# Cannot read existing Message Signing Key pair for all integrations and fleet actions

**URL:** <https://discuss.elastic.co/t/cannot-read-existing-message-signing-key-pair-for-all-integrations-and-fleet-actions/360205>\
**Category:** Kibana\
**Created:** [May 24, 2024, 8:43pm UTC](https://discuss.elastic.co/t/cannot-read-existing-message-signing-key-pair-for-all-integrations-and-fleet-actions/360205 "2024-05-24T20:43:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mealbert23](https://avatars.discourse-cdn.com/v4/letter/m/53a042/32.png) [@mealbert23](https://discuss.elastic.co/u/mealbert23)\
**Post date:** [May 24, 2024, 8:43pm UTC](https://discuss.elastic.co/t/cannot-read-existing-message-signing-key-pair-for-all-integrations-and-fleet-actions/360205/1 "2024-05-24T20:43:58Z")

</div>

Hi,

I have deployed Elasticsearch and Kibana on a aws eks cluster by mostly following the quickstart guide for elastic cloud on kubernetes. I was able to get both elasticsearch and kibana running but know I want to setup integrations with AWS. No matter which instructions I follow I can't seem to get past the error "Cannot read existing Message Signing Key pair". I have tried creating Fleet server and agent with the same error. Any help as to why I am getting this error and how to resolve it would be great.  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 24, 2024, 8:46pm UTC](https://discuss.elastic.co/t/cannot-read-existing-message-signing-key-pair-for-all-integrations-and-fleet-actions/360205/2 "2024-05-24T20:46:15Z")

</div>

Hello and welcome,

Where are you receiving that message? it is not clear from where is this message.

You need to share the entire error.

---

<div class="post-metadata">

**Author:** ![mealbert23](https://avatars.discourse-cdn.com/v4/letter/m/53a042/32.png) [@mealbert23](https://discuss.elastic.co/u/mealbert23)\
**Post date:** [May 24, 2024, 8:53pm UTC](https://discuss.elastic.co/t/cannot-read-existing-message-signing-key-pair-for-all-integrations-and-fleet-actions/360205/3 "2024-05-24T20:53:55Z")

</div>

Hi,

Thanks for the quick reply. It shows up in Kibana on any of the integrations when clicking add integration, clicking save and continue, and on the Fleet page when trying to add a Fleet server or agent.

The entire message is: Configuration error

Cannot read existing Message Signing Key pair  
That's it.  
Thanks.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 24, 2024, 9:00pm UTC](https://discuss.elastic.co/t/cannot-read-existing-message-signing-key-pair-for-all-integrations-and-fleet-actions/360205/4 "2024-05-24T21:00:36Z")

</div>

Please share a screenshot of the error.

---

<div class="post-metadata">

**Author:** ![mealbert23](https://avatars.discourse-cdn.com/v4/letter/m/53a042/32.png) [@mealbert23](https://discuss.elastic.co/u/mealbert23)\
**Post date:** [May 24, 2024, 9:04pm UTC](https://discuss.elastic.co/t/cannot-read-existing-message-signing-key-pair-for-all-integrations-and-fleet-actions/360205/5 "2024-05-24T21:04:08Z")

</div>

Sure, here you go. I get the same error when trying to add a fleet manager or agent.

 ![Screenshot 2024-05-24 at 2.03.26 PM](https://us1.discourse-cdn.com/elastic/original/3X/7/0/7001f9ca7ce37619dd66cc3f7170d966b0d1d9cd.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 24, 2024, 9:11pm UTC](https://discuss.elastic.co/t/cannot-read-existing-message-signing-key-pair-for-all-integrations-and-fleet-actions/360205/6 "2024-05-24T21:11:19Z")

</div>

Yeah, I do not use ECK, but this github issue has more explanation about this error and a workaround to fix it: [Saving Agent Policy fails with "Cannot read existing Message Signing Key pair" · Issue #176528 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/176528#issuecomment-1936330383)

It seems related to having another kibana instance in eck change the signing key I guess.

---

<div class="post-metadata">

**Author:** ![mealbert23](https://avatars.discourse-cdn.com/v4/letter/m/53a042/32.png) [@mealbert23](https://discuss.elastic.co/u/mealbert23)\
**Post date:** [May 28, 2024, 8:35pm UTC](https://discuss.elastic.co/t/cannot-read-existing-message-signing-key-pair-for-all-integrations-and-fleet-actions/360205/7 "2024-05-28T20:35:51Z")

</div>

Hi @leandrojmp ,

Thanks for the link. After some trial and error I was able to get the old keys deleted and new keys generated. After that I was able to setup the aws integration successfully. I do have one last questions. Is the elastic agent and Fleet server required for the integrations to work? With everything I am reading it is not 100% clear. Also when trying to setup the Fleet server I can't seem to get passed the "Install to a centralized host". I am running this on an EKS setup and all the official documentation mentions either elastic cloud or on prem. If you could point me in the right direction or have any insights that would be great. If I don't need a Fleet Server or Agent even better.

Thanks in advance.
