# Are the Self Signed Certs bound by IP / Hostname

**URL:** <https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147>\
**Category:** Elastic Security\
**Created:** [April 15, 2025, 12:20pm UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147 "2025-04-15T12:20:35Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Umang\_Pachaury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umang_pachaury/32/113523_2.png) [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Post date:** [April 15, 2025, 12:20pm UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/1 "2025-04-15T12:20:35Z")

</div>

Hi,  
We have a cluster in which we have enabled TLS security. To enable the security we used the elastic cert utility to generate the cert and CA. While generation of the certs or the CA any of the prompts did not ask us about the Hostnames or IP. We generated just one certificate and used that cert in all the nodes. Now the machines are moving to new IP and we are confused if the previous cert which is working now will work or not. Are the certs generated with elasticsearch cert-util are bound by IP/Hostname?  
Will there be any changes with respect to already generated passwords which were generated using elasticsearch-setup-passwords?  
Any update regarding this

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 15, 2025, 2:26pm UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/2 "2025-04-15T14:26:04Z")

</div>

What version are you on? (please always include that)

> [@Umang\_Pachaury](#):
>
> To enable the security we used the elastic cert utility to generate the cert and CA.

> [@Umang\_Pachaury](#):
>
> Are the certs generated with elasticsearch cert-util are bound by IP/Hostname?

Yes assuming you used the default process, it is not clear exactly how you created them but yes. You will need to create new certs.

You can create them again manually from the new hosts and / or use an `instances.yml`

> [@Umang\_Pachaury](#):
>
> Will there be any changes with respect to already generated passwords which were generated using elasticsearch-setup-passwords?

There should not be ... people rotate / apply new certs as part of normal maintenance, which does not change the Authentication.

---

<div class="post-metadata">

**Author:** ![Umang\_Pachaury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umang_pachaury/32/113523_2.png) [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Post date:** [April 16, 2025, 9:57am UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/3 "2025-04-16T09:57:43Z")

</div>

Thanks for the reply we are using elasticsearch version 8.15.1

We generated the certificates using the **elasticsearch-certutil** using the CA mode.  
Using that we generated single CA and single Certificate which we used in each and every node in our cluster and till now faced no issue. In the CA mode certificate generation it did not ask the IP or the DNS info for any machine.

> **[elasticsearch-certutil | Elastic Documentation](https://www.elastic.co/docs/reference/elasticsearch/command-line-tools/certutil#certutil-ca)**
>
> The elasticsearch-certutil command simplifies the creation of certificates for use with Transport Layer Security (TLS) in the Elastic Stack. You can specify...

---

<div class="post-metadata">

**Author:** ![Umang\_Pachaury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umang_pachaury/32/113523_2.png) [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Post date:** [April 16, 2025, 1:25pm UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/4 "2025-04-16T13:25:22Z")

</div>

> **[Set up transport TLS | Elastic documentation](https://www.elastic.co/docs/deploy-manage/security/set-up-basic-security)**
>
> Configuring TLS between nodes is the basic security setup to prevent unauthorized nodes from accessing to your Elasticsearch cluster, and it's required...

We have followed this approach in this while creating initial CA and Certificate. It does not ask for IP or hostname. So will the same certificate work when the IP for the hosts of the cluster will change?

This documentation does not include the instances.yml file related steps in which we used to generate certs for every instance using docker. Is that approach obsolete?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 16, 2025, 2:33pm UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/5 "2025-04-16T14:33:25Z")

</div>

> [@Umang\_Pachaury](#):
>
> We have followed this approach in this while creating initial CA and Certificate. It does not ask for IP or hostname. So will the same certificate work when the IP for the hosts of the cluster will change?

Yes but it determines the hostname automatically and thus ties the certificate to the hostname it you can see that if you run a `curl -v` or looks at the certificate

or get the truststore password

```auto
./bin/elasticsearch-keystore show xpack.security.transport.ssl.truststore.secure_password

```

then look at the cert

```auto
$ openssl pkcs12 -in transport.p12 -clcerts -nokeys 
Enter Import Password: <<< PASSWORD FROM ABOVE 
Bag Attributes
    friendlyName: transport
    localKeyID: 54 69 6D 65 20 31 37 34 33 30 31 36 37 35 35 32 36 34 
subject=CN=hyperion. <<< HERE HOSTNAME CERT IS BOUND TO 
issuer=CN=Elasticsearch security auto-configuration transport CA

```

Look for IPs or SubjectAltName etc...

