# Elastic Agent 7.10.1 : javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate

**URL:** <https://discuss.elastic.co/t/elastic-agent-7-10-1-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/260607>\
**Category:** Elastic Security\
**Created:** [January 9, 2021, 2:11pm UTC](https://discuss.elastic.co/t/elastic-agent-7-10-1-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/260607 "2021-01-09T14:11:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hilo21](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilo21/32/66272_2.png) [@hilo21](https://discuss.elastic.co/u/hilo21)\
**Post date:** [January 9, 2021, 2:11pm UTC](https://discuss.elastic.co/t/elastic-agent-7-10-1-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/260607/1 "2021-01-09T14:11:24Z")

</div>

Hello,

I was testing the latest version of Elastic Stack 7.10.1. So far, so far following the documentation I managed setup an test environment and setup a small lab.

I am interested in testing (Simulating Attacks) on a machine that has Elastic Agent installed. So far I managed to install it on a windows 7 machine and after pulling my hair over why my Agent is only online for couple of minutes before it goes completely offline I managed to enroll it using Fleet.

My agent is now enrolled but I am not receiving any data. After reviewing Elasticsearch logs I found this error :

```auto
[WARN][o.e.h.AbstractHttpServerTransport] [aio] caught exception while handling client http traffic, closing connection Netty4HttpChannel{localAddress=/192.168.20.155:9200, remoteAddress=/192.168.20.25:50945}
io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad_certificate

```

This clearly indicates that elasticsearch refusing communication with the machine that has Elastic Agent 192.168.20.25.

I am trying to do the same configuration here as I did for my agents like winlogbeat and filebeat but it doesn't work for me :

```auto
outputs:
  default:
    type: elasticsearch
    hosts: [https://192.168.20.155:9200]
    ssl.certificate_authorities: ["C:\Tools\cert\elastic-stack-ca.pem"]
    ssl.verification_mode: none
    username: elastic
    password: elastic

```

I can't find any documentation on how to configrue elastic agent to use self signed certificates. can you please help or guide me.

Thank you

---

<div class="post-metadata">

**Author:** ![hilo21](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilo21/32/66272_2.png) [@hilo21](https://discuss.elastic.co/u/hilo21)\
**Post date:** [January 9, 2021, 4:11pm UTC](https://discuss.elastic.co/t/elastic-agent-7-10-1-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/260607/2 "2021-01-09T16:11:43Z")

</div>

Okey I solved it, gonna leave this here for others

Did some more digging in github repos. I found this issue :

> <https://github.com/elastic/kibana/issues/72718>
>
> Summary of the problem
> Having secure communication between Elastic-Agent and elasticsearch or tier services requires to deal with SSL (TLS), which is...

  
which lead me to this other one with a workaround :  

> <https://github.com/elastic/kibana/issues/73483#issuecomment-676419501>
>
> Design
> Design Custom CAs and SSL options #72718
> Ingest Manager
> Add support for custom CA for outputs #73487
> Add support for Custom...

  
Because I am just testing this I disabled verification in the action-store.yml file found (in my windows machine) here `C:\Program Files\Elastic\Agent\data\elastic-agent-1da173\`:

```auto
  outputs:
    default:
      api_key: 1Pje5..................
      hosts:
      - https://192.168.20.155:9200
      type: elasticsearch
      ssl.verification_mode: none

```

---

<div class="post-metadata">

**Author:** ![K\_I\_M](https://avatars.discourse-cdn.com/v4/letter/k/838e76/32.png) [@K\_I\_M](https://discuss.elastic.co/u/K_I_M)\
**Post date:** [February 3, 2021, 3:42pm UTC](https://discuss.elastic.co/t/elastic-agent-7-10-1-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/260607/3 "2021-02-03T15:42:36Z")

</div>

> [@hilo21](#):
>
> disabled verification in the action-store.yml

## kibana.yml

elasticsearch.username: "elastic"  
elasticsearch.password: "............"  
elasticsearch.ssl.certificateAuthorities: ["/etc/kibana/certs/ca-test.crt"]  
server.ssl.enabled: true  
server.ssl.certificate: /etc/kibana/certs/elastic-test-visual.crt  
server.ssl.key: /etc/kibana/certs/elastic-test-visual.key  
xpack.security.enabled: true  
xpack.security.audit.enabled: true  
xpack.fleet.enabled: true  
xpack.encryptedSavedObjects.encryptionKey: "................."

## elasticsearch.yml (on test1 node) ...

xpack.security.enabled: true  
xpack.security.authc.api\_key.enabled: true

#### Transport layer

xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.key: certs/elastic-test1.key  
xpack.security.transport.ssl.certificate: certs/elastic-test1.crt  
xpack.security.transport.ssl.certificate\_authorities: certs/ca-test.crt

#### HTTP layer

xpack.security.http.ssl.enabled: true  
xpack.security.http.ssl.verification\_mode: certificate  
xpack.security.http.ssl.key: certs/elastic-test1.key  
xpack.security.http.ssl.certificate: certs/elastic-test1.crt  
xpack.security.http.ssl.certificate\_authorities: certs/ca-test.crt

# on host with elastic-agent:

1. copy ca-test.crt to /etc/pki/tls/certs/ (centos7) truststore
2. ./elastic-agent enroll [https://kibana\_host](https://kibana_host) --certificate-authorities /etc/pki/tls/certs/ca-test.crt

- ssl.verification oK
- Data streams onboard

Thanks for hint 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:21am UTC](https://discuss.elastic.co/t/elastic-agent-7-10-1-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/260607/4 "2022-11-04T08:21:13Z")

</div>


