# Fleet agent installation failed: x509 error with --insecure

**URL:** <https://discuss.elastic.co/t/fleet-agent-installation-failed-x509-error-with-insecure/366259>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [September 9, 2024, 4:17pm UTC](https://discuss.elastic.co/t/fleet-agent-installation-failed-x509-error-with-insecure/366259 "2024-09-09T16:17:18Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![kev24](https://avatars.discourse-cdn.com/v4/letter/k/ecd19e/32.png) [@kev24](https://discuss.elastic.co/u/kev24)\
**Post date:** [September 25, 2024, 9:45pm UTC](https://discuss.elastic.co/t/fleet-agent-installation-failed-x509-error-with-insecure/366259/5 "2024-09-25T21:45:06Z")

</div>

Hey! sure thing:

When deploying the ES cluster for the first time I had to extract the fingerprint of the _http_ certificate by executing the following command in any of the members of the cluster:

```auto
openssl x509 -in /usr/share/config/http-certs/ca.crt -sha256 -fingerprint | grep SHA256 | sed 's/://g'

```

The result of this command is the trusted fingerprint that should be configured on the _output_ section of the fleet settings.

After a year, Elasticsearch renewed the certificate, changing this fingerprint, so the agents with the old fingerprint would throw the x509 error.

The solution was basically updating the fingerprint in the fleet configuration, so it would be propagated automatically through the agents.

![image](https://us1.discourse-cdn.com/elastic/original/3X/f/8/f8b7230b9af22a613b3e8d9ddcd702d3bbe7d7e7.png)

I hope this answers on more detail your questions

---

_[View the full topic](https://discuss.elastic.co/t/fleet-agent-installation-failed-x509-error-with-insecure/366259)._
