# Configure beats to reload certificates?

**URL:** <https://discuss.elastic.co/t/configure-beats-to-reload-certificates/305976>\
**Category:** Beats\
**Tags:** beats-development\
**Created:** [May 30, 2022, 6:56pm UTC](https://discuss.elastic.co/t/configure-beats-to-reload-certificates/305976 "2022-05-30T18:56:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fgjensen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fgjensen/32/62320_2.png) [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Post date:** [May 30, 2022, 6:56pm UTC](https://discuss.elastic.co/t/configure-beats-to-reload-certificates/305976/1 "2022-05-30T18:56:42Z")

</div>

We deploy most beattypes to hosts managed by different service providers. The beats ships data to Logstash beats endpoints protected with TLS and firewalls. This setup works very well.

However, changing expired TLS certificates may impose some problems, since either the beats and/or the firewalls cache the TLS certificate, so Logstash validates a certificate to be expired even though it has been replaced by a new certificate.

If the certificate is cached on the beats host a restart of the beats fixes the problem. However, this not an elegant solution. How can I configure a beat to detect if the key/certificate must be reloaded?

Best regards  
Flemming

---

<div class="post-metadata">

**Author:** ![ibra\_013](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ibra_013/32/104827_2.png) [@ibra\_013](https://discuss.elastic.co/u/ibra_013)\
**Post date:** [June 1, 2022, 10:20am UTC](https://discuss.elastic.co/t/configure-beats-to-reload-certificates/305976/2 "2022-06-01T10:20:48Z")

</div>

Hi,

Interested in the answer.

---

<div class="post-metadata">

**Author:** ![fgjensen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fgjensen/32/62320_2.png) [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Post date:** [June 3, 2022, 6:25am UTC](https://discuss.elastic.co/t/configure-beats-to-reload-certificates/305976/3 "2022-06-03T06:25:05Z")

</div>

Perhaps it is not possible from the beats, but we could to it with apt and chocolatey when the beats are deployed.

BR Flemming

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 1, 2022, 8:25am UTC](https://discuss.elastic.co/t/configure-beats-to-reload-certificates/305976/4 "2022-07-01T08:25:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
