# How to deploy an elastic-agent in fleet against an elasticsearch with a self-signed certificate?

**URL:** https://discuss.elastic.co/t/how-to-deploy-an-elastic-agent-in-fleet-against-an-elasticsearch-with-a-self-signed-certificate/276575
**Category:** Beats
**Tags:** fleet
**Created:** [June 21, 2021, 7:31pm UTC](https://discuss.elastic.co/t/how-to-deploy-an-elastic-agent-in-fleet-against-an-elasticsearch-with-a-self-signed-certificate/276575 "2021-06-21T19:31:58Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![leprovokateur](https://avatars.discourse-cdn.com/v4/letter/l/8e8cbc/32.png) [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)
#### Post date: [June 21, 2021, 7:31pm UTC](https://discuss.elastic.co/t/how-to-deploy-an-elastic-agent-in-fleet-against-an-elasticsearch-with-a-self-signed-certificate/276575/1 "2021-06-21T19:31:58Z")

</div>

Hi,

I deployed a fleet server using elastic-agent, which runs fine.

For the deployment of an elastic-agent I use --insecure, because the fleet server, Kibana, and elasticsearch use a self-signed certificate.

I get a connection to the fleet server, but not to the elasticsearch, because filebeat and metricbeat don't want to connect.

If a add ssl.certificate\_authorities: /etc/elasticsearch-ca.pem to the state.yml file, I get a connection, but is there another, more elegant way doing this?

On Windows this file does not exist, what would I do there?

Best regards,  
Robert

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 19, 2021, 7:32pm UTC](https://discuss.elastic.co/t/how-to-deploy-an-elastic-agent-in-fleet-against-an-elasticsearch-with-a-self-signed-certificate/276575/2 "2021-07-19T19:32:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