> [@Umang\_Pachaury](#):
>
> This documentation does not include the instances.yml file related steps in which we used to generate certs for every instance using docker. Is that approach obsolete?

No the original method is valid, I was showing you options

In short you need to regenerate the certs ...

I am not specifically sure why if you ONLY changed the IPs why they original certs are not working but I would regenerate them. Looks at the certs and determine.

This is "cert stuff" ...yeah ugh... but elasticsearch does not really do anything special

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 16, 2025, 5:29pm UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/6 "2025-04-16T17:29:42Z")

</div>

> [@Regenerate the SSL Certificate that was auto-generated on setup of ElasticSearch](https://discuss.elastic.co/t/regenerate-the-ssl-certificate-that-was-auto-generated-on-setup-of-elasticsearch/377216/1):
>
> Hello! We have been using Elasticsearch with Zammad on an Ubuntu server for several months, and we recently moved the server to a new IP address. Because Elasticsearch was set up with the former IP address, the auto-generated SSL Certificate, "/etc/elasticsearch/certs/http\_ca.crt", is not working with the new IP address. Specifically, it gives an error that the IP address does not match the one in the certificate. We were wondering if there was a command to use that would regenerate this SSL C…

---

<div class="post-metadata">

**Author:** ![Umang\_Pachaury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umang_pachaury/32/113523_2.png) [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Post date:** [April 18, 2025, 12:43pm UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/7 "2025-04-18T12:43:02Z")

</div>

Hi Stephen,

We tried it with the same old certificate and it worked. I guess the steps followed in the above doc does not bound the certificate with IP/Host, because it is mentioned to generate one certificate and copy it to other nodes in the cluster.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 18, 2025, 1:51pm UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/8 "2025-04-18T13:51:07Z")

</div>

Hmmm my test showed bound to host name using the default method.

Just to help me out can you show me where it says create one cert and copy to all the nodes?

---

<div class="post-metadata">

**Author:** ![Umang\_Pachaury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umang_pachaury/32/113523_2.png) [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Post date:** [April 21, 2025, 6:00am UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/9 "2025-04-21T06:00:03Z")

</div>

> **[Set up transport TLS | Elastic Docs](https://www.elastic.co/docs/deploy-manage/security/set-up-basic-security#encrypt-internode-communication)**
>
> Configuring TLS between nodes is the basic security setup to prevent unauthorized nodes from accessing to your Elasticsearch cluster, and it's required...

In this doc in the step 2 :

> On any single node, generate a certificate and private key for the nodes in your cluster. You include the elastic-stack-ca.p12 output file that you generated in the previous step.

And in step 3 :

> On **every** node in your cluster, copy the `elastic-certificates.p12` file to the `$ES_PATH_CONF` directory.

Is my interpretation correct or am I understanding it wrong ?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 21, 2025, 1:45pm UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/10 "2025-04-21T13:45:31Z")

</div>

Nope you are correct for `transport` ..  
For `http` interface they are bound to hostname and IP  
That was my confusion, apologies

Are you still having issues?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [April 21, 2025, 7:31pm UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/11 "2025-04-21T19:31:16Z")

</div>

> [@Umang\_Pachaury](#):
>
> We tried it with the same old certificate and it worked. I guess the steps followed in the above doc does not bound the certificate with IP/Host, because it is mentioned to generate one certificate and copy it to other nodes in the cluster.

I have created certi on A cluster and have used on completely different cluster on different network segment and it works.

---

<div class="post-metadata">

**Author:** ![Umang\_Pachaury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umang_pachaury/32/113523_2.png) [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Post date:** [April 21, 2025, 11:23pm UTC](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/12 "2025-04-21T23:23:17Z")

</div>

Oh i see,  
No we are not facing any issues thanks.
