# Unable to apply SSL certificate

**URL:** <https://forum.opensearch.org/t/unable-to-apply-ssl-certificate/20387>\
**Category:** Security\
**Created:** [July 19, 2024, 7:37am UTC](https://forum.opensearch.org/t/unable-to-apply-ssl-certificate/20387 "2024-07-19T07:37:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![opensearch1](https://avatars.discourse-cdn.com/v4/letter/o/a87d85/32.png) [@opensearch1](https://forum.opensearch.org/u/opensearch1)\
**Post date:** [July 19, 2024, 7:37am UTC](https://forum.opensearch.org/t/unable-to-apply-ssl-certificate/20387/1 "2024-07-19T07:37:51Z")

</div>

**Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):  
2.11.1

**Describe the issue** :  
I have created selef signed admin and root ca certificate to configure opensearch ssl.  
I updated opensearch-cluster-master-config with below plugins configuration for opensearch.yml

```auto
apiVersion: v1
data:
  opensearch.yml: |
    cluster.name: opensearch-cluster
    network.host: 0.0.0.0

     19 plugins:
 20 security:
 21 ssl:
 22 transport:
 23 pemcert_filepath: esnode.pem
 24 pemkey_filepath: esnode-key.pem
 25 pemtrustedcas_filepath: root-ca.pem
 26 enforce_hostname_verification: false
 27 http:
 28 enabled: true
 29 pemcert_filepath: admin.pem
 30 pemkey_filepath: admin-key.pem
 31 pemtrustedcas_filepath: root-ca.pem
 32 allow_unsafe_democertificates: true
 33 allow_default_init_securityindex: true

```

However this is not picked up by opensearch.  
What I found out there is duplicate configuration which is also getting added below my configmap configurations in opensearch.yml  
below

```auto
######## Start OpenSearch Security Demo Configuration ########
# WARNING: revise all the lines below before you go into production
plugins.security.ssl.transport.pemcert_filepath: esnode.pem
plugins.security.ssl.transport.pemkey_filepath: esnode-key.pem
plugins.security.ssl.transport.pemtrustedcas_filepath: root-ca.pem
plugins.security.ssl.transport.enforce_hostname_verification: false
plugins.security.ssl.http.enabled: true
plugins.security.ssl.http.pemcert_filepath: esnode.pem
plugins.security.ssl.http.pemkey_filepath: esnode-key.pem
plugins.security.ssl.http.pemtrustedcas_filepath: root-ca.pem
plugins.security.allow_unsafe_democertificates: true
plugins.security.allow_default_init_securityindex: true
plugins.security.authcz.admin_dn:
  - CN=kirk,OU=client,O=client,L=test, C=de

plugins.security.audit.type: internal_opensearch
plugins.security.enable_snapshot_restore_privilege: true
plugins.security.check_snapshot_restore_write_privileges: true
plugins.security.restapi.roles_enabled: ["all_access", "security_rest_api_access"]
plugins.security.system_indices.enabled: true
plugins.security.system_indices.indices: [".plugins-ml-config", ".plugins-ml-connector", ".plugins-ml-model-group", ".plugins-ml-model", ".plugins-ml-task", ".plugins-ml-conversation-meta", ".plugins-ml-conversation-interactions", ".opendistro-alerting-config", ".opendistro-alerting-alert*", ".opendistro-anomaly-results*", ".opendistro-anomaly-detector*", ".opendistro-anomaly-checkpoints", ".opendistro-anomaly-detection-state", ".opendistro-reports-*", ".opensearch-notifications-*", ".opensearch-notebooks", ".opensearch-observability", ".ql-datasources", ".opendistro-asynchronous-search-response*", ".replication-metadata-store", ".opensearch-knn-models", ".geospatial-ip2geo-data*"]
node.max_local_storage_nodes: 3
######## End OpenSearch Security Demo Configuration ########

```

Who is adding this duplicate configuration.

**Configuration** :  
Helm based kubectl installation

**Relevant Logs or Screenshots** :

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [July 19, 2024, 1:37pm UTC](https://forum.opensearch.org/t/unable-to-apply-ssl-certificate/20387/2 "2024-07-19T13:37:19Z")

</div>

@opensearch1 Did you use official OpenSearch helm charts?

