Cant get cluster up with security enabled

Centos 7
Opensearch TGZ installation

Cant get cluster up and running if security enabled. Cluster start to successfully communicate when i switch security off.

the one and only error in logs which may be the root of problem is this on both nodes

WARNING: An illegal reflective access operation has occurred
WARNING: Illegal reflective access by$DescriptorNameSetter (file:/home/opensearch/opensearch-1.0.0/plugins/opensearch-security/opensearch-security- to field
WARNING: Please consider reporting this to the maintainers of$DescriptorNameSetter
WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations
WARNING: All illegal access operations will be denied in a future release

configs is like elk-m DB1
http.port: 8200
transport.port: 8300
discovery.seed_hosts: ["",""]
cluster.initial_master_nodes: ["DB1", "DB2"] node.pem node-key.pem root-ca.pem false true node.pem node-key.pem root-ca.pem false true
  - "CN=admin,OU=DIT,O=org,L=Moscow,ST=Moscow,C=RU"
  - 'CN=NODE1,OU=DIT,O=org,L=Moscow,ST=Moscow,C=RU'
  - 'CN=NODE2,OU=DIT,O=org,L=Moscow,ST=Moscow,C=RU' internal_opensearch true true ["all_access", "security_rest_api_access"] true [".opendistro-alerting-config", ".opendistro-alerting-alert*", ".opendistro-anomaly-results*", ".opendistro-anomaly-detector*", ".opendistro-anomaly-checkpoints", ".opendistro-anomaly-detection-state", ".opendistro-reports-*", ".opendistro-notifications-*", ".opendistro-notebooks", ".opendistro-asynchronous-search-response*"]
node.max_local_storage_nodes: 3

the communication on tcp:8300 is successfull(TLS at least)

Same time on classic ports i have elk up and running as a charm.

Can someone help me understand how to debug this behaviour?