# Unable to access opensearch dashboard post install - Getting ConnectionError in logs

**URL:** <https://forum.opensearch.org/t/unable-to-access-opensearch-dashboard-post-install-getting-connectionerror-in-logs/21675>\
**Category:** OpenSearch Dashboards\
**Tags:** install, security-issue\
**Created:** [September 27, 2024, 11:01am UTC](https://forum.opensearch.org/t/unable-to-access-opensearch-dashboard-post-install-getting-connectionerror-in-logs/21675 "2024-09-27T11:01:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sathis](https://avatars.discourse-cdn.com/v4/letter/s/34f0e0/32.png) [@sathis](https://forum.opensearch.org/u/sathis)\
**Post date:** [September 27, 2024, 11:01am UTC](https://forum.opensearch.org/t/unable-to-access-opensearch-dashboard-post-install-getting-connectionerror-in-logs/21675/1 "2024-09-27T11:01:47Z")

</div>

**Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):

opensearch-dashboards/stable,now 2.17.0 amd64 [installed]  
opensearch/stable,now 2.17.0 amd64 [installed]

**Describe the issue** :  
Unable to access the opensearch dashboard URL  
Getting an error on the browser `OpenSearch Dashboards server is not ready yet`

**Configuration** :

server:Ubuntu 20.04.6 LTS with 2TB mem and 50 Cpus. Trying to run single node cluster.Installed via APT.

root@logger:/var/log/opensearch-dashboards# cat /etc/opensearch-  
dashboards/opensearch\_dashboards.yml | grep -v “#” | grep -v ^$

```auto
server.port: 5601
server.host: "10.196.141.81"
opensearch.hosts: [https://192.100.141.81:9200]
opensearch.ssl.verificationMode: none
opensearch.username: admin
opensearch.password: Admin!123
opensearch.requestHeadersWhitelist: [authorization, securitytenant]
opensearch_security.multitenancy.enabled: true
opensearch_security.multitenancy.tenants.preferred: [Private, Global]
opensearch_security.readonly_mode.roles: [kibana_read_only]
opensearch_security.cookie.secure: false

```

* * *

root@logger:/var/log/opensearch-dashboards# cat /etc/opensearch/opensearch.yml | grep -v “#” | grep -v ^$

```auto
cluster.name: my-application
node.name: node-1
path.data: /var/lib/opensearch
path.logs: /var/log/opensearch
network.host: 0.0.0.0
discovery.type: single-node
plugins.security.ssl.transport.pemcert_filepath: esnode.pem
plugins.security.ssl.transport.pemkey_filepath: esnode-key.pem
plugins.security.ssl.transport.pemtrustedcas_filepath: root-ca.pem
plugins.security.ssl.transport.enforce_hostname_verification: false
plugins.security.ssl.http.enabled: true
plugins.security.ssl.http.pemcert_filepath: esnode.pem
plugins.security.ssl.http.pemkey_filepath: esnode-key.pem
plugins.security.ssl.http.pemtrustedcas_filepath: root-ca.pem
plugins.security.allow_unsafe_democertificates: true
plugins.security.allow_default_init_securityindex: true
plugins.security.authcz.admin_dn: ['CN=kirk,OU=client,O=client,L=test,C=de']
plugins.security.audit.type: internal_opensearch
plugins.security.enable_snapshot_restore_privilege: true
plugins.security.check_snapshot_restore_write_privileges: true
plugins.security.restapi.roles_enabled: [all_access, security_rest_api_access]
plugins.security.system_indices.enabled: true
plugins.security.system_indices.indices: [.plugins-ml-agent, .plugins-ml-config, .plugins-ml-connector,
  .plugins-ml-controller, .plugins-ml-model-group, .plugins-ml-model, .plugins-ml-task,
  .plugins-ml-conversation-meta, .plugins-ml-conversation-interactions, .plugins-ml-memory-meta,
  .plugins-ml-memory-message, .plugins-ml-stop-words, .opendistro-alerting-config,
  .opendistro-alerting-alert*, .opendistro-anomaly-results*, .opendistro-anomaly-detector*,
  .opendistro-anomaly-checkpoints, .opendistro-anomaly-detection-state, .opendistro-reports-*,
  .opensearch-notifications-*, .opensearch-notebooks, .opensearch-observability, .ql-datasources,
  .opendistro-asynchronous-search-response*, .replication-metadata-store, .opensearch-knn-models,
  .geospatial-ip2geo-data*, .plugins-flow-framework-config, .plugins-flow-framework-templates,
  .plugins-flow-framework-state]
node.max_local_storage_nodes: 3

