# How to generate ssl certificate for new node in existing cluster

**URL:** <https://discuss.elastic.co/t/how-to-generate-ssl-certificate-for-new-node-in-existing-cluster/265689>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 27, 2021, 11:58am UTC](https://discuss.elastic.co/t/how-to-generate-ssl-certificate-for-new-node-in-existing-cluster/265689 "2021-02-27T11:58:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [February 27, 2021, 11:58am UTC](https://discuss.elastic.co/t/how-to-generate-ssl-certificate-for-new-node-in-existing-cluster/265689/1 "2021-02-27T11:58:59Z")

</div>

I have 7 node cluster and now i want to add another node for previous nodes i have

- master\_node1.crt and master\_node1.key
- master\_node2.crt and master\_node2.key
- master\_node3.crt and master\_node3.key
- data\_node1.crt and data\_node1.key
- data\_node2.crt and data\_node2.key
- data\_node3.crt and data\_node3.key
- data\_node4.crt and master\_node4.key
- ca.crt and ca.key

```auto
 bin/elasticsearch-certutil cert --name ew2 --days 7300 --keysize 2048 --pem --ip xx.xx.xx.xx --out /etc/elasticsearch/ew2.zip

```

for new node i have the folllowing configuration..the configuration is same as the previous nodes

```auto

xpack.security.enabled: true
#xpack.security.audit.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.client_authentication: required
xpack.security.transport.ssl.verification_mode: full
xpack.security.transport.ssl.key: certs/ew2/ew2.key
xpack.security.transport.ssl.certificate: certs/ew2/ew2.crt
xpack.security.transport.ssl.certificate_authorities: certs/ca/ca.crt

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.key: certs/ew2/ew2.key
xpack.security.http.ssl.certificate: certs/ew2/ew2.crt
xpack.security.http.ssl.certificate_authorities: certs/ca/ca.crt

```

but i got the warning

```auto
[2021-02-27T17:25:24,375][WARN][o.e.x.c.s.t.n.SecurityNetty4Transport] [em2] client did not trust this server's certificate, closing connection Netty4TcpChannel{localAddress=/master_node_1:9300, remoteAddress=/data_node_4:47046}

```

How can i generate ssl certificate for new node in existing cluster if i have ca.crt and ca.key file ?

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [February 27, 2021, 4:57pm UTC](https://discuss.elastic.co/t/how-to-generate-ssl-certificate-for-new-node-in-existing-cluster/265689/2 "2021-02-27T16:57:37Z")

</div>

I solved it 😀

```auto
bin/elasticsearch-certgen --cert <path_of_ca.crt file> --key <path_of_ca.key file> - --in new_instances.yaml --keysize 2048 --out itest.zip

```

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 28, 2021, 11:56am UTC](https://discuss.elastic.co/t/how-to-generate-ssl-certificate-for-new-node-in-existing-cluster/265689/3 "2021-02-28T11:56:14Z")

</div>

That will work, but certgen is deprecated and is likely to be removed in ES 8.0

What you really want is:

```auto
bin/elasticsearch-certutil cert --ca-cert ca.crt --ca-key ca.key \
    --name ew2 --days 7300 --keysize 2048 --pem --ip xx.xx.xx.xx --out /etc/elasticsearch/ew2.zi
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2021, 11:56am UTC](https://discuss.elastic.co/t/how-to-generate-ssl-certificate-for-new-node-in-existing-cluster/265689/4 "2021-03-28T11:56:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
