# HTTP Certificates when CA is a chain

**URL:** <https://discuss.elastic.co/t/http-certificates-when-ca-is-a-chain/362738>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 8, 2024, 8:02pm UTC](https://discuss.elastic.co/t/http-certificates-when-ca-is-a-chain/362738 "2024-07-08T20:02:17Z")\
**Posts on this page:** 1\
**Showing post:** 13

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 15, 2024, 1:10am UTC](https://discuss.elastic.co/t/http-certificates-when-ca-is-a-chain/362738/13 "2024-07-15T01:10:05Z")

</div>

What's in `ca.crt` is it the chain or just the root cert?

What I would normally do in your case is:

1. configure ES to send the whole chain (or at least the leaf & intermediate)
2. configure clients to trust the root only.

Configuring ES to use the chain can be done by concatenating the certificates together and using that chained certificate file for `xpack.security.http.ssl.certificate`  
You can follow the steps here

> [@Unable to verify the first certificate on postman](https://discuss.elastic.co/t/unable-to-verify-the-first-certificate-on-postman/344071/3):
>
> This seems to be the result of two things: Postman doesn't trust the issuing certificate from Let's Encrypt Your ES node is configured to only send the leaf certificate in the SSL handshake The background info is here [Chain of Trust - Let's Encrypt](https://letsencrypt.org/certificates/) Let's encrypt has an offline root cert, and a separate issuing certificate. That's very normal for a CA. But what it means is that, if you: Are using a tool (like Postman, or any other client) that trusts Let's Encrypt's root cert (technica…

---

_[View the full topic](https://discuss.elastic.co/t/http-certificates-when-ca-is-a-chain/362738)._
