# Elastic Agent with Private Certificate Still not working

**URL:** <https://discuss.elastic.co/t/elastic-agent-with-private-certificate-still-not-working/246515>\
**Category:** Elastic Security\
**Tags:** elastic-agent\
**Created:** [August 26, 2020, 9:36pm UTC](https://discuss.elastic.co/t/elastic-agent-with-private-certificate-still-not-working/246515 "2020-08-26T21:36:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![francescouk](https://avatars.discourse-cdn.com/v4/letter/f/7feea3/32.png) [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Post date:** [August 26, 2020, 9:36pm UTC](https://discuss.elastic.co/t/elastic-agent-with-private-certificate-still-not-working/246515/1 "2020-08-26T21:36:35Z")

</div>

Hello there,

I´m now using a private certificate (GoDaddy) and even so, I cannot make it to work.

Bellow I got my ELK stack using the private certificate:

![certificate](https://us1.discourse-cdn.com/elastic/original/3X/e/4/e4bebc58c939d232dec5b8cc69c8f8931e058c50.png)

Bellow I got the first step towards the enrolling:

 ![certificate2](https://us1.discourse-cdn.com/elastic/original/3X/e/3/e3ba2902297c2d33465c0fcdf26c203e2dcd2ef5.png)

Bellow I got the error from the agent trying to comunicate:

 ![certificate3](https://us1.discourse-cdn.com/elastic/original/3X/a/2/a278d622c7f1ec125e5f787d26b12c213572c68b.png)

So my final question is, does the elastic agent really works? Which steps should be made for it work?

---

<div class="post-metadata">

**Author:** ![NickFritts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickfritts/32/47189_2.png) [@NickFritts](https://discuss.elastic.co/u/NickFritts)\
**Post date:** [August 27, 2020, 7:44pm UTC](https://discuss.elastic.co/t/elastic-agent-with-private-certificate-still-not-working/246515/2 "2020-08-27T19:44:59Z")

</div>

Hello @francescouk,

I think you're getting caught up in some issues that are largely summarized here: [https://github.com/elastic/kibana/issues/73483](https://github.com/elastic/kibana/issues/73483)

In the meantime, did you see the follow-up in this post as well? [Elastic Agent not sending Data](https://discuss.elastic.co/t/elastic-agent-not-sending-data/245728/16) Have you been able to make sure that the CA cert is in the trusted roots store for the computer account on your endpoint?

-Nick Fritts

---

<div class="post-metadata">

**Author:** ![francescouk](https://avatars.discourse-cdn.com/v4/letter/f/7feea3/32.png) [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Post date:** [August 28, 2020, 2:31pm UTC](https://discuss.elastic.co/t/elastic-agent-with-private-certificate-still-not-working/246515/3 "2020-08-28T14:31:16Z")

</div>

I did. I´ve done a full reinstall of the ELK stack, created the elastic self certificate and after adding the ca certificate to the root store, I could connect to elasticsearch.

So far, what I´ve seen was, even adding the certificate, in the beggin elasticsearch make the connection but after a while it complaints about the connection as display bellow:

```auto
Caused by: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad_certificate
        at sun.security.ssl.Alert.createSSLException(Alert.java:131) ~[?:?]
        at sun.security.ssl.Alert.createSSLException(Alert.java:117) ~[?:?]
        at sun.security.ssl.TransportContext.fatal(TransportContext.java:312) ~[?:?]
        at sun.security.ssl.Alert$AlertConsumer.consume(Alert.java:293) ~[?:?]
        at sun.security.ssl.TransportContext.dispatch(TransportContext.java:185) ~[?:?]
        at sun.security.ssl.SSLTransport.decode(SSLTransport.java:167) ~[?:?]
        at sun.security.ssl.SSLEngineImpl.decode(SSLEngineImpl.java:729) ~[?:?]
        at sun.security.ssl.SSLEngineImpl.readRecord(SSLEngineImpl.java:684) ~[?:?]
        at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:499) ~[?:?]
        at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:475) ~[?:?]
        at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:634) ~[?:?]

```

I did restart both elastic-agent and elastic endpoint. After restart, the connection has been restored but not for long as image bellow can confirm:

 ![elastic](https://us1.discourse-cdn.com/elastic/original/3X/2/e/2e0c486d9504f45016d693270667279a36b4adc4.png)

---

<div class="post-metadata">

**Author:** ![NickFritts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickfritts/32/47189_2.png) [@NickFritts](https://discuss.elastic.co/u/NickFritts)\
**Post date:** [August 31, 2020, 12:47pm UTC](https://discuss.elastic.co/t/elastic-agent-with-private-certificate-still-not-working/246515/4 "2020-08-31T12:47:06Z")

</div>

Hi @francescouk

Is this still your current status? I saw your post that everything was working in the other thread and thought it was posted after this one.

Could you check the agent and endpoint log files and tell me if there's anything that stands out there? Are you getting data from either agent or endpoint in Elasticsearch?

---

<div class="post-metadata">

**Author:** ![PublicName](https://avatars.discourse-cdn.com/v4/letter/p/74df32/32.png) [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Post date:** [September 2, 2020, 4:57pm UTC](https://discuss.elastic.co/t/elastic-agent-with-private-certificate-still-not-working/246515/5 "2020-09-02T16:57:28Z")

</div>

@francescouk

I ran into the same issue which can be duplicated pretty easy. Just something to poke at can you see if you have both client and server auth in the enhanced key usage part of the certificate. With server only the connection will not be established to kibana but will to elastic partly.

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/2/523013fd72013d33c94b65c5b670a19376fa8011.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:11am UTC](https://discuss.elastic.co/t/elastic-agent-with-private-certificate-still-not-working/246515/6 "2022-11-04T08:11:33Z")

</div>


