# Elastic agent offline after upgrade from Fleet

**URL:** <https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [October 13, 2023, 8:20am UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973 "2023-10-13T08:20:48Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![DaddyYusk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daddyyusk/32/127617_2.png) [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Post date:** [October 13, 2023, 8:20am UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/1 "2023-10-13T08:20:48Z")

</div>

Hi,  
Because of the last vulnerabilities from this week affecting Elastic Suite, I've made an upgrade from 8.8.0 to 8.10.3 of all my Elastic Agent from Fleet.

Now all the agents are Offline (and displaying the version as 8.8.0) despite the fact that metrics and logs are still forwarded and properly received...

```auto
* requester 0/1 to host https://192.168.202.23:8220/ errored: Post "https://192.168.202.23:8220/api/fleet/agents/c8f50944-ebb2-447a-a030-e3624cac5be7/acks?": x509: cannot validate certificate for 192.168.202.23 because it doesn't contain any IP SANs

```

Any idea please?  
Regards.

---

<div class="post-metadata">

**Author:** ![DaddyYusk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daddyyusk/32/127617_2.png) [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Post date:** [October 13, 2023, 10:19am UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/2 "2023-10-13T10:19:39Z")

</div>

So it seems that my certificate doesn't contain any IP SANs...  
Do you have any walkthough for updating my certificate on both Elastic Agent and Fleet Server?  
As I'm unable to find the configuration file for Fleet Server...

This leads me to a more general question : how to proceed for certificates renewal?

Thanks!

---

<div class="post-metadata">

**Author:** ![nchaulet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nchaulet/32/77896_2.png) [@nchaulet](https://discuss.elastic.co/u/nchaulet)\
**Post date:** [October 13, 2023, 12:26pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/3 "2023-10-13T12:26:02Z")

</div>

Hi @DaddyYusk

If it's possible for you to re-enroll your fleet server you can re-enroll it with your new certificate following the doc here [Configure SSL/TLS for self-managed Fleet Servers | Fleet and Elastic Agent Guide [8.10] | Elastic](https://www.elastic.co/guide/en/fleet/current/secure-connections.html)

---

<div class="post-metadata">

**Author:** ![nchaulet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nchaulet/32/77896_2.png) [@nchaulet](https://discuss.elastic.co/u/nchaulet)\
**Post date:** [October 13, 2023, 1:36pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/4 "2023-10-13T13:36:05Z")

</div>

By curiosity I am trying to figure how the certificate became invalid, how did you upgrade your fleet server?

---

<div class="post-metadata">

**Author:** ![DaddyYusk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daddyyusk/32/127617_2.png) [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Post date:** [October 13, 2023, 4:19pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/5 "2023-10-13T16:19:28Z")

</div>

Thanks a lot @nchaulet for the provided link ; this one is already in my bookmarks for quite some times and définitively useful.  
But it showcases only a SSL/TLS deployment from scratch, not an update of the certificate (and I didn't found this case in the Elastic documentation...)

One question please : if I re-enroll my fleet server, will I loose all the already enrolled Elastic Agents and need to re-enroll them again on the new Fleet Server?

Regards.

---

<div class="post-metadata">

**Author:** ![DaddyYusk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daddyyusk/32/127617_2.png) [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Post date:** [October 13, 2023, 4:21pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/6 "2023-10-13T16:21:30Z")

</div>

Also I did the upgrade of Elasticsearch, Logstash and Kibana from the packet manager apt.  
For the Fleet Server and all Elastic Agents, I did that using Kibana's Fleet UI.

---

<div class="post-metadata">

**Author:** ![DaddyYusk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daddyyusk/32/127617_2.png) [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Post date:** [October 13, 2023, 4:24pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/7 "2023-10-13T16:24:01Z")

</div>

And I should probably register a domain name for the Fleet Server in order to avoid this kind of issues too.

---

<div class="post-metadata">

**Author:** ![nchaulet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nchaulet/32/77896_2.png) [@nchaulet](https://discuss.elastic.co/u/nchaulet)\
**Post date:** [October 16, 2023, 1:14pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/8 "2023-10-16T13:14:59Z")

</div>

if you re-enroll a fleet server accessible to the same address using the same CA it should be fine for the already enrolled agents.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 16, 2023, 1:21pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/9 "2023-10-16T13:21:12Z")

</div>

@nchaulet just curious, what would be the answer for this?

