# Kibana shows old/expired Cluster's certificates even though I have updated them

**URL:** <https://discuss.elastic.co/t/kibana-shows-old-expired-clusters-certificates-even-though-i-have-updated-them/326120>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 22, 2023, 5:07am UTC](https://discuss.elastic.co/t/kibana-shows-old-expired-clusters-certificates-even-though-i-have-updated-them/326120 "2023-02-22T05:07:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![raespinoza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raespinoza/32/117551_2.png) [@raespinoza](https://discuss.elastic.co/u/raespinoza)\
**Post date:** [February 22, 2023, 5:07am UTC](https://discuss.elastic.co/t/kibana-shows-old-expired-clusters-certificates-even-though-i-have-updated-them/326120/1 "2023-02-22T05:07:15Z")

</div>

Hi all,

I have updated our cluster's certificates that are about to expire. I followed the steps suggested by the official docs and completed the task with success.....at least that's what I thought.

I generated all new certificates signed by the same CA that I used 3 years ago when I signed the ones that are now expiring . (1 for http and 1 for transport - I know that I can use the same one but wanted to have different ones). After uploading the new certs to all nodes (to the location specified in elasticsearch.yml) and then restarted the cluster....all works fine and it seems to be using the new certs.

However, when I query **GET \_ssl/certificates** from kibana, it shows the new certificates along with the ones that don't exist anymore. What else do I have to do in order to remove them completely from the cluster? I checked all the nodes but couldn't find them at all.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/5/0528d2d63c09ccfa79bb67bf967457000fec1c8e.png)

Thanks,

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 22, 2023, 5:17am UTC](https://discuss.elastic.co/t/kibana-shows-old-expired-clusters-certificates-even-though-i-have-updated-them/326120/2 "2023-02-22T05:17:59Z")

</div>

Welcome to our community! 😃

Can you confirm what page(s) you used from the docs?  
Did you restart the nodes?

---

<div class="post-metadata">

**Author:** ![raespinoza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raespinoza/32/117551_2.png) [@raespinoza](https://discuss.elastic.co/u/raespinoza)\
**Post date:** [February 22, 2023, 5:34am UTC](https://discuss.elastic.co/t/kibana-shows-old-expired-clusters-certificates-even-though-i-have-updated-them/326120/3 "2023-02-22T05:34:34Z")

</div>

Hi, Thanks for the welcome 🙂

I basically followed 2 pages:

> **[Update certificates with the same CA | Elasticsearch Guide \[7.17\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/update-node-certs-same.html)**

> **[Securing Elastic Stack 7.6.1](https://medium.com/@arvirzk/securing-elastic-stack-7-6-1-82d6a2c94fa6)**
>
> Elasticsearch, Kibana, & Filebeat

And yes, I did a full-restart of the whole cluster as a rolling restart didn't work.

BTW cluster uses elasticsearch v7.6.

Regards,

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 22, 2023, 8:09am UTC](https://discuss.elastic.co/t/kibana-shows-old-expired-clusters-certificates-even-though-i-have-updated-them/326120/4 "2023-02-22T08:09:18Z")

</div>

Please note that version is [EOL](https://www.elastic.co/support/eol) and no longer supported, you should be looking to upgrade as a matter of urgency.

Did you restart your nodes?

---

<div class="post-metadata">

**Author:** ![raespinoza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raespinoza/32/117551_2.png) [@raespinoza](https://discuss.elastic.co/u/raespinoza)\
**Post date:** [February 22, 2023, 9:09pm UTC](https://discuss.elastic.co/t/kibana-shows-old-expired-clusters-certificates-even-though-i-have-updated-them/326120/5 "2023-02-22T21:09:01Z")

</div>

Yes we know we have to upgrade soon.  
and yes, I did restart all nodes.

Any idea why the old certificates still show up?  
In our prod cluster, all data nodes and client node are using successfully the new certificates for both: transport and HTTP, so I didn't really understand why there are still records of the old ones.

Is this a bug or something?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2023, 9:09pm UTC](https://discuss.elastic.co/t/kibana-shows-old-expired-clusters-certificates-even-though-i-have-updated-them/326120/6 "2023-03-22T21:09:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
