# Change certificate for up and running cluster

**URL:** <https://discuss.elastic.co/t/change-certificate-for-up-and-running-cluster/290976>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 5, 2021, 8:56am UTC](https://discuss.elastic.co/t/change-certificate-for-up-and-running-cluster/290976 "2021-12-05T08:56:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hinoryo](https://avatars.discourse-cdn.com/v4/letter/h/8c91f0/32.png) [@hinoryo](https://discuss.elastic.co/u/hinoryo)\
**Post date:** [December 5, 2021, 8:56am UTC](https://discuss.elastic.co/t/change-certificate-for-up-and-running-cluster/290976/1 "2021-12-05T08:56:53Z")

</div>

hello,  
i want to change/update the whole cluster nodes certificates (because I've lost the ca.key so i can't generate a new certificate for the new node), for that i generated new certs for the cluster nodes using :

```auto
/bin/elasticsearch-certutil cert --keep-ca-key ca --pem --in /etc/elasticsearch/instance.new.yml --out /etc/elasticsearch/certs.zip

```

and modified the Elasticsearch.yml file for all nodes to use the new generated certificates but when i restart the cluster i got the following errors:

```auto
[o.e.x.s.t.n.SecurityNetty4HttpServerTransport] [node1] http client did not trust this server's certificate, closing connection Netty4HttpChannel{localAddress=/
o.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad_certificate
        at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:471) ~[netty-codec-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:276) ~[netty-codec-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:379) [netty-transport-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:365) [netty-transport-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:357) [netty-transport-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1410) [netty-transport-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:379) [netty-transport-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:365) [netty-transport-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:919) [netty-transport-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:163) [netty-transport-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:714) [netty-transport-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.channel.nio.NioEventLoop.processSelectedKeysPlain(NioEventLoop.java:615) [netty-transport-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:578) [netty-transport-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:493) [netty-transport-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.util.concurrent.SingleThreadEventExecutor$4.run(SingleThreadEventExecutor.java:989) [netty-common-4.1.49.Final.jar:4.1.49.Final]
        at io.netty.util.internal.ThreadExecutorMap$2.run(ThreadExecutorMap.java:74) [netty-common-4.1.49.Final.jar:4.1.49.Final]
        at java.lang.Thread.run(Thread.java:831) [?:?]
Caused by: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad_certificate

```

I'm i missing something ?  
Thank you

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 6, 2021, 3:18am UTC](https://discuss.elastic.co/t/change-certificate-for-up-and-running-cluster/290976/2 "2021-12-06T03:18:15Z")

</div>

> [@hinoryo](#):
>
> I'm i missing something ?

I imagine so, but since you haven't provided a detailed description of the steps you took, it's hard to know where you went wrong.

> [@hinoryo](#):
>
> modified the Elasticsearch.yml file for all nodes to use the new generated certificates

What exactly did you do?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2022, 3:18am UTC](https://discuss.elastic.co/t/change-certificate-for-up-and-running-cluster/290976/3 "2022-01-03T03:18:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
