# Fleet with own artifact registry fails cause of external GPG validation

**URL:** <https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [October 27, 2023, 9:55am UTC](https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904 "2023-10-27T09:55:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![xtruthx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xtruthx/32/10435_2.png) [@xtruthx](https://discuss.elastic.co/u/xtruthx)\
**Post date:** [October 27, 2023, 9:55am UTC](https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904/1 "2023-10-27T09:55:16Z")

</div>

I have in an environment as described here [Air Gapped Env artifacts](https://www.elastic.co/guide/en/fleet/current/air-gapped.html#host-artifact-registry)  
hosted my own artifact registry. This is also cleanly queried during upgrade see log.  
However, a GPG validation is attempted externally. But why? Where can I see more about this what am I missing except the settings in Fleet Management?

Log from elastic agent who acts as fleet-server.

Console Output

```auto
elastic-agent upgrade 8.10.4 --source-uri https://artifcats.mycompany.com:443
Error: Failed trigger upgrade of daemon: failed verification of agent binary: 2 errors occurred:
        * Get "https://artifacts.elastic.co/GPG-KEY-elastic-agent": dial tcp [IPV6]:443: connect: connection timed out
        * Get "https://artifacts.elastic.co/GPG-KEY-elastic-agent": dial tcp [IPV6]:443: connect: connection timed out
For help, please see our troubleshooting guide at https://www.elastic.co/guide/en/fleet/8.9/fleet-troubleshooting.html

```

Fleet-Server log:

```auto
11:14:35.385
elastic_agent
[elastic_agent][info] Upgrading agent
11:14:40.525
elastic_agent
[elastic_agent][info] download from https://artifacts.mycompany.com:443/beats/elastic-agent/elastic-agent-8.10.4-linux-x86_64.tar.gz completed in 5 seconds @ 112.2MBps
11:14:40.526
elastic_agent
[elastic_agent][info] download from https://artifacts.mycompany.com:443/beats/elastic-agent/elastic-agent-8.10.4-linux-x86_64.tar.gz.sha512 completed in Less than a second @ +InfYBps
11:14:41.619
elastic_agent
[elastic_agent][info] Default PGP being appended
11:19:06.685
elastic_agent
[elastic_agent][info] Default PGP being appended

```

I dont get it why this happens there are no explanation about handling signing.

Is this maybe an issue?

---

<div class="post-metadata">

**Author:** ![xtruthx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xtruthx/32/10435_2.png) [@xtruthx](https://discuss.elastic.co/u/xtruthx)\
**Post date:** [October 30, 2023, 6:59am UTC](https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904/3 "2023-10-30T06:59:01Z")

</div>

Even after doing the workaround here as decscribed here [Workaround](https://github.com/elastic/elastic-agent/blob/main/docs/pgp-workaround.md)  
I get a x509 because the certificate is not issued to [artifacts.elastic.co](http://artifacts.elastic.co). Nowhere can I find a setting how to disable the verification. I can't update the agents neither from the command line nor from the Fleet WebUI.

```auto
12:12:42.212
elastic_agent
[elastic_agent][info] Default PGP being appended
12:12:43.316
elastic_agent
[elastic_agent][info] Default PGP being appended
12:12:43.358
elastic_agent
[elastic_agent][error] upgrade to version 8.10.4 failed: failed verification of agent binary: 2 errors occurred:
	* Get "https://artifacts.elastic.co/GPG-KEY-elastic-agent": x509: certificate is valid for artifacts.mycompany.com, not artifacts.elastic.co
	* Get "https://artifacts.elastic.co/GPG-KEY-elastic-agent": x509: certificate is valid for artifacts.mycompany.com, not artifacts.elastic.co

```

how is this supposed to work with a separate artifacts registry?

---

<div class="post-metadata">

**Author:** ![Bearloggs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bearloggs/32/127052_2.png) [@Bearloggs](https://discuss.elastic.co/u/Bearloggs)\
**Post date:** [October 30, 2023, 1:46pm UTC](https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904/4 "2023-10-30T13:46:35Z")

</div>

Seems related to this [issue](https://www.elastic.co/guide/en/fleet/current/release-notes-8.10.0.html#known-issues-8.10.0).

The simplest seems to be to uninstall the agent and reinstall it to version 8.10.3 or higher from scratch.  
I haven't found another solution on my side with same problem.

---

<div class="post-metadata">

**Author:** ![xtruthx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xtruthx/32/10435_2.png) [@xtruthx](https://discuss.elastic.co/u/xtruthx)\
**Post date:** [October 31, 2023, 5:45am UTC](https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904/5 "2023-10-31T05:45:27Z")

</div>

danke für die Antwort. Ich hatte fast befürchtet, dass das so ist. Aber ich kann es fast immer noch nicht glauben. Das wird echt hart, da sind schon eine Elastic Agents ausgerollt.

---

<div class="post-metadata">

**Author:** ![xtruthx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xtruthx/32/10435_2.png) [@xtruthx](https://discuss.elastic.co/u/xtruthx)\
**Post date:** [November 3, 2023, 1:14pm UTC](https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904/6 "2023-11-03T13:14:30Z")

</div>

> [@xtruthx](#):
>
> danke für die Antwort. Ich hatte fast befürchtet, dass das so ist. Aber ich kann es fast immer noch nicht glauben. Das wird echt hart, da sind schon eine Elastic Agents ausgerollt.

Now in English sorry folks!  
Thank you for your answer. I was almost afraid that this was the case. But I still almost can't believe it. It's going to be really hard, there are already some Elastic Agents rolled out.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 3, 2023, 1:51pm UTC](https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904/7 "2023-11-03T13:51:42Z")

</div>

> [@xtruthx](#):
>
> t's going to be really hard, there are already some Elastic Agents rolled out.

Wouldn't the Option 2 described as a Workaround in the issue linked work in your case?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 1, 2023, 1:51pm UTC](https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904/8 "2023-12-01T13:51:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
