# Is it preferable to use publicly signed certificates for fleet server?

**URL:** <https://discuss.elastic.co/t/is-it-preferable-to-use-publicly-signed-certificates-for-fleet-server/332732>\
**Category:** Elastic Observability\
**Created:** [May 6, 2023, 11:13pm UTC](https://discuss.elastic.co/t/is-it-preferable-to-use-publicly-signed-certificates-for-fleet-server/332732 "2023-05-06T23:13:16Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [May 9, 2023, 7:02pm UTC](https://discuss.elastic.co/t/is-it-preferable-to-use-publicly-signed-certificates-for-fleet-server/332732/4 "2023-05-09T19:02:27Z")

</div>

Thanks Julia! This was a question that I posted earlier and it was answered by a few people:

> [@How to prevent other nodes from joining my cluster?](https://discuss.elastic.co/t/how-to-prevent-other-nodes-from-joining-my-cluster/326096):
>
> How can I prevent other elasticsearch nodes from joining my cluster. Let's say I initiate a single node elastic cluster like this: (Notice I am using letsencrypt ssl certificates) cluster.initial\_master\_nodes: ["node1"] cluster.name: my-application node.name: node1 path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch network.host: node1.example.com http.port: 9200 xpack.security.enabled: true xpack.security.enrollment.enabled: true xpack.security.http.ssl: enabled: true key…

I wasn't sure if similar situation would happen with elastic agents and fleet servers?

If the certs were by signed by a public CA, would that cause any concerns for ES nodes/agents?

---

_[View the full topic](https://discuss.elastic.co/t/is-it-preferable-to-use-publicly-signed-certificates-for-fleet-server/332732)._
