# Certificate error occurred when installing the fleet server

**URL:** <https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710>\
**Category:** Beats\
**Tags:** fleet\
**Created:** [December 21, 2022, 2:29am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710 "2022-12-21T02:29:47Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![lovelike123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lovelike123/32/114986_2.png) [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Post date:** [December 21, 2022, 2:29am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/1 "2022-12-21T02:29:47Z")

</div>

My Elasticsearch and Kibana versions are 8.5.0. When installing the fly, certificate errors are reported all the time. My elasticsearch has set three nodes, and the certificate generated by using the （elasticsearch-certutil ca） command  
Adding -- insert or --fleet-server-es-insecure doesn't even work

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6d6801e59ac5deb1fc5dcb7d2928da94c89b6020.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/c/ac822952b0fb3e7d50c8fabb27f511f88083624f.png)

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 21, 2022, 2:38am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/2 "2022-12-21T02:38:44Z")

</div>

It's probably because the agent does not trust the Fleet Server cert. You can append `--insecure` to your `elastic-agent install` command or add the command line flag to specify the CA cert for the Fleet Server [Configure SSL/TLS for self-managed Fleet Servers | Fleet and Elastic Agent Guide [8.5] | Elastic](https://www.elastic.co/guide/en/fleet/current/secure-connections.html).

---

<div class="post-metadata">

**Author:** ![lovelike123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lovelike123/32/114986_2.png) [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Post date:** [December 21, 2022, 2:56am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/3 "2022-12-21T02:56:52Z")

</div>

I added the two parameters -- insurance or --fleet-server-es-insecure, but both of them failed. The same error still occurred

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d71373341bd73229b74d878fa9fa2e163921fd4.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73435f1435d086d0ad24be0b56abe43d43785027.png)

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 21, 2022, 3:15am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/4 "2022-12-21T03:15:10Z")

</div>

Have you configured the Elasticsearch output in Fleet settings?

Have you configured the Fleet server URL in Fleet settings?

---

<div class="post-metadata">

**Author:** ![lovelike123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lovelike123/32/114986_2.png) [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Post date:** [December 21, 2022, 3:46am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/5 "2022-12-21T03:46:40Z")

</div>

no,What should I do？

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 21, 2022, 3:48am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/6 "2022-12-21T03:48:15Z")

</div>

Go to Kibana \> Fleet \> Settings, configure the Fleet server URL and Elasticsearch output + SSL.

The steps are mentioned in the doc as well [Configure SSL/TLS for self-managed Fleet Servers | Fleet and Elastic Agent Guide [8.5] | Elastic](https://www.elastic.co/guide/en/fleet/current/secure-connections.html).

---

<div class="post-metadata">

**Author:** ![lovelike123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lovelike123/32/114986_2.png) [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Post date:** [December 21, 2022, 3:54am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/7 "2022-12-21T03:54:23Z")

</div>

I have set it, but the error is still the same

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fb4a637b2bb344341db5bb0db22e8f74639bc725.png)

---

<div class="post-metadata">

**Author:** ![lovelike123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lovelike123/32/114986_2.png) [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Post date:** [December 21, 2022, 3:55am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/8 "2022-12-21T03:55:30Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5e8b1f4dbc7a120aabad7446c6a2e91c82078b7c.png)

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 21, 2022, 4:09am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/9 "2022-12-21T04:09:52Z")

</div>

May want to try to re-generate a new Fleet server service token to test.

---

<div class="post-metadata">

**Author:** ![lovelike123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lovelike123/32/114986_2.png) [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Post date:** [December 21, 2022, 5:55am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/10 "2022-12-21T05:55:45Z")

</div>

I tried. It didn't work

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e985d256084b46bd3c0a42d04f87592be06625f1.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d7302cc19beffac3f3462ea7dce6210ffe7d45ee.png)

---

<div class="post-metadata">

**Author:** ![lovelike123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lovelike123/32/114986_2.png) [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Post date:** [December 21, 2022, 6:41am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/11 "2022-12-21T06:41:09Z")

</div>

When I was in elastic-agent install, this problem occurred in elasticsearch

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88de2767c1484da0b9b60e026b13e7e0c9ec05d6.png)

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 21, 2022, 8:52am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/12 "2022-12-21T08:52:41Z")

</div>

Is your Elasticsearch listening on `http` or `https`?

---

<div class="post-metadata">

**Author:** ![lovelike123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lovelike123/32/114986_2.png) [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Post date:** [December 21, 2022, 8:57am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/13 "2022-12-21T08:57:31Z")

</div>

listening on https .My elasticsearch has set three nodes  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/b/1ba1116610a6b5bcc1ca338f8efc8537a4a424c0.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/8/78f1fd5036311d0c1807be5fa986e6b95d2acf5d.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/8/d895aa6905a792334c7d94b59f8526fd707d8d78.png)

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 21, 2022, 9:06am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/14 "2022-12-21T09:06:06Z")

</div>

I am at loss.  
You may want to check if you are using the correct CA cert that you passed to the `elastic-agent install` command.

Are you using the same cert for all the 3 nodes, or different certs with different CA?

---

<div class="post-metadata">

**Author:** ![lovelike123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lovelike123/32/114986_2.png) [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Post date:** [December 21, 2022, 9:10am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/15 "2022-12-21T09:10:14Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/3/a39146395625deca17f237723032e5c87a0431a3.png)

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 21, 2022, 9:13am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/16 "2022-12-21T09:13:38Z")

</div>

Looks like you are using the auto-generated SSL keys/certs/keystores. If that's the case, each instance generates their own SSL key/cert/keystore and CA, so they are not the same.

---

<div class="post-metadata">

**Author:** ![lovelike123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lovelike123/32/114986_2.png) [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Post date:** [December 21, 2022, 9:18am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/17 "2022-12-21T09:18:14Z")

</div>

Yes, I use it （./bin/elasticsearch-certutil ca ）and （./bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12）Generate certificate. （./bin/elasticsearch-certutil http）generates http certificates for different nodes  
What should I do?

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 21, 2022, 9:20am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/18 "2022-12-21T09:20:22Z")

</div>

Can you try to use the same CA cert that you used to attempt to install the agent with `curl`? e.g. `curl -v --cacert <path to CA cert> https://...:9200`.

---

<div class="post-metadata">

**Author:** ![lovelike123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lovelike123/32/114986_2.png) [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Post date:** [December 21, 2022, 9:25am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/19 "2022-12-21T09:25:20Z")

</div>

Do you mean that

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a9eb0e681f258ccf9cf1f0741454d3405ed88c60.png)

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 21, 2022, 9:28am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710/20 "2022-12-21T09:28:01Z")

</div>

You specified `--fleet-server-es-ca` in `elastic-agent install` command. Use the same CA cert with curl to try to connect to Elasticsearch, and see if that succeeds.

[Next page](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710.md?page=2)
