# Issues with Fleet Server (Elastic Agent Setup) in local Elasticsearch deployment with self signed certificates

**URL:** <https://discuss.elastic.co/t/issues-with-fleet-server-elastic-agent-setup-in-local-elasticsearch-deployment-with-self-signed-certificates/276151>\
**Category:** Beats\
**Tags:** docker, fleet, elastic-agent\
**Created:** [June 16, 2021, 1:37pm UTC](https://discuss.elastic.co/t/issues-with-fleet-server-elastic-agent-setup-in-local-elasticsearch-deployment-with-self-signed-certificates/276151 "2021-06-16T13:37:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![SMT\_Mas](https://avatars.discourse-cdn.com/v4/letter/s/f1d935/32.png) [@SMT\_Mas](https://discuss.elastic.co/u/SMT_Mas)\
**Post date:** [June 16, 2021, 1:37pm UTC](https://discuss.elastic.co/t/issues-with-fleet-server-elastic-agent-setup-in-local-elasticsearch-deployment-with-self-signed-certificates/276151/1 "2021-06-16T13:37:51Z")

</div>

Hello,

I'm trying to install Elastic Agent with a local ELK Environment and have no luck because of Fleet Server issues.

Server Info:

- ELK on version 7.13.1 with self-signed certificates running in Docker containers on x64 Linux
- Host for Elastic Agent does not seem to matter (tried both Windows / Linux)

I'm trying to add Elastic Agent but Fleet Server just produces all kinds off error messages:

First I simply followed the instructions to add an agent in Kibana

1. Download Agent with correct Version for the correct OS
2. Generate token
3. copy and run the command

> sudo ./elastic-agent install -f --fleet-server-es=https://[pc-name]:9200 --fleet-server-service-token=[token]

> [timestamp] INFO cmd/enroll\_cmd.go:300 Generating self-signed certificate for Fleet Server  
> [timestamp] INFO cmd/enroll\_cmd.go:610 Waiting for Elastic Agent to start Fleet Server  
> [timestamp] INFO cmd/enroll\_cmd.go:643 Fleet Server - Starting  
> [timestamp] INFO cmd/enroll\_cmd.go:643 Fleet Server - Error - x509: certificate is not valid for any names, but wanted to match [pc-name]  
> [timestamp] INFO cmd/enroll\_cmd.go:648 Fleet Server - Error - x509: certificate is not valid for any names, but wanted to match [pc-name]  
> [timestamp] INFO cmd/enroll\_cmd.go:643 Fleet Server - Starting

Since there was a certificate issue I tried to add the parameter "--fleet-server-es-ca=[path-to-elasticsearch-root-ca]" but it entered into a loop of crashes/starts/restarts.  
That happened every time I added this parameter to any command.

> [timestamp] INFO cmd/enroll\_cmd.go:300 Generating self-signed certificate for Fleet Server  
> [timestamp] INFO cmd/enroll\_cmd.go:610 Waiting for Elastic Agent to start Fleet Server  
> [timestamp] INFO cmd/enroll\_cmd.go:643 Fleet Server - Restarting  
> [timestamp] INFO cmd/enroll\_cmd.go:648 Fleet Server - Restarting

Just adding "--insecure" which worked on 7.12.1 before we upgraded this setup to 7.13.1 did not work.  
So I created certificates for the client in case that resolved the certificate issue.  
The additional parameters "--fleet-server-cert" and "--fleet-server-cert-key" required the "--url" Parameter and documentation mentioned that I would require the "--fleet-server-insecure-http" Parameter

> sudo ./elastic-agent install -f --fleet-server-es=https://[pc-name]:9200/ --fleet-server-service-token=[token] --insecure --fleet-server-cert=[server.crt] --fleet-server-cert-key=[server.key] --url=https://[pc-name]:9243/ --fleet-server-insecure-http

> [timestamp] INFO cmd/enroll\_cmd.go:643 Fleet Server - Starting  
> [timestamp] INFO cmd/enroll\_cmd.go:643 Fleet Server - Error - x509: certificate is not valid for any names, but wanted to match [pc-name]  
> [timestamp] INFO cmd/enroll\_cmd.go:648 Fleet Server - Error - x509: certificate is not valid for any names, but wanted to match [pc-name]

I tried this with different inputs (localhost as address as recommended as an example) and leaving out the "--fleet-server-insecure-http" parameter without a different result.

I hope somebody can help with this rather frustrating problem.

Both in ES Cloud Deployment in AWS where a Fleet Server is automatically proviced and without certificates I had my first Agents running in less than 5 minutes.

Thanks

edit1: just some formatting changes

---

<div class="post-metadata">

**Author:** ![leprovokateur](https://avatars.discourse-cdn.com/v4/letter/l/8e8cbc/32.png) [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)\
**Post date:** [June 18, 2021, 12:52pm UTC](https://discuss.elastic.co/t/issues-with-fleet-server-elastic-agent-setup-in-local-elasticsearch-deployment-with-self-signed-certificates/276151/2 "2021-06-18T12:52:37Z")

</div>

Hi,

You should create a certificate for whatever [pc-name] is.

Best regards,  
Robert

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2021, 2:52pm UTC](https://discuss.elastic.co/t/issues-with-fleet-server-elastic-agent-setup-in-local-elasticsearch-deployment-with-self-signed-certificates/276151/3 "2021-07-16T14:52:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
