# Deploy elastic-agent with cert?

**URL:** <https://discuss.elastic.co/t/deploy-elastic-agent-with-cert/247397>\
**Category:** Elasticsearch\
**Tags:** elastic-agent\
**Created:** [September 3, 2020, 1:57pm UTC](https://discuss.elastic.co/t/deploy-elastic-agent-with-cert/247397 "2020-09-03T13:57:29Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![elk6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk6/32/72282_2.png) [@elk6](https://discuss.elastic.co/u/elk6)\
**Post date:** [September 3, 2020, 1:57pm UTC](https://discuss.elastic.co/t/deploy-elastic-agent-with-cert/247397/1 "2020-09-03T13:57:29Z")

</div>

I'm trying to deploy the agent but my kibana instance requires a certificate which won't let me connect to it. Is there a way to give it a certificate or another way around this?

```
fail to enroll: fail to execute request to Kibana: Post "https://elk.companyname.net:5601/api/ingest_manager/fleet/agents/enroll?": x509: certificate signed by unknown authority
```

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [September 3, 2020, 4:44pm UTC](https://discuss.elastic.co/t/deploy-elastic-agent-with-cert/247397/2 "2020-09-03T16:44:35Z")

</div>

Good question for which I don't have the answer. But some random thoughts which popup:

- Is this on a Linux or Windows system?
- Is your CA certificate in the certificate store of your os?

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 4, 2020, 7:27am UTC](https://discuss.elastic.co/t/deploy-elastic-agent-with-cert/247397/3 "2020-09-04T07:27:32Z")

</div>

Hi @elk6 Have a look at [[Ingest management] Use insecure elasticsearch output managed in fleet mode for elastic agent](https://discuss.elastic.co/t/ingest-management-use-insecure-elasticsearch-output-managed-in-fleet-mode-for-elastic-agent/246022) and the linked issues. Unfortunately it is currently a common issue users hit in 7.9 (see [https://discuss.elastic.co/tag/stack-ingest-management](https://discuss.elastic.co/tag/stack-ingest-management)) and we are working on solutions. In the link threads you find potential workarounds.

---

<div class="post-metadata">

**Author:** ![elk6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk6/32/72282_2.png) [@elk6](https://discuss.elastic.co/u/elk6)\
**Post date:** [September 4, 2020, 9:38am UTC](https://discuss.elastic.co/t/deploy-elastic-agent-with-cert/247397/4 "2020-09-04T09:38:41Z")

</div>

It's linux. I just did -i for insecure connection.

---

<div class="post-metadata">

**Author:** ![elk6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk6/32/72282_2.png) [@elk6](https://discuss.elastic.co/u/elk6)\
**Post date:** [September 4, 2020, 9:43am UTC](https://discuss.elastic.co/t/deploy-elastic-agent-with-cert/247397/5 "2020-09-04T09:43:24Z")

</div>

Hi ruflin, thanks for the response. Loved your live demo!

I was able to connect with with an insecure connection ( I thought the point of all this was to eliminate all the massive headache of certificates). Now my only problem is that I don't see anything in my dataset, even though my agent is live, shows no errors, and is set to collect system and apache intergrations.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 4, 2020, 11:29am UTC](https://discuss.elastic.co/t/deploy-elastic-agent-with-cert/247397/6 "2020-09-04T11:29:05Z")

</div>

Would be great if we would have solve all the certificate issue. We kind of have when you use our Elastic Cloud as there all the certificates are known. If you run it on your own, you will still have to deal with all the certificate stuff.

Can you check the filebeat logs under `data` on the agent side if you see any errors in there? We don't bubble up these connections in a good way yet ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2020, 11:29am UTC](https://discuss.elastic.co/t/deploy-elastic-agent-with-cert/247397/7 "2020-10-02T11:29:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
