# Domain gets resolved to IP before cert verification

**URL:** <https://discuss.elastic.co/t/domain-gets-resolved-to-ip-before-cert-verification/330935>\
**Category:** Elastic Security\
**Created:** [April 27, 2023, 9:52am UTC](https://discuss.elastic.co/t/domain-gets-resolved-to-ip-before-cert-verification/330935 "2023-04-27T09:52:31Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Octelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/octelly/32/120320_2.png) [@Octelly](https://discuss.elastic.co/u/Octelly)\
**Post date:** [April 27, 2023, 9:52am UTC](https://discuss.elastic.co/t/domain-gets-resolved-to-ip-before-cert-verification/330935/1 "2023-04-27T09:52:31Z")

</div>

I have a Step-CA instance from which I obtain certificates through lego's CLI. The CA is trusted on all nodes system-wide and the certificates are generated for their domains. Elasticsearch is configured to use these domains as its address as well.

The problem I'm running into, is a Java error complaining about `No subject alternative names matching IP address [resolved IP] found`. This should not be necessary however, right? I've seen this working on another Elasticsearch instance and there were no complaints. My only guess is that the problems stems from the domains only being configured in `/etc/hosts` (on all nodes including the CA of course).  
#elastic-stack:elasticsearch

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2023, 9:52am UTC](https://discuss.elastic.co/t/domain-gets-resolved-to-ip-before-cert-verification/330935/2 "2023-05-25T09:52:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
