# Elasticsearch and Docker Generating http\_ca.crt

**URL:** <https://discuss.elastic.co/t/elasticsearch-and-docker-generating-http-ca-crt/299011>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [March 7, 2022, 8:06pm UTC](https://discuss.elastic.co/t/elasticsearch-and-docker-generating-http-ca-crt/299011 "2022-03-07T20:06:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![SwampyFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/swampyfox/32/89601_2.png) [@SwampyFox](https://discuss.elastic.co/u/SwampyFox)\
**Post date:** [March 7, 2022, 8:06pm UTC](https://discuss.elastic.co/t/elasticsearch-and-docker-generating-http-ca-crt/299011/1 "2022-03-07T20:06:34Z")

</div>

I have followed the instructions on installing Elasticsearch on Docker for version 8.0.1.

I am able to run the curl command against "[https://localhost:9200](https://localhost:9200)" with the http\_ca.crt and the password generated for the elastic user. However, if I replace "localhost" with the IP address of the host, I get the error message "no alternative certificate subject name matches target host name '##.#.###.#".

Is this going to be an issue when I try to connect an Elastic Agent on a separate machine? If so, what changes do I need to make? Or is there additional documentation that I can refer to.

Thank you

Chuck

---

<div class="post-metadata">

**Author:** ![SwampyFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/swampyfox/32/89601_2.png) [@SwampyFox](https://discuss.elastic.co/u/SwampyFox)\
**Post date:** [March 8, 2022, 3:10pm UTC](https://discuss.elastic.co/t/elasticsearch-and-docker-generating-http-ca-crt/299011/2 "2022-03-08T15:10:08Z")

</div>

Bump - Is there a way to control the cert generation, especially the host, when starting Elastic using Docker Run?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 9, 2022, 8:40am UTC](https://discuss.elastic.co/t/elasticsearch-and-docker-generating-http-ca-crt/299011/3 "2022-03-09T08:40:26Z")

</div>

Hi @SwampyFox

You can start your container with

```auto
docker run --name es01 --net elastic -p 9200:9200 -p 9300:9300 -e "http.publish_host=<HOST_IP_HERE>" -it docker.elastic.co/elasticsearch/elasticsearch:8.1.0

```

and we'll put the HOST\_IP in the SANs of the HTTP certificate so that you can use it to connect to it over https

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2022, 8:40am UTC](https://discuss.elastic.co/t/elasticsearch-and-docker-generating-http-ca-crt/299011/4 "2022-04-06T08:40:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
