# How to use DOMAIN NAME for CERTIFICATE, one certificate for entire cluster and adding more nodes without creating a new cert

**URL:** <https://discuss.elastic.co/t/how-to-use-domain-name-for-certificate-one-certificate-for-entire-cluster-and-adding-more-nodes-without-creating-a-new-cert/197892>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 3, 2019, 3:25pm UTC](https://discuss.elastic.co/t/how-to-use-domain-name-for-certificate-one-certificate-for-entire-cluster-and-adding-more-nodes-without-creating-a-new-cert/197892 "2019-09-03T15:25:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mhsh64](https://avatars.discourse-cdn.com/v4/letter/m/d6d6ee/32.png) [@mhsh64](https://discuss.elastic.co/u/mhsh64)\
**Post date:** [September 3, 2019, 3:25pm UTC](https://discuss.elastic.co/t/how-to-use-domain-name-for-certificate-one-certificate-for-entire-cluster-and-adding-more-nodes-without-creating-a-new-cert/197892/1 "2019-09-03T15:25:34Z")

</div>

Hi All,

I want to use one CERTIFICATE for all ES nodes ([es1.srv.com](http://es1.srv.com) ,[es2.srv.com](http://es2.srv.com) , [es3.srv.com](http://es3.srv.com) )as well as KIBANA ([es2.srv.com](http://es2.srv.com)), I created a CSR like bellow:

```
[dn]
C=US
ST=LA
L=TEST
O=SOMETHING
OU=SOMETHING
CN=es2.srv.com
 
[req_ext]
subjectAltName = @alt_names
 
[alt_names]
DNS.1 = srv.com

```

That is working on all of my three nodes Elasticsearch and Kibana, but I get the following error in Kibana that the other two host names are not in alternative names, ( [es1.srv.com](http://es1.srv.com) and [es3.srv.com](http://es3.srv.com) )

I want to use domain name in SAN (alternative name ) to make ES expand-ability easier, in future if I want to add one more to ES cluster, I wont need to create a new certificate.

How can I use Domain name for certificate ?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 9, 2019, 3:03pm UTC](https://discuss.elastic.co/t/how-to-use-domain-name-for-certificate-one-certificate-for-entire-cluster-and-adding-more-nodes-without-creating-a-new-cert/197892/2 "2019-09-09T15:03:47Z")

</div>

> [@mhsh64](#):
>
> I want to use one CERTIFICATE for all ES nodes ([es1.srv.com](http://es1.srv.com) ,[es2.srv.com](http://es2.srv.com) , [es3.srv.com](http://es3.srv.com) )as well as KIBANA ([es2.srv.com](http://es2.srv.com)),

Please keep in mind that this would mean that you need to share the same private key in all your nodes and kibana, and if one get's compromised TLS will be compromised for all.

> [@mhsh64](#):
>
> I created a CSR like bellow:
> 
> ```auto
> [alt_names]
> DNS.1 = srv.com
> 
> ```

This doesn't work exactly like that. Setting `srv.com` as a SAN, doesn't work like a wildcard in itself so this doesn't cover anything under `*.srv.com` . You need to add `*.srv.com` to your alternative names ( assuming your CA allows that, some do and some don't ) .

---

<div class="post-metadata">

**Author:** ![mhsh64](https://avatars.discourse-cdn.com/v4/letter/m/d6d6ee/32.png) [@mhsh64](https://discuss.elastic.co/u/mhsh64)\
**Post date:** [September 9, 2019, 4:55pm UTC](https://discuss.elastic.co/t/how-to-use-domain-name-for-certificate-one-certificate-for-entire-cluster-and-adding-more-nodes-without-creating-a-new-cert/197892/3 "2019-09-09T16:55:48Z")

</div>

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2019, 4:55pm UTC](https://discuss.elastic.co/t/how-to-use-domain-name-for-certificate-one-certificate-for-entire-cluster-and-adding-more-nodes-without-creating-a-new-cert/197892/4 "2019-10-07T16:55:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
