# Fleet Server x509 Error (GODEBUG=x509ignoreCN=0)

**URL:** <https://discuss.elastic.co/t/fleet-server-x509-error-godebug-x509ignorecn-0/281427>\
**Category:** Beats\
**Tags:** fleet, elastic-agent\
**Created:** [August 14, 2021, 6:07am UTC](https://discuss.elastic.co/t/fleet-server-x509-error-godebug-x509ignorecn-0/281427 "2021-08-14T06:07:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![morgan.atwood](https://avatars.discourse-cdn.com/v4/letter/m/bcef8e/32.png) [@morgan.atwood](https://discuss.elastic.co/u/morgan.atwood)\
**Post date:** [August 14, 2021, 6:07am UTC](https://discuss.elastic.co/t/fleet-server-x509-error-godebug-x509ignorecn-0/281427/1 "2021-08-14T06:07:04Z")

</div>

Greeting,

Running into a problem with setting up the Fleet server.

I have a standalone development server running Kibana, Elasticsearch, and Elastic-agent. Very excited to try out the new agent and security features in 7.14! 😁

When trying to setup the fleet server I run into an error with the certificate being used. Below is command I'm running

```auto
sudo elastic-agent enroll --url=https://elastic:8220 \
 -f \
 --fleet-server-es=https://elastic:9200 \
 --fleet-server-service-token=AAEAAWVsYXN0aWMvZmxlZXQtc2VydmVyL3Rva2VuLTE2Mjg5MTM1MDYwODY6VFM4N3RvZmlUb3FibkM4ektmQkx3dw \
  --fleet-server-policy=7c276ea0-fc59-11eb-811b-21110687356f \
  --certificate-authorities=/etc/elastic-agent/certs/ca/fleet-server-ca.crt \
  --fleet-server-es-ca=/etc/elastic-agent/certs/fleet-server.crt \
  --fleet-server-cert=/etc/elastic-agent/certs/fleet-server.crt \
  --fleet-server-cert-key=/etc/elastic-agent/certs/fleet-server.key

```

Error message below

> 2021-08-14T05:40:33.300Z INFO cmd/enroll\_cmd.go:526 Spawning Elastic Agent daemon as a subprocess to complete bootstrap process.
> 
> 2021-08-14T05:40:33.435Z INFO application/application.go:66 Detecting execution mode
> 
> 2021-08-14T05:40:33.435Z INFO application/application.go:87 Agent is in Fleet Server bootstrap mode
> 
> 2021-08-14T05:40:33.588Z INFO [api] api/server.go:62 Starting stats endpoint
> 
> 2021-08-14T05:40:33.588Z INFO application/fleet\_server\_bootstrap.go:124 Agent is starting
> 
> 2021-08-14T05:40:33.588Z INFO [api] api/server.go:64 Metrics endpoint listening on: /var/lib/elastic-agent/data/tmp/elastic-agent.sock (configured: unix:///var/lib/elastic-agent/data/tmp/elastic-agent.sock)
> 
> 2021-08-14T05:40:33.588Z INFO application/fleet\_server\_bootstrap.go:134 Agent is stopped
> 
> 2021-08-14T05:40:33.590Z INFO stateresolver/stateresolver.go:48 New State ID is 6ljz3EMv
> 
> 2021-08-14T05:40:33.590Z INFO stateresolver/stateresolver.go:49 Converging state requires execution of 1 step(s)
> 
> 2021-08-14T05:40:33.619Z INFO operation/operator.go:259 operation 'operation-install' skipped for fleet-server.7.14.0
> 
> 2021-08-14T05:40:33.731Z INFO log/reporter.go:40 2021-08-14T05:40:33Z - message: Application: fleet-server--7.14.0: State changed to STARTING: Starting - type: 'STATE' - sub\_type: 'STARTING'
> 
> 2021-08-14T05:40:33.732Z INFO stateresolver/stateresolver.go:66 Updating internal state
> 
> 2021-08-14T05:40:34.303Z INFO cmd/enroll\_cmd.go:701 Fleet Server - Starting
> 
> 2021-08-14T05:40:34.750Z ERROR status/reporter.go:236 Elastic Agent status changed to: 'error'
> 
> 2021-08-14T05:40:34.750Z ERROR log/reporter.go:36 2021-08-14T05:40:34Z - message: Application: fleet-server--7.14.0: State changed to FAILED: Error - x509: certificate relies on legacy Common Name field, use SANs or temporarily enable Common Name matching with GODEBUG=x509ignoreCN=0 - type: 'ERROR' - sub\_type: 'FAILED'
> 
> 2021-08-14T05:40:35.304Z INFO cmd/enroll\_cmd.go:701 Fleet Server - Error - x509: certificate relies on legacy Common Name field, use SANs or temporarily enable Common Name matching with GODEBUG=x509ignoreCN=0
> 
> Error: fleet-server never started by elastic-agent daemon: context cancel

