# Generate xpack SSL certificates with longer expiry date

**URL:** <https://discuss.elastic.co/t/generate-xpack-ssl-certificates-with-longer-expiry-date/323275>\
**Category:** Elasticsearch\
**Created:** [January 16, 2023, 7:50pm UTC](https://discuss.elastic.co/t/generate-xpack-ssl-certificates-with-longer-expiry-date/323275 "2023-01-16T19:50:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![smiley\_tamy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smiley_tamy/32/113375_2.png) [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Post date:** [January 16, 2023, 7:50pm UTC](https://discuss.elastic.co/t/generate-xpack-ssl-certificates-with-longer-expiry-date/323275/1 "2023-01-16T19:50:39Z")

</div>

When we generate SSL certificates with elasticsearch-certutil, we get them with the expiry of 3 years  
Is there a way that we can generate the certificates with longer expiry date such as 5 years or so.  
Is it possible to mention the expiry while creating the certificates

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 16, 2023, 7:53pm UTC](https://discuss.elastic.co/t/generate-xpack-ssl-certificates-with-longer-expiry-date/323275/2 "2023-01-16T19:53:57Z")

</div>

Hi @smiley_tamy

Per the docs [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/certutil.html) us the `days` parameter with certain restrictions.

> `--days <n>`  
> Specifies an integer value that represents the number of days the generated certificates are valid. The default value is `1095`. This parameter cannot be used with the `csr` or `http` parameters.

---

<div class="post-metadata">

**Author:** ![smiley\_tamy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smiley_tamy/32/113375_2.png) [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Post date:** [January 16, 2023, 7:56pm UTC](https://discuss.elastic.co/t/generate-xpack-ssl-certificates-with-longer-expiry-date/323275/3 "2023-01-16T19:56:39Z")

</div>

Thank you for the quick reply 😀

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2023, 7:57pm UTC](https://discuss.elastic.co/t/generate-xpack-ssl-certificates-with-longer-expiry-date/323275/4 "2023-02-13T19:57:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
