# Fleet server setup documentation incorrect when using quickstart + (elastic with TLS)

**URL:** https://discuss.elastic.co/t/fleet-server-setup-documentation-incorrect-when-using-quickstart-elastic-with-tls/288526
**Category:** Beats
**Tags:** fleet
**Created:** [November 5, 2021, 8:38pm UTC](https://discuss.elastic.co/t/fleet-server-setup-documentation-incorrect-when-using-quickstart-elastic-with-tls/288526 "2021-11-05T20:38:48Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![tfriesen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tfriesen/32/96772_2.png) [@tfriesen](https://discuss.elastic.co/u/tfriesen)
#### Post date: [November 5, 2021, 8:38pm UTC](https://discuss.elastic.co/t/fleet-server-setup-documentation-incorrect-when-using-quickstart-elastic-with-tls/288526/1 "2021-11-05T20:38:48Z")

</div>

The documentation for setting up a fleet server, both the online guide and via the 'Add a fleet server', don't account for a situation where Elasticsearch is configured with TLS, but you want to use Quickstart for setting up a fleet server.

Selecting quickstart generates the following command:

```auto
./elastic-agent install -f --fleet-server-es=http://localhost:9200 --fleet-server-service-token=<redacted> --fleet-server-policy=<redacted>

```

(Note ES URL is http, not https)

This causes the elastic agent setup to fail with the unhelpful:

```auto
2021-11-05T14:48:17.712-0500 INFO cmd/enroll_cmd.go:372 Generating self-signed certificate for Fleet Server
2021-11-05T14:48:20.398-0500 INFO cmd/enroll_cmd.go:724 Fleet Server - Starting
2021-11-05T14:48:21.401-0500 INFO cmd/enroll_cmd.go:724 Fleet Server - Error - EOF
2021-11-05T14:48:27.412-0500 INFO cmd/enroll_cmd.go:729 Fleet Server - Error - EOF
2021-11-05T14:48:31.419-0500 INFO cmd/enroll_cmd.go:724 Fleet Server - Restarting
2021-11-05T14:48:32.420-0500 INFO cmd/enroll_cmd.go:724 Fleet Server - Error - EOF
...
2021-11-05T14:50:17.638-0500 INFO cmd/enroll_cmd.go:729 Fleet Server - Error - EOF
Error: fleet-server never started by elastic-agent daemon: context canceled
For help, please see our troubleshooting guide at https://www.elastic.co/guide/en/fleet/7.15/fleet-troubleshooting.html
Error: enroll command failed with exit code: 1
For help, please see our troubleshooting guide at https://www.elastic.co/guide/en/fleet/7.15/fleet-troubleshooting.html

```

If we specify [https://localhost:9200](https://localhost:9200) , the command fails due to self-signed certificates, which --insecure does not resolve. Specifying:

```auto
./elastic-agent install -f --fleet-server-es=https://localhost:9200 --fleet-server-service-token=... --fleet-server-policy=... --fleet-server-es-ca <path to ES pub cert>

```

Works.

Perhaps it's a bit of a corner case: Self-signed ES TLS certs + quickstart Fleet, but at least a more helpful error message would be nice.

Don't seem to be the only person who's run into this: [Attempting to start Fleet Server fails - #2 by blaker](https://discuss.elastic.co/t/attempting-to-start-fleet-server-fails/282859/2) and [Fleet server agent unable to start- Connection refused - #3 by Psyhil](https://discuss.elastic.co/t/fleet-server-agent-unable-to-start-connection-refused/285818/3)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 3, 2021, 10:39pm UTC](https://discuss.elastic.co/t/fleet-server-setup-documentation-incorrect-when-using-quickstart-elastic-with-tls/288526/2 "2021-12-03T22:39:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
