# About certgen, csr, and wildcard certificates

**URL:** <https://discuss.elastic.co/t/about-certgen-csr-and-wildcard-certificates/100380>\
**Category:** Elasticsearch\
**Created:** [September 13, 2017, 3:52pm UTC](https://discuss.elastic.co/t/about-certgen-csr-and-wildcard-certificates/100380 "2017-09-13T15:52:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cornoualis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cornoualis/32/23246_2.png) [@Cornoualis](https://discuss.elastic.co/u/Cornoualis)\
**Post date:** [September 13, 2017, 3:52pm UTC](https://discuss.elastic.co/t/about-certgen-csr-and-wildcard-certificates/100380/1 "2017-09-13T15:52:58Z")

</div>

Hi,

I'm desperately trying to enable TLS on my cluster (I want the node to use TLS for transport communication, for API access, and https for kibana).

My cluster is composed of 9 nodes, but may evolve in the future so I would like to have a wildcard certificate to use the same key/cert on every (future) member of the cluster.

I created **DNS aliases** for every member of my cluster as so:  
`nodename.mycluster.mycompany`

Some examples:  
`master1.mycluster.mycompany`  
`data2.mycluster.mycompany`  
`...`

Again, the idea is to allow my cluster to evolve without having to ask for new certificates every time.

In "short"...I want to have ONE certificate for \*.myscluster.mycompany  
I cannot use a wildcard based on the hostname since every servers use the same naming convention and using a wildcard at this level would allow far too many machine to use the cert/key.

In the [documentation](https://www.elastic.co/guide/en/x-pack/current/ssl-tls.html), I didn't find anything about it, and I tried different arguments for "certgen -csr"...but in the end it never worked.

What arguments should I use to get a proper certificate?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Cornoualis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cornoualis/32/23246_2.png) [@Cornoualis](https://discuss.elastic.co/u/Cornoualis)\
**Post date:** [September 14, 2017, 12:48pm UTC](https://discuss.elastic.co/t/about-certgen-csr-and-wildcard-certificates/100380/2 "2017-09-14T12:48:11Z")

</div>

I found the solution!

Instance name: \*.mycluster.mycompany  
Ip: N/A  
DNS name: \*.mycluster.mycompany

The only problem remaining was the "Extended  
Key Usage" field that is kept blank by certgen...by default, my PKI fill this field with "Server Authentication"...which prevented the certificate to work properly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 12, 2017, 12:48pm UTC](https://discuss.elastic.co/t/about-certgen-csr-and-wildcard-certificates/100380/3 "2017-10-12T12:48:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