---

<div class="post-metadata">

**Author:** ![opensearch1](https://avatars.discourse-cdn.com/v4/letter/o/a87d85/32.png) [@opensearch1](https://forum.opensearch.org/u/opensearch1)\
**Post date:** [July 19, 2024, 1:52pm UTC](https://forum.opensearch.org/t/unable-to-apply-ssl-certificate/20387/3 "2024-07-19T13:52:47Z")

</div>

Hi @pablo ,

Yes. I installed from official helm chart. I think accessing configMap is not viable solution here. I need to mount certificates, private keys and my custom opensearch.yml in opensearch-cluster-master pod. Docker based deployment working using this approach.

Using configMap is adding my custom plugin configurations to existing default opensearch.yml file. As default configurations are below confimap based configurations, default configs overwrites and hence my certificates never work.

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [July 19, 2024, 2:20pm UTC](https://forum.opensearch.org/t/unable-to-apply-ssl-certificate/20387/4 "2024-07-19T14:20:37Z")

</div>

@opensearch1 Helm charts are different than docker. You can mount certificates either through configmap or secret. For certificates you should use secret.

In this scenario both are used. Config map is used for opensearch.yml and secret for certificates.  
You can find both by running the following commands.

```auto
kubectl get secret -n <namespace>
kubectl get configmap -n <namespace>

```

I would recommend getting more familiar with Kubernetes as that will help you better navigate helm charts.

If you’d like to use custom certificates, you can use helm charts and define secrets with your certs.

> <https://github.com/opensearch-project/helm-charts/blob/a018f838ec44dd0b9337e0403a541580cc39c0f3/charts/opensearch/values.yaml#L123C1-L123C13>

Also you could replace certificates in the nodes cert secrets and then recreate OpenSearch pods.

---

<div class="post-metadata">

**Author:** ![opensearch1](https://avatars.discourse-cdn.com/v4/letter/o/a87d85/32.png) [@opensearch1](https://forum.opensearch.org/u/opensearch1)\
**Post date:** [July 23, 2024, 12:32pm UTC](https://forum.opensearch.org/t/unable-to-apply-ssl-certificate/20387/5 "2024-07-23T12:32:55Z")

</div>

Hi @pablo ,  
The problem was default opensearch demo configuration will always append to existing opensearch.yml no matter whether you provide opensearch.yml through helm or dont give.  
I had to stop it by passing DISABLE\_INSTALL\_DEMO\_CONFIG as true in helm values. Now only one set of cert configurations are there which are of yaml synax.

This causes another problem of configuring OPENSEARCH\_INITIAL\_ADMIN\_PASSWORD. With DISABLE\_INSTALL\_DEMO\_CONFIG as true, OPENSEARCH\_INITIAL\_ADMIN\_PASSWORD is always admin no matter what you give.

Any idea how that can be done.

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [July 23, 2024, 11:49pm UTC](https://forum.opensearch.org/t/unable-to-apply-ssl-certificate/20387/6 "2024-07-23T23:49:59Z")

</div>

@opensearch1 I’ve just deployed the cluster and I’ve also got duplicated configuration in opensearch.yml.

I’ve reported this as a bug in GitHub.

