# Is there a way to ease installing fleet server to a elasticsearch server secured by self-signed certificate

**URL:** <https://discuss.elastic.co/t/is-there-a-way-to-ease-installing-fleet-server-to-a-elasticsearch-server-secured-by-self-signed-certificate/281583>\
**Category:** Elastic Observability\
**Tags:** fleet\
**Created:** [August 16, 2021, 6:08pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-ease-installing-fleet-server-to-a-elasticsearch-server-secured-by-self-signed-certificate/281583 "2021-08-16T18:08:19Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ZeLAxyz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zelaxyz/32/93228_2.png) [@ZeLAxyz](https://discuss.elastic.co/u/ZeLAxyz)\
**Post date:** [August 16, 2021, 6:08pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-ease-installing-fleet-server-to-a-elasticsearch-server-secured-by-self-signed-certificate/281583/1 "2021-08-16T18:08:19Z")

</div>

Hi,

I just tried installing fleet server to a elasticsearch server secured by self-signed certificate. And I get an error message:

app@fs00:~/elastic-agent-7.14.0-linux-x86\_64$ sudo ./elastic-agent install -f --fleet-server-es=https://10.1.26.70:9200 --fleet-server-service-token=......  
....  
....  
cmd/enroll\_cmd.go:701 Fleet Server - Error - x509: cannot validate certificate for 10.1.26.70 because it doesn't contain any IP SANs

I know a valid certificate is important for production env. But as I just want to do a POC test, is there a way to bypass this validation? For example, set "none" or "certificate" to certain ssl validation settings.

Thanks!

---

<div class="post-metadata">

**Author:** ![BlueNick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluenick/32/93294_2.png) [@BlueNick](https://discuss.elastic.co/u/BlueNick)\
**Post date:** [August 17, 2021, 4:06pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-ease-installing-fleet-server-to-a-elasticsearch-server-secured-by-self-signed-certificate/281583/2 "2021-08-17T16:06:02Z")

</div>

I'm also interested if someone can helps!

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![leprovokateur](https://avatars.discourse-cdn.com/v4/letter/l/8e8cbc/32.png) [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)\
**Post date:** [August 18, 2021, 7:21am UTC](https://discuss.elastic.co/t/is-there-a-way-to-ease-installing-fleet-server-to-a-elasticsearch-server-secured-by-self-signed-certificate/281583/3 "2021-08-18T07:21:12Z")

</div>

Hi there,

Just add --insecure to the command line, see [How to deploy an elastic-agent in fleet against an elasticsearch with a self-signed certificate?](https://discuss.elastic.co/t/how-to-deploy-an-elastic-agent-in-fleet-against-an-elasticsearch-with-a-self-signed-certificate/276575) where I described a further obstacle.

Best regards  
Robert

---

<div class="post-metadata">

**Author:** ![ZeLAxyz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zelaxyz/32/93228_2.png) [@ZeLAxyz](https://discuss.elastic.co/u/ZeLAxyz)\
**Post date:** [August 18, 2021, 3:49pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-ease-installing-fleet-server-to-a-elasticsearch-server-secured-by-self-signed-certificate/281583/4 "2021-08-18T15:49:14Z")

</div>

Thanks for your reply. I have tried --insecure but failed. As I understand, --insecure is used by agent to bypass the verification of the self-signed certs used by fleet server. It does not work for the communication between fleet server and elasticsearch. At least it does not work for the IP based access.

Update: I have seen other post mentioned that --insecure is worked for early versions. For 7.14 it seems does not work.

Best regards,  
Roy

---

<div class="post-metadata">

**Author:** ![blaker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blaker/32/65621_2.png) [@blaker](https://discuss.elastic.co/u/blaker)\
**Post date:** [August 18, 2021, 4:48pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-ease-installing-fleet-server-to-a-elasticsearch-server-secured-by-self-signed-certificate/281583/5 "2021-08-18T16:48:25Z")

</div>

Read the discussion here, it describes how the output settings must be configured in the Fleet settings flyout in Kibana.

