# Installing Elasticsearch with third party CA certificates

**URL:** <https://discuss.elastic.co/t/installing-elasticsearch-with-third-party-ca-certificates/318440>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 8, 2022, 2:02pm UTC](https://discuss.elastic.co/t/installing-elasticsearch-with-third-party-ca-certificates/318440 "2022-11-08T14:02:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![a.gavric](https://avatars.discourse-cdn.com/v4/letter/a/73ab20/32.png) [@a.gavric](https://discuss.elastic.co/u/a.gavric)\
**Post date:** [November 8, 2022, 2:02pm UTC](https://discuss.elastic.co/t/installing-elasticsearch-with-third-party-ca-certificates/318440/1 "2022-11-08T14:02:52Z")

</div>

Good afternoon, we are planning on deploying Elastic search with third party publicly signed certificates from Lets Encrypt and i have been trying to find a way of replacing the certificates that are provided by the Elasticsearch utility, are there any specific steps required like adding them to the keystore in order to replace the ones generated by the utility with the publicly signed ones?

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [November 9, 2022, 3:39am UTC](https://discuss.elastic.co/t/installing-elasticsearch-with-third-party-ca-certificates/318440/2 "2022-11-09T03:39:57Z")

</div>

TLS can be configured for ES on both the transport interface (node-to-node) and HTTP interface (external client to ES node). Which one do you plan to replace with publicly signed certificates?

We do _not_ recommend using publicly signed certificates for the transport interface because it possibly means anyone else can obtain a cert from the public CA, spin up a node and join your cluster.

If you want to replace the certs used for the HTTP interface, you need to change the relevant settings listed on [this page](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html#security-http-tls-ssl-key-trusted-certificate-settings).

---

<div class="post-metadata">

**Author:** ![a.gavric](https://avatars.discourse-cdn.com/v4/letter/a/73ab20/32.png) [@a.gavric](https://discuss.elastic.co/u/a.gavric)\
**Post date:** [November 9, 2022, 8:27am UTC](https://discuss.elastic.co/t/installing-elasticsearch-with-third-party-ca-certificates/318440/3 "2022-11-09T08:27:42Z")

</div>

Hi Yang, thank you for the information, we did not originally plan to do this, however when we deployed it with the certificates generated by the Elasticsearch certificate utility, and deployed the fleet server in a production setup. however no data was coming in until we set the ssl.verification\_mode: none for output settings, and i am not sure if that is by design or not.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [November 10, 2022, 12:46am UTC](https://discuss.elastic.co/t/installing-elasticsearch-with-third-party-ca-certificates/318440/4 "2022-11-10T00:46:14Z")

</div>

If this is for Fleet server to connect, it is on the HTTP interface which is OK to use certs signed by public CAs.

> however no data was coming in until we set the ssl.verification\_mode: none for output settings, and i am not sure if that is by design or not.

No, it is defintiely _not_ by design. Having `none` as verification mode basically disables TLS which is a high risk. You should fix that as soon as possible. For certificates generated by Elasticsearch certificate utility to work between Fleet-server and Elasticsearch, you need configure the necessary trust. Have you read this [documentation page](https://www.elastic.co/guide/en/fleet/current/secure-connections.html)?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2022, 12:47am UTC](https://discuss.elastic.co/t/installing-elasticsearch-with-third-party-ca-certificates/318440/5 "2022-12-08T00:47:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
