# \[elastic\_agent.metricbeat\]\[info\] CA certificate matching 'ca\_trusted\_fingerprint' found, adding it to 'certificate\_authorities'

**URL:** <https://discuss.elastic.co/t/elastic-agent-metricbeat-info-ca-certificate-matching-ca-trusted-fingerprint-found-adding-it-to-certificate-authorities/358418>\
**Category:** Elasticsearch\
**Created:** [April 29, 2024, 11:10am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-info-ca-certificate-matching-ca-trusted-fingerprint-found-adding-it-to-certificate-authorities/358418 "2024-04-29T11:10:13Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![otortosa](https://avatars.discourse-cdn.com/v4/letter/o/90db22/32.png) [@otortosa](https://discuss.elastic.co/u/otortosa)\
**Post date:** [April 29, 2024, 11:10am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-info-ca-certificate-matching-ca-trusted-fingerprint-found-adding-it-to-certificate-authorities/358418/1 "2024-04-29T11:10:13Z")

</div>

Hello team!

I receive from my Ubuntu host these logs all the time.

[elastic\_agent.metricbeat][info] CA certificate matching 'ca\_trusted\_fingerprint' found, adding it to 'certificate\_authorities'

[elastic\_agent.metricbeat][info] 'ca\_trusted\_fingerprint' set, looking for matching fingerprints

What can be causing this logs?

Find below my elasticsearch.yml

# Enable security features

xpack.security.enabled: true

xpack.security.enrollment.enabled: true

# Enable encryption for HTTP API client connections, such as Kibana, Logstash, and Agents

xpack.security.http.ssl:  
enabled: true  
keystore.path: certs/http.p12

# Enable encryption and mutual authentication between cluster nodes

xpack.security.transport.ssl:  
enabled: true  
verification\_mode: certificate  
keystore.path: certs/transport.p12  
truststore.path: certs/transport.p12

Thanks in advance!

Kind regards,

---

<div class="post-metadata">

**Author:** ![otortosa](https://avatars.discourse-cdn.com/v4/letter/o/90db22/32.png) [@otortosa](https://discuss.elastic.co/u/otortosa)\
**Post date:** [April 29, 2024, 11:54am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-info-ca-certificate-matching-ca-trusted-fingerprint-found-adding-it-to-certificate-authorities/358418/2 "2024-04-29T11:54:07Z")

</div>

I followed this thread and still receiving the logs.

> **[Set up basic security for the Elastic Stack | Elasticsearch Guide \[8.13\] |...](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup.html#encrypt-internode-communication)**

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 30, 2024, 4:44am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-info-ca-certificate-matching-ca-trusted-fingerprint-found-adding-it-to-certificate-authorities/358418/3 "2024-04-30T04:44:25Z")

</div>

Why are you concerned about this message? It's perfectly normal.

---

<div class="post-metadata">

**Author:** ![otortosa](https://avatars.discourse-cdn.com/v4/letter/o/90db22/32.png) [@otortosa](https://discuss.elastic.co/u/otortosa)\
**Post date:** [April 30, 2024, 6:17am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-info-ca-certificate-matching-ca-trusted-fingerprint-found-adding-it-to-certificate-authorities/358418/4 "2024-04-30T06:17:48Z")

</div>

Hello Tim,

Wanted to know if my SSL Configuration is correct.

Thanks,

---

<div class="post-metadata">

**Author:** ![otortosa](https://avatars.discourse-cdn.com/v4/letter/o/90db22/32.png) [@otortosa](https://discuss.elastic.co/u/otortosa)\
**Post date:** [September 16, 2024, 3:03pm UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-info-ca-certificate-matching-ca-trusted-fingerprint-found-adding-it-to-certificate-authorities/358418/5 "2024-09-16T15:03:05Z")

</div>

Hello Tim,

Checking again the situation, wanted to know if I can avoid this logs in my Observability Explorer.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 18, 2024, 2:23am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-info-ca-certificate-matching-ca-trusted-fingerprint-found-adding-it-to-certificate-authorities/358418/6 "2024-09-18T02:23:30Z")

</div>

I don't think there's any way to avoid them, nor do I understand why you are so keen to do so.

Tools produce informational messages, trying to hide them is futile.

---

<div class="post-metadata">

**Author:** ![raiden](https://avatars.discourse-cdn.com/v4/letter/r/8dc957/32.png) [@raiden](https://discuss.elastic.co/u/raiden)\
**Post date:** [January 14, 2025, 12:49am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-info-ca-certificate-matching-ca-trusted-fingerprint-found-adding-it-to-certificate-authorities/358418/7 "2025-01-14T00:49:32Z")

</div>

Understandable but it just seems like noise, since it is repeating that message without providing any informational value, as the CA cert and fingerprint ARE configured and found matching. So saying its searching for it and finding it over and over can be a bit of a distraction. After a while you take for granted that it IS configured correctly. If something else were to come up it'd be buried beneath reams of data that isn't providing additional value but it consuming attention and data storage.

I've seen on other occasions that certain settings can be configured for fleet in Kibana, making it so that the setting is natively understood without the need to ping the system for known information. Just for the sake of efficiency is there nothing comparable to that for this particular situation?

---

<div class="post-metadata">

**Author:** ![JeffP](https://avatars.discourse-cdn.com/v4/letter/j/e495f1/32.png) [@JeffP](https://discuss.elastic.co/u/JeffP)\
**Post date:** [January 30, 2025, 12:49am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-info-ca-certificate-matching-ca-trusted-fingerprint-found-adding-it-to-certificate-authorities/358418/8 "2025-01-30T00:49:20Z")

</div>

There must be a way to disable these 'info' messages from the Elastic agent. I'm seeing about 30 messages / minute from filebeat and metricbeat combined. That's a bit much.

Sample messages:

```auto
{"log.level":"info","@timestamp":"2025-01-30T00:46:47.002Z","message":"'ca_trusted_fingerprint' set, looking for matching fingerprints","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"log.logger":"tls","log.origin":{"file.line":179,"file.name":"tlscommon/tls_config.go","function":"github.com/elastic/elastic-agent-libs/transport/tlscommon.trustRootCA"},"service.name":"filebeat","ecs.version":"1.6.0","ecs.version":"1.6.0"}

{"log.level":"info","@timestamp":"2025-01-30T00:46:47.002Z","message":"CA certificate matching 'ca_trusted_fingerprint' found, adding it to 'certificate_authorities'","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"service.name":"filebeat","ecs.version":"1.6.0","log.logger":"tls","log.origin":{"file.line":199,"file.name":"tlscommon/tls_config.go","function":"github.com/elastic/elastic-agent-libs/transport/tlscommon.trustRootCA"},"ecs.version":"1.6.0"}

```

Or moving these to 'error' or 'debug' log levels seems appropriate.
