# Certificate Error When Setting Up Winlogbeat

**URL:** <https://discuss.elastic.co/t/certificate-error-when-setting-up-winlogbeat/308414>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 29, 2022, 12:00am UTC](https://discuss.elastic.co/t/certificate-error-when-setting-up-winlogbeat/308414 "2022-06-29T00:00:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jared9922](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jared9922/32/99712_2.png) [@Jared9922](https://discuss.elastic.co/u/Jared9922)\
**Post date:** [June 29, 2022, 12:00am UTC](https://discuss.elastic.co/t/certificate-error-when-setting-up-winlogbeat/308414/1 "2022-06-29T00:00:52Z")

</div>

I am setting up an elastic stack for my organization and I am running into some issues. The error happens when I try to run the following command

```auto
.\winlogbeat.exe setup -e

```

When I run that command, I get the following: x509 certificate signed by unknown authority. I was just wondering what the best way to resolve this issue is. With the version of the elasticstack I installed it seems that security is already setup for you. Could somebody link me a guide to help me understand these things better or give me some feedback on how to solve this error?

Thanks,  
Jared

---

<div class="post-metadata">

**Author:** ![preetish\_P](https://avatars.discourse-cdn.com/v4/letter/p/77aa72/32.png) [@preetish\_P](https://discuss.elastic.co/u/preetish_P)\
**Post date:** [June 29, 2022, 10:06am UTC](https://discuss.elastic.co/t/certificate-error-when-setting-up-winlogbeat/308414/2 "2022-06-29T10:06:07Z")

</div>

Hi @Jared9922 ,

Refer [this](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-ssl.html#client-verification-mode)

You either need to sign the server certificate with a CA and define it under : `certificate_authorities`

Or, simply use `verification_mode: none`

---

<div class="post-metadata">

**Author:** ![Jared9922](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jared9922/32/99712_2.png) [@Jared9922](https://discuss.elastic.co/u/Jared9922)\
**Post date:** [June 29, 2022, 4:07pm UTC](https://discuss.elastic.co/t/certificate-error-when-setting-up-winlogbeat/308414/3 "2022-06-29T16:07:00Z")

</div>

We already have certificates setup from what I understand (Elasticsearch autoconfigured it). How do I get a certificate on my windows machine that is signed from my master cert on my elastic machine?

TLDR: How do I generate a certificate, on my main cert from elastic, that can be put on each system I have my beats on. Is there some good documentation for this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2022, 6:07pm UTC](https://discuss.elastic.co/t/certificate-error-when-setting-up-winlogbeat/308414/4 "2022-07-27T18:07:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
