# A Question for Configure SSL/TLS for self-managed Fleet Servers

**URL:** <https://discuss.elastic.co/t/a-question-for-configure-ssl-tls-for-self-managed-fleet-servers/303218>\
**Category:** Elasticsearch\
**Tags:** fleet, elastic-agent\
**Created:** [April 26, 2022, 6:29am UTC](https://discuss.elastic.co/t/a-question-for-configure-ssl-tls-for-self-managed-fleet-servers/303218 "2022-04-26T06:29:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![quhang](https://avatars.discourse-cdn.com/v4/letter/q/5daacb/32.png) [@quhang](https://discuss.elastic.co/u/quhang)\
**Post date:** [April 26, 2022, 6:29am UTC](https://discuss.elastic.co/t/a-question-for-configure-ssl-tls-for-self-managed-fleet-servers/303218/1 "2022-04-26T06:29:47Z")

</div>

Hello there,  
When try to configure SSL for the fleet and Join an elc cluster that currently has enabled https refer this article:

> **[Configure SSL/TLS for self-managed Fleet Servers | Fleet and Elastic Agent...](https://www.elastic.co/guide/en/fleet/master/secure-connections.html)**

In this document, the **Elasticsearch-ca.crt** confuses me, according the description, it should be the ca of my elastic stack, so I export the ca from the p12 file by this command:

openssl pkcs12 -in elastic-certificates.p12 -cacerts -nokeys -chain -out elastic-stack-ca.crt

is there anything wrong with my understanding or operation here?

When I continue following the documentation performing the install operation,  
./elastic-agent install -f   
--url=https://10.x.x.x:8220   
--fleet-server-es=https://pctcs009.elktst.net:9200   
--fleet-server-service-token=AAEAAWVsYXN0aWMvZmxlZXQtc2VydmVyL3Rva2VuLTE2NTA1MDcxMzkyMzU6d2hLX3R5RFQ   
--fleet-server-policy=a2013870-ab38-11ec-a6e9-03c37ca20fdb   
--fleet-server-es-ca=/usr/share/elastic-agent-8.1.1-linux-x86\_64/elastic-certificates.p12   
--certificate-authorities=/usr/share/elastic-agent-8.1.1-linux-x86\_64/ca.crt   
--fleet-server-cert=/usr/share/elastic-agent-8.1.1-linux-x86\_64/tctst001.crt   
--fleet-server-cert-key=/usr/share/elastic-agent-8.1.1-linux-x86\_64/tctst001.key

I get this error message:  
**fleet-server--8.1.1[]: State changed to FAILED: Error - x509: certificate is not valid for any names, but wanted to match pctcs009**

Can anyone help to point out my mistake?

My environment information:

Elasticsearch version is 8.1.1  
agent: elastic-agent-8.1.1-linux-x86\_64.tar.gz

./bin/Elasticsearch-certutil ca  
./bin/Elasticsearch-certutil cert --ca elastic-stack-ca.p12

Elasticsearch.yml  
xpack.security.enabled: true  
xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12  
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

xpack.security.http.ssl.enabled: true  
xpack.security.http.ssl.keystore.path: elastic-certificates.p12  
xpack.security.http.ssl.truststore.path: elastic-certificates.p12  
xpack.security.http.ssl.client\_authentication: optional

very appreciate if someone can help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2022, 6:30am UTC](https://discuss.elastic.co/t/a-question-for-configure-ssl-tls-for-self-managed-fleet-servers/303218/2 "2022-05-24T06:30:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
