# Error-Failed version compatibility check with elasticsearch: tls: failed to verify certificate: x509: certificate signed by unknown authority

**URL:** <https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711>\
**Category:** Elastic Agent\
**Created:** [December 20, 2023, 11:24am UTC](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711 "2023-12-20T11:24:59Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Austin1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austin1/32/125287_2.png) [@Austin1](https://discuss.elastic.co/u/Austin1)\
**Post date:** [December 20, 2023, 11:24am UTC](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711/1 "2023-12-20T11:24:59Z")

</div>

Hi all ,  
Please help me with setting up elastic agent container!  
I got below error when I used podman run command followed:

**Error-Failed version compatibility check with elasticsearch: tls: failed to verify certificate: x509: certificate signed by unknown authority**

```auto
podman run --privileged -e FLEET_SERVER_ENABLE=1 -e FLEET_SERVER ELASTICSEARCH_HOST="https://xyz:9200" -e KIBANA_FLEET_HOST="http://xyz:5601/" -e KIBANA_FLEET_USERNAME="elastic" -e KIBANA FLEET PASSWORD="<password>" -e FLEET SERVER SERVICE TOKEN=" **********IUQ==" -e FLEET_SERVER_POLICY_ID=******* -bb19e9cf" -e FLEET_SERVER_ES_CA= "/local/server/path/to/volumes/certs/http_ca.crt" -e INSECURE=true -p 8220:8220 imageID

```

My elasticsearch and kibana are working perfectly accessible at respectively where xyz is name of self hosted server name where I am working.

```auto
https://xyz:9200
http://xyz:5601

```

Below is my elasticsearch.yml

```auto
xpack.security.enabled: true
 
xpack.security.enrollment.enabled: true
 
xpack.security.http.ssl:
      enabled: true
      keystore.path: certs/http.p12
 
#Enable encryption and mutual authentication between cluster nodes
 
xpack.security.transport.ssl:
      enabled: true
      verification mode: certificate
      keystore.path: certs/transport.p12
      truststore.path: certs/transport.p12

```

Following are podman commands to start elasticsearch and kibana

```auto
podman run -e ES_JAVA_OPTS="-Xms4g-Xmx4g" --name kib01 --net host -p 5601:5601 imageID
podman run -e ES_JAVA_OPTS="-Xms4g-Xmx4g" --name kib01 --net host -p 9200:9200 -p 9300:9300 -e "discovery.type=single-node" -it imageID

```

I am using 8.11.1 version images  
For my elasticsearch security is auto enabled (Didn't create any custom certs)  
Can someone please help me with this, I am stuck at this point from past one week.

---

<div class="post-metadata">

**Author:** ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Post date:** [December 22, 2023, 3:18am UTC](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711/2 "2023-12-22T03:18:49Z")

</div>

Is the `-e FLEET_SERVER_ES_CA= "/local/server/path/to/volumes/certs/http_ca.crt"` really available in the Fleet server? I'd double check in the logs what is happening there.

Alternatively, you could try `--fleet-server-es-insecure` when working with a self generated CA (see [Elastic Agent command reference | Fleet and Elastic Agent Guide [8.11] | Elastic](https://www.elastic.co/guide/en/fleet/current/elastic-agent-cmd-options.html) for the background of the command).

---

<div class="post-metadata">

**Author:** ![Austin1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austin1/32/125287_2.png) [@Austin1](https://discuss.elastic.co/u/Austin1)\
**Post date:** [December 22, 2023, 4:10am UTC](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711/3 "2023-12-22T04:10:29Z")

</div>

Hi @xeraa  
Thanks for your reply!  
When I use --fleet-server-es-insecure flag  
I got following:  
Error: Request to get security token from kibana: Not found

---

<div class="post-metadata">

**Author:** ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Post date:** [December 22, 2023, 11:14pm UTC](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711/4 "2023-12-22T23:14:28Z")

