elasticsearch.ElasticsearchSecurityException: Cannot authenticate null
> > 
> > > ```
> > > at com.floragunn.searchguard.transport.SearchGuardRequestHandler.messageReceivedDecorate(SearchGuardRequestHandler.java:176) ~[search-guard-5-5.6.4-18.jar:?]
> > > 
> > > ```
> > 
> > > ```
> > > at com.floragunn.searchguard.ssl.transport.SearchGuardSSLRequestHandler.messageReceived(SearchGuardSSLRequestHandler.java:140) ~[search-guard-ssl-5.6.4-23.jar:5.6.4-23]
> > > 
> > > ```
> > 
> > > ```
> > > at com.floragunn.searchguard.SearchGuardPlugin$4$1.messageReceived(SearchGuardPlugin.java:423) ~[search-guard-5-5.6.4-18.jar:?]
> > > 
> > > ```
> > 
> > > ```
> > > at org.elasticsearch.transport.RequestHandlerRegistry.processMessageReceived(RequestHandlerRegistry.java:69) ~[elasticsearch-5.6.4.jar:5.6.4]
> > > 
> > > ```
> > 
> > > ```
> > > at org.elasticsearch.transport.TcpTransport$RequestHandler.doRun(TcpTransport.java:1553) ~[elasticsearch-5.6.4.jar:5.6.4]
> > > 
> > > ```
> > 
> > > ```
> > > at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) ~[elasticsearch-5.6.4.jar:5.6.4]
> > > 
> > > ```
> > 
> > > ```
> > > at org.elasticsearch.common.util.concurrent.EsExecutors$1.execute(EsExecutors.java:110) ~[elasticsearch-5.6.4.jar:5.6.4]
> > > 
> > > ```
> > 
> > > ```
> > > at org.elasticsearch.transport.TcpTransport.handleRequest(TcpTransport.java:1510) ~[elasticsearch-5.6.4.jar:5.6.4]
> > > 
> > > ```
> > 
> > > ```
> > > at org.elasticsearch.transport.TcpTransport.messageReceived(TcpTransport.java:1393) ~[elasticsearch-5.6.4.jar:5.6.4]
> > > 
> > > ```
> > 
> > > ```
> > > at org.elasticsearch.transport.netty4.Netty4MessageChannelHandler.channelRead(Netty4MessageChannelHandler.java:74) ~[transport-netty4-client-5.6.4.jar:5.6.4]
> > > 
> > > ```
> > 
> > > ```
> > > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]
> > > 
> > > ```
> > 
> > > ```
> > > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]
> > > 
> > > ```
> > 
> > > ```
> > > at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]
> > > 
> > > ```
> > 
> > > ```
> > > at io.netty.handler.codec.ByteToMessageDecoder.fireChannelRead(ByteToMessageDecoder.java:310) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]
> > > 
> > > ```
> > 
> > > ```
> > > at io.netty.handler.codec.ByteToMessageDecoder.fireChannelRead(ByteToMessageDecoder.java:297) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]
> > > 
> > > ```
> > 
> > > ```
> > > at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:413) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]
> > > 
> > > ```
> > 
> > > ```
> > > at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:265) ~[netty-codec-4.1.13.Final.jar:4.1.13.Final]
> > > 
> > > ```
> > 
> > > ```
> > > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]
> > > 
> > > ```
> > 
> > > ```
> > > at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]
> > > 
> > > ```
> > 
> > > ```
> > > at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]
> > > 
> > > ```
> > 
> > > ```
> > > at io.netty.channel.ChannelInboundHandlerAdapter.channelRead(ChannelInboundHandlerAdapter.java:86) ~[netty-transport-4.1.13.Final.jar:4.1.13.Final]
> > > 
> > > ```
> 
> > Seems your elasticsearch.yml is not correct, should look like
> > 
> > searchguard.nodes\_dn:
> > 
> > - ‘CN=[root.ca.searchblox.com](http://root.ca.searchblox.com),OU=CA,O=SearchBlox Com, Inc.,DC=searchblox,DC=com’
> > 
> > searchguard.authcz.admin\_dn:
> > 
> > - ‘CN=[kirk.example.com](http://kirk.example.com),OU=Ops,O=Example Com, Inc.,DC=example,DC=com’
> > 
> > The entry:
> > 
> > > searchguard.authcz.admin\_dn:
> > 
> > > - CN=kirk,OU=client,O=client,L=test, C=de
> > 
> > seems to be a leftover from the demo installation?
