Hi Julia,
Also, do you have anything other than the certificate itself in this file --fleet-server-cert=/etc/elasticsearch/certs/fleet-server/fleet-server.crt ?
Answer to this question.
Not it is single certificate. See below with some redaction.
more /etc/elasticsearch/certs/fleet-server/fleet-server.crt
-----BEGIN CERTIFICATE-----
MIIDVTCCAj2gAwIBAgIURGvzoTRoxyxUjfJ9HZ9fk7HWMhwwDQYJKoZIhvcNAQEL
XXXXXX - Lots taken out
6wPJO4KHweGUgme3awNILzch6o77H0taYOqep95MovO1Am9X41ideoo=
-----END CERTIFICATE-----
A decode of the certificate is below.
{
    "name": "\/CN=fleet-server",
    "subject": {
        "CN": "fleet-server"
    },
    "hash": "f0450f6b",
    "issuer": {
        "CN": "Elastic Certificate Tool Autogenerated CA"
    },
    "version": 2,
    "serialNumber": "0x446BF3A13468C72C548DF27D1D9F5F93B1D6321C",
    "serialNumberHex": "446BF3A13468C72C548DF27D1D9F5F93B1D6321C",
    "validFrom": "240312145458Z",
    "validTo": "270312145458Z",
    "validFrom_time_t": 1710255298,
    "validTo_time_t": 1804863298,
    "signatureTypeSN": "RSA-SHA256",
    "signatureTypeLN": "sha256WithRSAEncryption",
    "signatureTypeNID": 668,
    "purposes": {
        "1": [
            true,
            false,
            "sslclient"
        ],
        "2": [
            true,
            false,
            "sslserver"
        ],
        "3": [
            true,
            false,
            "nssslserver"
        ],
        "4": [
            true,
            false,
            "smimesign"
        ],
        "5": [
            true,
            false,
            "smimeencrypt"
        ],
        "6": [
            true,
            false,
            "crlsign"
        ],
        "7": [
            true,
            true,
            "any"
        ],
        "8": [
            true,
            false,
            "ocsphelper"
        ],
        "9": [
            false,
            false,
            "timestampsign"
        ]
    },
    "extensions": {
        "subjectKeyIdentifier": "2D:06:29:4C:AE:F8:E2:88:C8:0C:EC:CB:88:A2:EB:EC:B3:53:A4:FB",
        "authorityKeyIdentifier": "keyid:8D:BC:CE:07:AD:3A:AA:66:7E:9C:42:C0:66:3D:BC:76:F2:C8:5B:3B\n",
        "subjectAltName": "DNS:rhoslog01.agriculture.gov.ie, IP Address:10.2.134.121",
        "basicConstraints": "CA:FALSE"
    }
}
Best Regards,
Kevin.