> <https://github.com/opensearch-project/helm-charts/issues/564>
>
> \*\*Describe the bug\*\*
> 
> Bug Fix for configMap Read-only file system error in sta…tefulset.yml creates duplicated security config in opensearch.yml
> 
> https://github.com/opensearch-project/helm-charts/commit/a1c5b8f301d68649f0534b63bf545a61844ce651#diff-08885706cd45ad445d2696cd7e39cf7d4b5e82cb51b0ee6bd86e6ee9f818e158
> 
> \*\*To Reproduce\*\*
> 
> Steps to reproduce the behaviour:
> 1. Deploy charts from the latest back to 2.11.1. 
> 2. OpenSearch nodes will get deployed but opensearch.yml will contain duplicated security config. 
> 3. The OpenSearch node will ignore the custom security config from values.yml (.Values.config.opensearch.yml) and will use a duplicated config as per the example. 
> 
> Example: 
> \`\`\`
> pablo@kube-1:~$ kubectl exec -it opensearch-cluster-master-0 -- cat config/opensearch.yml
> Defaulted container "opensearch" out of: opensearch, fsgroup-volume (init), configfile (init)
> cluster.name: opensearch-cluster
> 
> \# Bind to all interfaces because we don't know what IP address Docker will assign to us.
> network.host: 0.0.0.0
> 
> \# Setting network.host to a non-loopback address enables the annoying bootstrap checks. "Single-node" mode disables them again.
> \# Implicitly done if ".singleNode" is set to "true".
> \# discovery.type: single-node
> 
> \# Start OpenSearch Security Demo Configuration
> \# WARNING: revise all the lines below before you go into production
> plugins:
> security:
> ssl:
> transport:
> pemcert\_filepath: admin.pem
> pemkey\_filepath: admin-key.pem
> pemtrustedcas\_filepath: root-ca.pem
> enforce\_hostname\_verification: false
> http:
> enabled: true
> pemcert\_filepath: esnode.pem
> pemkey\_filepath: esnode-key.pem
> pemtrustedcas\_filepath: root-ca.pem
> allow\_unsafe\_democertificates: true
> allow\_default\_init\_securityindex: true
> authcz:
> admin\_dn:
> - CN=kirk,OU=client,O=client,L=test,C=de
> audit.type: internal\_opensearch
> enable\_snapshot\_restore\_privilege: true
> check\_snapshot\_restore\_write\_privileges: true
> restapi:
> roles\_enabled: \["all\_access", "security\_rest\_api\_access"\]
> system\_indices:
> enabled: true
> indices:
> \[
> ".opendistro-alerting-config",
> ".opendistro-alerting-alert\*",
> ".opendistro-anomaly-results\*",
> ".opendistro-anomaly-detector\*",
> ".opendistro-anomaly-checkpoints",
> ".opendistro-anomaly-detection-state",
> ".opendistro-reports-\*",
> ".opendistro-notifications-\*",
> ".opendistro-notebooks",
> ".opendistro-asynchronous-search-response\*",
> \]
> \######## End OpenSearch Security Demo Configuration ########
> 
> \######## Start OpenSearch Security Demo Configuration ########
> \# WARNING: revise all the lines below before you go into production
> plugins.security.ssl.transport.pemcert\_filepath: esnode.pem
> plugins.security.ssl.transport.pemkey\_filepath: esnode-key.pem
> plugins.security.ssl.transport.pemtrustedcas\_filepath: root-ca.pem
> plugins.security.ssl.transport.enforce\_hostname\_verification: false
> plugins.security.ssl.http.enabled: true
> plugins.security.ssl.http.pemcert\_filepath: esnode.pem
> plugins.security.ssl.http.pemkey\_filepath: esnode-key.pem
> plugins.security.ssl.http.pemtrustedcas\_filepath: root-ca.pem
> plugins.security.allow\_unsafe\_democertificates: true
> plugins.security.allow\_default\_init\_securityindex: true
> plugins.security.authcz.admin\_dn:
> - CN=kirk,OU=client,O=client,L=test, C=de
> 
> plugins.security.audit.type: internal\_opensearch
> plugins.security.enable\_snapshot\_restore\_privilege: true
> plugins.security.check\_snapshot\_restore\_write\_privileges: true
> plugins.security.restapi.roles\_enabled: \["all\_access", "security\_rest\_api\_access"\]
> plugins.security.system\_indices.enabled: true
> plugins.security.system\_indices.indices: \[".plugins-ml-config", ".plugins-ml-connector", ".plugins-ml-model-group", ".plugins-ml-model", ".plugins-ml-task", ".plugins-ml-conversation-meta", ".plugins-ml-conversation-interactions", ".opendistro-alerting-config", ".opendistro-alerting-alert\*", ".opendistro-anomaly-results\*", ".opendistro-anomaly-detector\*", ".opendistro-anomaly-checkpoints", ".opendistro-anomaly-detection-state", ".opendistro-reports-\*", ".opensearch-notifications-\*", ".opensearch-notebooks", ".opensearch-observability", ".ql-datasources", ".opendistro-asynchronous-search-response\*", ".replication-metadata-store", ".opensearch-knn-models", ".geospatial-ip2geo-data\*"\]
> node.max\_local\_storage\_nodes: 3
> \######## End OpenSearch Security Demo Configuration ########
> \`\`\`
> 
> \*\*Expected behavior\*\*
> opensearch.yml must contain only a single security configuration provided through values.yaml. 
> 
> \*\*Chart Name\*\*
> Specify the Chart which is affected?
> All charts from OpenSearch version 2.11.1 to the latest.

I’ll test the password issue.
