# ECE - Certificate chain was invalid

**URL:** <https://discuss.elastic.co/t/ece-certificate-chain-was-invalid/217125>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Created:** [January 30, 2020, 8:21am UTC](https://discuss.elastic.co/t/ece-certificate-chain-was-invalid/217125 "2020-01-30T08:21:39Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [January 30, 2020, 3:30pm UTC](https://discuss.elastic.co/t/ece-certificate-chain-was-invalid/217125/2 "2020-01-30T15:30:52Z")

</div>

Are the suggestions in this topic of any use?

> [@ECE 2.0.1 Unable to upload Letsencrypt TLS certificate](https://discuss.elastic.co/t/ece-2-0-1-unable-to-upload-letsencrypt-tls-certificate/158802/4):
>
> Despite its name, I'm not convinced fullchain.pem includes the CA cert, can you double check? If not, try converting/cating that in Otherwise you should be able to use openssl to verify the combined PEM is valid (or if not, what's wrong with it), eg: Let's assume the following values are set: SRV\_KEY=[path to server RSA key] SRV\_CERT=[path to server X509 cert] INTER\_CERT=[path to intermediate CA X509 cert] CA\_CERT=[path to CA X509 cert] CHAIN=[path to certificate chain, eg cat $SRV\_KEY $SRV\_C…

---

_[View the full topic](https://discuss.elastic.co/t/ece-certificate-chain-was-invalid/217125)._