```

* * *

**Relevant Logs or Screenshots** :

```auto
root@logger:~# curl -X GET https://localhost:9200 -u 'admin:Admin!123' --insecure --verbose
Note: Unnecessary use of -X or --request, GET is already inferred.
* Trying ::1:9200...
* TCP_NODELAY set
* Connected to localhost (::1) port 9200 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
* CAfile: /etc/ssl/certs/ca-certificates.crt
  CApath: /etc/ssl/certs
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* error:1408F10B:SSL routines:ssl3_get_record:wrong version number
* Closing connection 0
curl: (35) error:1408F10B:SSL routines:ssl3_get_record:wrong version number
root@logger:~# 

```

* * *

```auto
Sep 27 16:02:58 logger opensearch-dashboards[2832587]: {"type":"log","@timestamp":"2024-09-27T10:32:58Z","tags":["error","opensearch","data"],"pid":2832587,"message":"[ConnectionError]: write EPROTO 00C83585A57F0000:error:0A00010B:SSL routines:ssl3_get_record:wrong version number:../deps/openssl/openssl/ssl/record/ssl3_record.c:355:\n"}
Sep 27 16:03:00 logger opensearch-dashboards[2832587]: {"type":"log","@timestamp":"2024-09-27T10:33:00Z","tags":["error","opensearch","data"],"pid":2832587,"message":"[ConnectionError]: write EPROTO 00C83585A57F0000:error:0A00010B:SSL routines:ssl3_get_record:wrong version number:../deps/openssl/openssl/ssl/record/ssl3_record.c:355:\n"}
Sep 27 16:03:03 logger opensearch-dashboards[2832587]: {"type":"log","@timestamp":"2024-09-27T10:33:03Z","tags":["error","opensearch","data"],"pid":2832587,"message":"[ConnectionError]: write EPROTO 00C83585A57F0000:error:0A00010B:SSL routines:ssl3_get_record:wrong version number:../deps/openssl/openssl/ssl/record/ssl3_record.c:355:\n"}

```

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [September 27, 2024, 1:35pm UTC](https://forum.opensearch.org/t/unable-to-access-opensearch-dashboard-post-install-getting-connectionerror-in-logs/21675/2 "2024-09-27T13:35:52Z")

</div>

@sathis How did you deploy your cluster?

---

<div class="post-metadata">

**Author:** ![sathis](https://avatars.discourse-cdn.com/v4/letter/s/34f0e0/32.png) [@sathis](https://forum.opensearch.org/u/sathis)\
**Post date:** [September 30, 2024, 6:14am UTC](https://forum.opensearch.org/t/unable-to-access-opensearch-dashboard-post-install-getting-connectionerror-in-logs/21675/3 "2024-09-30T06:14:36Z")

</div>

Thanks for looking into this pablo.  
I followed this steps provided in this link `https://opensearch.org/docs/latest/install-and-configure/install-opensearch/debian/#install-opensearch-from-an-apt-repository`

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [September 30, 2024, 9:00pm UTC](https://forum.opensearch.org/t/unable-to-access-opensearch-dashboard-post-install-getting-connectionerror-in-logs/21675/4 "2024-09-30T21:00:42Z")

</div>

@sathis At this point I think this should work from the curl level.

```auto
curl http://localhost:9200

```

This procedure doesn’t mention security plugin init. You’ll need to run securityadmin.sh once the cluster is up and running.  
Also for OpenSearch Dashboards the good practice is using `kibanaserver` user instead of `admin`. You shouldn’t expose admin’s passwords in any config file.  
Password of `kibanaserver` user is `kibanaserver`.

> **[Applying changes to configuration files](https://opensearch.org/docs/latest/security/configuration/security-admin/)**
>
> Applying changes to configuration files
