# How do I renew my elasticsearch self signed certificate which will not have impact on logstash vms

**URL:** https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096
**Category:** Elasticsearch
**Tags:** elastic-stack-security
**Created:** [April 24, 2024, 7:30am UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096 "2024-04-24T07:30:25Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![sudhir\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sudhir_singh/32/104889_2.png) [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)
#### Post date: [April 24, 2024, 7:30am UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096/1 "2024-04-24T07:30:25Z")

</div>

Hi Everyone. My elasticsearch self signed certificate is about to expire and I have More than thousands of logstash vms which I'm using for logstash data ingestion to elasticsearch and I'm using the elasticsearch credentials. It is not feasible to change the credentials in logstash configuration if I change the certificates. Please help me through it. What else can be done here.

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [April 24, 2024, 10:28am UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096/2 "2024-04-24T10:28:09Z")

</div>

You need to provide more details.

We don't know what your current configuration looks like, so we really aren't going to be able to offer you good advice about the steps you can take.

---

<div class="post-metadata">

### Author: ![sudhir\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sudhir_singh/32/104889_2.png) [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)
#### Post date: [April 24, 2024, 11:26am UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096/3 "2024-04-24T11:26:59Z")

</div>

This is what my elasticsearch.yml looks like

```auto
http.cors.enabled: true

#discovery.zen.ping_timeout: 100s
#discovery.zen.fd.ping_timeout: 100s
#cluster.max_shards_per_node: 2000

node.master: false
node.data: true

xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

```

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [April 24, 2024, 1:13pm UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096/4 "2024-04-24T13:13:14Z")

</div>

You also need to share an example of your logstash output.

Are you going to change the CA as well?

---

<div class="post-metadata">

### Author: ![sudhir\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sudhir_singh/32/104889_2.png) [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)
#### Post date: [April 25, 2024, 10:15am UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096/5 "2024-04-25T10:15:33Z")

</div>

```auto
output {
  elasticsearch {
        hosts => ["https://xyz.newyorktimes.in:443"]
        index => "timesjobs-%{+YYYY.MM.dd}"
        user => "logstash"
        password => "${ES_PWD}"
        ssl_certificate_verification => true
        cacert => "/etc/logstash/conf.d/star.timesinternet.in.pem"
        }
     }

```

This is my logstash config to push data into ES. Can you please help me with any idea without changing CA if I can extend the certificate expiry or generate new one so i don't have to touch logstash config.

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [April 25, 2024, 12:46pm UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096/6 "2024-04-25T12:46:07Z")

</div>

> [@sudhir\_singh](#):
>
> Can you please help me with any idea without changing CA if I can extend the certificate expiry or generate new one so i don't have to touch logstash config.

It really depends how you generate it, this is mostly unrelated to Elasticsearch or Logstash.

Is your CA expiring as well? If your CA is not expiring as well you can just generate new certificates to your Elasticsearch cluster and change them, it will not require any changes to logstash as you just specify the CA in logstash.

But if your CA is expiring as well, then there is not much you can do, you will need to change your configurations to use the new CA.

Or at least replace the CA file with the new one and restart the instances.

---

<div class="post-metadata">

### Author: ![sudhir\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sudhir_singh/32/104889_2.png) [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)
#### Post date: [April 26, 2024, 7:25am UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096/7 "2024-04-26T07:25:47Z")

</div>

Below command I used in dev tools

```auto
GET _ssl/certificates

```

And this returned the below result

```auto
[
  {
    "path" : "elastic-certificates.p12",
    "format" : "PKCS12",
    "alias" : "instance",
    "subject_dn" : "CN=Elastic Certificate Tool Autogenerated CA",
    "serial_number" : "dccaddtfasgyd2ssjnhu3djjse104cb0fce547f",
    "has_private_key" : false,
    "expiry" : "2024-07-04T09:31:38.000Z"
  },
  {
    "path" : "elastic-certificates.p12",
    "format" : "PKCS12",
    "alias" : "ca",
    "subject_dn" : "CN=Elastic Certificate Tool Autogenerated CA",
    "serial_number" : "dccaddtfasgyd2ssjnhu3djjse104cb0fce547f",
    "has_private_key" : false,
    "expiry" : "2024-07-04T09:31:38.000Z"
  },
  {
    "path" : "elastic-certificates.p12",
    "format" : "PKCS12",
    "alias" : "instance",
    "subject_dn" : "CN=instance",
    "serial_number" : "dccaddtfasgyd2ssjnhu3djjse104cb0fce547f",
    "has_private_key" : true,
    "expiry" : "2024-07-04T09:31:39.000Z"
  }
]

```

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [April 26, 2024, 12:38pm UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096/8 "2024-04-26T12:38:09Z")

</div>

> [@sudhir\_singh](#):
>
> ```auto
> {
> "path" : "elastic-certificates.p12",
> "format" : "PKCS12",
> "alias" : "ca",
> "subject_dn" : "CN=Elastic Certificate Tool Autogenerated CA",
> "serial_number" : "dccaddtfasgyd2ssjnhu3djjse104cb0fce547f",
> "has_private_key" : false,
> "expiry" : "2024-07-04T09:31:38.000Z"
> }
> 
> ```

Your CA is expiring as well, you will need to change the CA file used in **all** logstash outputs you have, this file `cacert => "/etc/logstash/conf.d/star.timesinternet.in.pem"`, there is no other way.

What you can done to have less impact is change _all_ your outputs to not validate the certificate, this way you can change your certificate in Elasticsearch and Logstash will ignore the certificate so it will keep sending data,

Then you can change the certificate file in logstash and fix this settings.

---

<div class="post-metadata">

### Author: ![sudhir\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sudhir_singh/32/104889_2.png) [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)
#### Post date: [April 29, 2024, 12:03pm UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096/9 "2024-04-29T12:03:13Z")

</div>

Basically you're asking me to do below thing in my logstash output:

```auto
ssl_certificate_verification => false

```

But when I will generate another certificate I will again have to provide the new credentials or it can be without credentials ?

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [April 29, 2024, 12:24pm UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096/10 "2024-04-29T12:24:15Z")

</div>

> [@sudhir\_singh](#):
>
> `ssl_certificate_verification => false`

Yeah, this is a temporarily solution to try to minimize the impact as you need to replace the CA.

> [@sudhir\_singh](#):
>
> But when I will generate another certificate I will again have to provide the new credentials or it can be without credentials ?

After you created the new CA and changed it in Elasticsearch you can then enable verification again in Logstash.

---

<div class="post-metadata">

### Author: ![sudhir\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sudhir_singh/32/104889_2.png) [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)
#### Post date: [May 10, 2024, 6:04am UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096/11 "2024-05-10T06:04:47Z")

</div>

> [@leandrojmp](#):
>
> /etc/logstash/conf.d/star.timesinternet.in.pem

The thing is I can renew the below ssl but is there any way to extend my CA expiry.

```auto
/etc/logstash/conf.d/star.timesinternet.in.pem

```
