# Certificate doesn't match any of the subject alternative names

**URL:** <https://discuss.elastic.co/t/certificate-doesnt-match-any-of-the-subject-alternative-names/298091>\
**Category:** Logstash\
**Created:** [February 23, 2022, 10:25pm UTC](https://discuss.elastic.co/t/certificate-doesnt-match-any-of-the-subject-alternative-names/298091 "2022-02-23T22:25:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [February 23, 2022, 10:25pm UTC](https://discuss.elastic.co/t/certificate-doesnt-match-any-of-the-subject-alternative-names/298091/1 "2022-02-23T22:25:55Z")

</div>

Since update to ELK 8 there is following problem:

`[2022-02-23T23:18:41,619][WARN][logstash.outputs.elasticsearch][main] Failed to perform request {:message=>"Certificate for <elasticsearch> doesn't match any of the subject alternative names: [fe80:0:0:0:b253:fe6:fed2:1963, localhost, 0:0:0:0:0:0:0:1, 127.0.0.1, 192.168.1.1, ASDF]", :exception=>Manticore::UnknownException, :cause=>javax.net.ssl.SSLPeerUnverifiedException: Certificate for <elasticsearch> doesn't match any of the subject alternative names: [fe80:0:0:0:b253:fe6:fed2:1963, localhost, 0:0:0:0:0:0:0:1, 127.0.0.1, 192.168.1.1, ASDF]}`

Now certificate is generated due apt-get install, not like before - manually, where I was able to set values like alternative name etc.

I found also solutions to verify only 'certificate', but it dont work in ELK 8.

I want have certificate validation with `ssl_certificate_verification => true` and I want have most universal config, so I have connection to hostname `elasticsearch` which I configure in `/etc/hosts` - I don't want always edit config in XX places. I dont want always edit config for it common name generated due install with apt.

Please help, thanks.

---

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [March 7, 2022, 2:08pm UTC](https://discuss.elastic.co/t/certificate-doesnt-match-any-of-the-subject-alternative-names/298091/2 "2022-03-07T14:08:39Z")

</div>

Any idea how can I edit/regenerate certificate to set own/wanted alternative names?

---

<div class="post-metadata">

**Author:** ![maof97](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maof97/32/101433_2.png) [@maof97](https://discuss.elastic.co/u/maof97)\
**Post date:** [March 8, 2022, 1:20am UTC](https://discuss.elastic.co/t/certificate-doesnt-match-any-of-the-subject-alternative-names/298091/3 "2022-03-08T01:20:38Z")

</div>

I had a similar problem like this ([Unable to create an enrollment token for Kibana. "Elasticsearch node HTTP layer SSL configuration Keystore doesn't contain any PrivateKey entries where the associated certificate is a CA certificate"](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token-for-kibana-elasticsearch-node-http-layer-ssl-configuration-keystore-doesnt-contain-any-privatekey-entries-where-the-associated-certificate-is-a-ca-certificate/297032))

A reply I got there was:

> [@Unable to create an enrollment token for Kibana. "Elasticsearch node HTTP layer SSL configuration Keystore doesn't contain any PrivateKey entries where the associated certificate is a CA certificate"](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token-for-kibana-elasticsearch-node-http-layer-ssl-configuration-keystore-doesnt-contain-any-privatekey-entries-where-the-associated-certificate-is-a-ca-certificate/297032/4):
>
> We do our best to detect all IP addresses of the interfaces that are up when Elasticsearch is installed and then use them as IP Subject Alternative Names in the HTTP TLS certificate.

So I guess you made the same mistake as me, by installing ES without the later used interface being already present.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2022, 1:20am UTC](https://discuss.elastic.co/t/certificate-doesnt-match-any-of-the-subject-alternative-names/298091/4 "2022-04-05T01:20:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
