# Fleet Server - Error - x509: certificate is valid for 127.0.0.1, not x.x.x.x

**URL:** <https://discuss.elastic.co/t/fleet-server-error-x509-certificate-is-valid-for-127-0-0-1-not-x-x-x-x/305226>\
**Category:** Elastic Security\
**Tags:** elastic-stack-security, fleet\
**Created:** [May 19, 2022, 7:16pm UTC](https://discuss.elastic.co/t/fleet-server-error-x509-certificate-is-valid-for-127-0-0-1-not-x-x-x-x/305226 "2022-05-19T19:16:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Carlos\_Vinicius](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_vinicius/32/95016_2.png) [@Carlos\_Vinicius](https://discuss.elastic.co/u/Carlos_Vinicius)\
**Post date:** [May 19, 2022, 7:16pm UTC](https://discuss.elastic.co/t/fleet-server-error-x509-certificate-is-valid-for-127-0-0-1-not-x-x-x-x/305226/1 "2022-05-19T19:16:49Z")

</div>

Dear, good afternoon!

I would like to ask for your support to solve a problem that I have been facing in the configuration of a fleet server in self mode, I created the CA, my Elasticsearch responds to HTTPS, I created a certificate following the procedure that is on the website [https://www](https://www). [Encrypt traffic in a self-managed cluster | Fleet and Elastic Agent Guide [7.14] | Elastic](http://elastic.co/guide/en/fleet/7.14/secure-connections.html)

but the error below occurs

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/7/27c409a554f3b75bb24f9b9b04344b6dcd5df26a.png)

Fleet Server - Error - x509: certificate is valid for 127.0.0.1, not 192.168.50.71

kibana configuration

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9a451f321803e53ca40280736b031e37f1756258.png)

command i used

sudo elastic-agent enroll --url=https://192.168.50.7:8220 \

-f \

--fleet-server-es=https://192.168.50.71:9200 \

--fleet-server-service-token=xxxxxxxxxxxx   
--fleet-server-policy=xxxxxxxxxxxxxxxx  
--certificate-authorities=/etc/ssl/certs/Elasticsearch/ca.crt   
--fleet-server-es-ca=/etc/ssl/certs/Elasticsearch/Elasticsearch.crt   
--fleet-server-cert=/etc/ssl/certs/Elasticsearch/fleet-server/fleet-server.crt   
--fleet-server-cert-key=/etc/ssl/certs/Elasticsearch/fleet-server/fleet-server.key

---

<div class="post-metadata">

**Author:** ![MichelLaterman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michellaterman/32/110221_2.png) [@MichelLaterman](https://discuss.elastic.co/u/MichelLaterman)\
**Post date:** [May 30, 2022, 5:09pm UTC](https://discuss.elastic.co/t/fleet-server-error-x509-certificate-is-valid-for-127-0-0-1-not-x-x-x-x/305226/2 "2022-05-30T17:09:57Z")

</div>

HI Carlos,

As the error message indicated the certificate that you created has been set for the localhost address (`127.0.0.1`), and not for the IP address that other machines will contact it by (`192.168.50.71`). You'll need to create a new certificate with the correct IP address.

---

<div class="post-metadata">

**Author:** ![Carlos\_Vinicius](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_vinicius/32/95016_2.png) [@Carlos\_Vinicius](https://discuss.elastic.co/u/Carlos_Vinicius)\
**Post date:** [May 30, 2022, 5:23pm UTC](https://discuss.elastic.co/t/fleet-server-error-x509-certificate-is-valid-for-127-0-0-1-not-x-x-x-x/305226/3 "2022-05-30T17:23:14Z")

</div>

Thank you very much for the answer, do I create a certificate using openssl?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2022, 5:24pm UTC](https://discuss.elastic.co/t/fleet-server-error-x509-certificate-is-valid-for-127-0-0-1-not-x-x-x-x/305226/4 "2022-06-27T17:24:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