Below is the how I'm generating the certs. I am providing SANs to the cert so this is kinda where I'm confused.

```auto
cat > fleet.cnf <<EOF
[req]
distinguished_name = req_distinguished_name
req_extensions = req_ext
prompt = no
[req_distinguished_name]
C = US
ST = NY
L = New York City
O = Dev
OU = SIEM
[req_ext]
subjectAltName = @alt_names
[alt_names]
IP.1 = 127.0.0.1
IP.2 = 172.31.4.162
DNS.1 = elastic
DNS.2 = kibana1
EOF

openssl genrsa -out fleet-server-ca.key 2048

openssl req -new -x509 -days 365 -key fleet-server-ca.key -subj "/C=US/ST=NY/L=New York City/O=dev/CN=Fleet-Server-CA" -out fleet-server-ca.crt

openssl req -newkey rsa:2048 -nodes -keyout fleet-server.key -config fleet.cnf -out fleet-server.csr

openssl x509 -req -days 365 -in fleet-server.csr -CA fleet-server-ca.crt -CAkey fleet-server-ca.key -CAcreateserial -out fleet-server.crt

```

To note I did add the fleet-ca cert to my elasticsearch cert authorites  
`xpack.security.http.ssl.certificate_authorities: ["/etc/elasticsearch/certs/ca/elastic-stack-ca.crt","/etc/elasticsearch/certs/ca/fleet-server-ca.crt"]`

I also I did follow the fleet secure connection documentation, but it lead to the same outcome. [Encrypt traffic in a self-managed cluster | Fleet and Elastic Agent Guide [7.14] | Elastic](https://www.elastic.co/guide/en/fleet/7.14/secure-connections.html)

Any help or suggestion is highly appreciated!

Thanks in advance,  
Morgan

---

<div class="post-metadata">

**Author:** ![blaker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blaker/32/65621_2.png) [@blaker](https://discuss.elastic.co/u/blaker)\
**Post date:** [August 17, 2021, 6:46pm UTC](https://discuss.elastic.co/t/fleet-server-x509-error-godebug-x509ignorecn-0/281427/2 "2021-08-17T18:46:52Z")

</div>

> [@morgan.atwood](#):
>
> `--fleet-server-es-ca=/etc/elastic-agent/certs/fleet-server.crt`

That should be the CA used to communicate and verify the elasticsearch certificate not the Fleet Server certificate. Are you sure you that is the correct file for that?

---

<div class="post-metadata">

**Author:** ![morgan.atwood](https://avatars.discourse-cdn.com/v4/letter/m/bcef8e/32.png) [@morgan.atwood](https://discuss.elastic.co/u/morgan.atwood)\
**Post date:** [August 17, 2021, 11:47pm UTC](https://discuss.elastic.co/t/fleet-server-x509-error-godebug-x509ignorecn-0/281427/3 "2021-08-17T23:47:58Z")

</div>

Hey Blake,  
I should have commented earlier but I did notice that and switched it but it didn't work.

However I did find the solution to being to regenerate all the certs as a .p12 first through the elasticsearch-certutil tool

Thanks for the reply!

---

<div class="post-metadata">

**Author:** ![blaker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blaker/32/65621_2.png) [@blaker](https://discuss.elastic.co/u/blaker)\
**Post date:** [August 18, 2021, 12:57pm UTC](https://discuss.elastic.co/t/fleet-server-x509-error-godebug-x509ignorecn-0/281427/4 "2021-08-18T12:57:33Z")

</div>

@morgan.atwood So you have it working?

---

<div class="post-metadata">

**Author:** ![morgan.atwood](https://avatars.discourse-cdn.com/v4/letter/m/bcef8e/32.png) [@morgan.atwood](https://discuss.elastic.co/u/morgan.atwood)\
**Post date:** [August 30, 2021, 3:01pm UTC](https://discuss.elastic.co/t/fleet-server-x509-error-godebug-x509ignorecn-0/281427/5 "2021-08-30T15:01:53Z")

</div>

Yes I do, thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2021, 5:01pm UTC](https://discuss.elastic.co/t/fleet-server-x509-error-godebug-x509ignorecn-0/281427/6 "2021-09-27T17:01:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