</div>

1. Kibana is up and running, right?
2. `-e KIBANA FLEET PASSWORD` looks like it's missing some underscores?

---

<div class="post-metadata">

**Author:** ![Austin1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austin1/32/125287_2.png) [@Austin1](https://discuss.elastic.co/u/Austin1)\
**Post date:** [December 25, 2023, 8:20am UTC](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711/5 "2023-12-25T08:20:27Z")

</div>

Hi @xeraa  
Thanks pointing command mistakes, while pasting the question I have missed those underscores but when I am running on my system underscores are present in the command. Also. my issue for certificate signed by unknown authority got resolved by using following command

```auto
podman run --privileged -e FLEET_SERVER_ENABLE=1 -e ELASTICSEARCH_HOST="https://xyz:9200" -e FLEET_SERVER ELASTICSEARCH_HOST="https://xyz:9200" -e KIBANA_FLEET_HOST="http://xyz:5601/" -e FLEET_SERVER_SERVICE_TOKEN=" **********IUQ==" -e FLEET_SERVER_POLICY_ID= "test1" -e FLEET_SERVER_ELASTICSEARCH_CA_TRUSTED_FINGERPRINT = "******** 129966" -e FLEET_SERVER_HOST="xyz" -e FLEET_SERVER_HOST="8220" -p 8220:8220 -e FLEET_SERVER_INSECURE_HTTP="true" -e KIBANA_FLEET_SETUP='1' -e KIBANA_FLEET_HOST="https://xyz:5601" -e KIBANA_FLEET_USERNAME="elastic" --network=host imageID

```

Now I found a new issue under kibana logs I have following error messages  
1.  
**Error[plugins.fleet]Error connecting to package registry: request to [https://epr.elastic.co/search?kibana.version=8.11.1](https://epr.elastic.co/search?kibana.version=8.11.1) failed, reason: connect ETIMEDOUT xx.xxx.xxx.xxx:xxx**  
2.  
**Error[plugins.fleet]Failed to fetch latest version of fleet\_server from registry: Error connecting to package registry: request to [https://epr.elastic.co/search?package=fleet\_server&prerelease=false&kibana.version=8.11.1](https://epr.elastic.co/search?package=fleet_server&prerelease=false&kibana.version=8.11.1) failed reason: connect ETIMEDOUT xx.xxx.xxx.xxx:xxx**

Also under Elastic agent logs I have following  
**"log.level":"info", "message": "waiting on policy with Fleet server integration":"test1", "component":{"binary":"fleet-server", "dataset":"elastic.agent.fleet\_server", "id":"fleet-server-default", "type":"fleet-server", "log":{"source":"fleet-server-default"}, "service.type":"fleet-server", "state":"STARTING", "ecs.version":"1.6.0", "service.name":"fleet-server", "ecs.version":"1.6.0"}**

I got the above message repeatedly and elasticagent stopped with following message  
**Fleet-server failed: context cancelled**

My idea about this issue:  
I am working on network traffic restricted environment, so I believe I am not able to access the mentioned URL  
there are 2 proposed solutions to work in Air gapped environment

1. Use Proxy server
2. Hosting elastic package registry

I think both these solutions are not possible in my case.  
Can you please help me resolving this or alternate solution?  
Thank you so much for your patience and response!

---

<div class="post-metadata">

**Author:** ![Austin1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austin1/32/125287_2.png) [@Austin1](https://discuss.elastic.co/u/Austin1)\
**Post date:** [December 25, 2023, 8:53am UTC](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711/6 "2023-12-25T08:53:50Z")

</div>

@xeraa please correct me if my understanding is wrong! 🙇‍♂️

---

<div class="post-metadata">

**Author:** ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Post date:** [January 5, 2024, 5:26am UTC](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711/7 "2024-01-05T05:26:41Z")

</div>

You are right on the proxy or hosting your own (as documented in [Air-gapped environments | Fleet and Elastic Agent Guide [8.11] | Elastic](https://www.elastic.co/guide/en/fleet/current/air-gapped.html)). I don't think there is any other way with Agent.

If that is absolutely impossible for your setup, what about falling back to Beats rather than using Fleet? Those shouldn't have that requirement.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2024, 5:27am UTC](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711/8 "2024-02-02T05:27:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