> [@DaddyYusk](#):
>
> This leads me to a more general question : how to proceed for certificates renewal?

How can the users change the certificate used by a Fleet Server on renewal scenarios for example? I could not find anything on the documentation, I opened a topic here about this and also a ticket on support but could not get any answer yet.

---

<div class="post-metadata">

**Author:** ![nchaulet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nchaulet/32/77896_2.png) [@nchaulet](https://discuss.elastic.co/u/nchaulet)\
**Post date:** [October 16, 2023, 1:28pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/10 "2023-10-16T13:28:25Z")

</div>

> [@DaddyYusk](#):
>
> certificates renewal

it's a good question we do not have a proper documentation yet for that, replacing the existing certificates files and restarting agents seems to work (if the certificate use the same CA)

---

<div class="post-metadata">

**Author:** ![DaddyYusk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daddyyusk/32/127617_2.png) [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Post date:** [October 16, 2023, 2:43pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/11 "2023-10-16T14:43:13Z")

</div>

That's great to hear.  
Do you know if it is possible to explicitely specify a path to the certificate file for Elastic Agent? Which configuration file do I need to edit for that please?  
Also what is the default path for the certificate file?  
Thanks a lot @nchaulet.

---

<div class="post-metadata">

**Author:** ![nchaulet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nchaulet/32/77896_2.png) [@nchaulet](https://discuss.elastic.co/u/nchaulet)\
**Post date:** [October 16, 2023, 6:09pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/12 "2023-10-16T18:09:53Z")

</div>

You should be able specify the path when you install your fleet server with ` --fleet-server-cert=/path/to/fleet-server.crt` and `--fleet-server-cert-key=/path/to/fleet-server.key`

---

<div class="post-metadata">

**Author:** ![DaddyYusk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daddyyusk/32/127617_2.png) [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Post date:** [October 16, 2023, 6:15pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/13 "2023-10-16T18:15:39Z")

</div>

Thanks @nchaulet for the reply!  
But I was meaning how to upgrade the certificate file path after a Fleet server install (in case we want to update it). Like editing elastic-agent.yml for example.

---

<div class="post-metadata">

**Author:** ![DaddyYusk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daddyyusk/32/127617_2.png) [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Post date:** [October 17, 2023, 6:43pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/14 "2023-10-17T18:43:28Z")

</div>

One more question please as I don't find the answer in the doc :

- How to add a SAN (altsubject) in the certificate using ./bin/elasticsearch-certutil ?

---

<div class="post-metadata">

**Author:** ![nchaulet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nchaulet/32/77896_2.png) [@nchaulet](https://discuss.elastic.co/u/nchaulet)\
**Post date:** [October 18, 2023, 12:09pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/15 "2023-10-18T12:09:23Z")

</div>

Hi @DaddyYusk

I think you can use the -ip or -dns flag when using `elasticsearch-certutil cert`

---

<div class="post-metadata">

**Author:** ![DaddyYusk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daddyyusk/32/127617_2.png) [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Post date:** [October 19, 2023, 6:22pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/16 "2023-10-19T18:22:20Z")

</div>

Hi @nchaulet.

Just a quick update about my state and I can confirm that :

- Following your "Configure SSL/TLS for self-managed Fleet Servers" link from scratch and then re-enrolling the Fleet-Server didn't lost my already enrolled Elastic-Agents.
- Overwriting the newly generated certificate (ca.crt) in each Elastic-Agent then restarting it (service) was indeed the way to update the certificate.
- The 2 above statements solved my issue.

But :

- Now in Kibana \> Fleet, the Elastic-Agents are stuck in "Upgrading" state. How to resolve that please?
- Overwriting the certificate (ca.crt) was the way to update the certificate for each Elastic-Agent. But what if I need to also change the path of the certificate? How to proceed please?

Once again thanks a lot for all your advices.  
Regards.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2023, 6:23pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973/17 "2023-11-16T18:23:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