> [@7.14 - Windows agent deployed with Fleet, but not sending data](https://discuss.elastic.co/t/7-14-windows-agent-deployed-with-fleet-but-not-sending-data/281347/2):
>
> The issue is that using --insecure only allow Elastic Agent to communicate with Fleet Server insecurely. It still takes the settings from the policy to communicate with Elasticsearch. You need to modify the output settings inside the Fleet UI in Kibana. You will want to add the following in the Elasticsearch output configuration (YAML) block: ssl.verification\_mode: none

---

<div class="post-metadata">

**Author:** ![BlueNick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluenick/32/93294_2.png) [@BlueNick](https://discuss.elastic.co/u/BlueNick)\
**Post date:** [August 19, 2021, 9:00am UTC](https://discuss.elastic.co/t/is-there-a-way-to-ease-installing-fleet-server-to-a-elasticsearch-server-secured-by-self-signed-certificate/281583/6 "2021-08-19T09:00:05Z")

</div>

Thanks for your reply, but this not solve the problem.  
My configuration.

 ![fleet settings](https://us1.discourse-cdn.com/elastic/original/3X/c/a/ca76fb85eed6407ce4ecc2844f0036dbaf5a8528.png)

The command for enrolling

elastic-agent enroll --url=https://_IP of the machine_:9201   
-f   
--fleet-server-es=https://_IP of the machine_:9200   
--fleet-server-service-token= _token_   
--fleet-server-policy=_policy ID_   
--certificate-authorities= _path to CA (of fleet server in pem format)_   
--fleet-server-es-ca=_path to CA (of elasticsearch in pem format)_   
--fleet-server-cert=_path to cert in pem forma_t   
--fleet-server-cert-key=_path to key in pem format_

I've tried also with --insecure flag

But the same error persist `Fleet Server - Error - x509: cannot validate certificate for *machine ip* because it doesn't contain any IP SANs`

---

<div class="post-metadata">

**Author:** ![BlueNick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluenick/32/93294_2.png) [@BlueNick](https://discuss.elastic.co/u/BlueNick)\
**Post date:** [August 20, 2021, 10:33am UTC](https://discuss.elastic.co/t/is-there-a-way-to-ease-installing-fleet-server-to-a-elasticsearch-server-secured-by-self-signed-certificate/281583/7 "2021-08-20T10:33:55Z")

</div>

I've found a solution, the problem is on elasticsearch side.  
When you create a certificate for elasticsearch you must specify a SAN (with IP or DNS record name).  
I've followed this guide for creating a self signed certificate with SAN specified.

[https://andreapavone.com/2021/02/self-signed-ssl-certificate-custom-root-ca/](https://andreapavone.com/2021/02/self-signed-ssl-certificate-custom-root-ca/)

When you create the SAN file configuration you can specify DNS.x or IP.x where x is the number of SAN record

Best regards  
Nick

---

<div class="post-metadata">

**Author:** ![ZeLAxyz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zelaxyz/32/93228_2.png) [@ZeLAxyz](https://discuss.elastic.co/u/ZeLAxyz)\
**Post date:** [August 20, 2021, 12:11pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-ease-installing-fleet-server-to-a-elasticsearch-server-secured-by-self-signed-certificate/281583/8 "2021-08-20T12:11:32Z")

</div>

Hi Nick,  
Thanks for your solution. A well-formed certificate together with customized certificate-authorities would fullfill the requirment of Fleet Server. But the requirement of a valid certificate still exist. And according to my experience, it is more strict than other components of Elastic Stack. The requirment rise the learning curve for fleet and agent.

Best regards  
Roy

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:31am UTC](https://discuss.elastic.co/t/is-there-a-way-to-ease-installing-fleet-server-to-a-elasticsearch-server-secured-by-self-signed-certificate/281583/9 "2022-11-04T08:31:54Z")

</div>


