# Manage CA certificate in GO and Java APM Agents

**URL:** <https://discuss.elastic.co/t/manage-ca-certificate-in-go-and-java-apm-agents/230394>\
**Category:** APM\
**Tags:** go, java\
**Created:** [April 29, 2020, 2:42pm UTC](https://discuss.elastic.co/t/manage-ca-certificate-in-go-and-java-apm-agents/230394 "2020-04-29T14:42:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![iorfix](https://avatars.discourse-cdn.com/v4/letter/i/9fc348/32.png) [@iorfix](https://discuss.elastic.co/u/iorfix)\
**Post date:** [April 29, 2020, 2:42pm UTC](https://discuss.elastic.co/t/manage-ca-certificate-in-go-and-java-apm-agents/230394/1 "2020-04-29T14:42:53Z")

</div>

Hi there,  
I'm using APM-Server and APM-Agents clients in go and Java.  
I'm moving to use https, but I'm using a private CA to issue server certificates (it is the same CA used for logstash, elastic and beat client authentication).  
I see in Ruby implementation there is a `ELASTIC_APM_SERVER_CA_CERT` param, but this is missing in Java and Go agent impls. There is an `ELASTIC_APM_SERVER_CERT` param, but this is not practical to use, since in our environment there are multiple APMserver nodes.  
In Java I assume I need to put the CA certificate in the Java TrustStore. What is the correct pattern in Go?  
I would avoid to put `ELASTIC_APM_VERIFY_SERVER_CERT` to false

---

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [April 30, 2020, 2:10am UTC](https://discuss.elastic.co/t/manage-ca-certificate-in-go-and-java-apm-agents/230394/2 "2020-04-30T02:10:43Z")

</div>

Yes, in Java you can configure the trust store.

Currently the Go agent does not provide configuration for this. I've opened [https://github.com/elastic/apm-agent-go/issues/752](https://github.com/elastic/apm-agent-go/issues/752) to add it. In the mean time, you could do this in code if you're so inclined:

```auto
package main

import (
        "crypto/x509"
        "io/ioutil"
        "net/http"

        "go.elastic.co/apm"
        "go.elastic.co/apm/transport"
)

func main() {
        apmTransport := apm.DefaultTracer.Transport.(*transport.HTTPTransport)
        httpTransport := apmTransport.Client.Transport.(*http.Transport)

        pem, err := ioutil.ReadFile("/path/to/ca.pem")
        if err != nil {
                // ...
        }
        caCerts := x509.NewCertPool()
        caCerts.AppendCertsFromPEM(pem)
        httpTransport.TLSClientConfig.RootCAs = caCerts
}

```

---

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [April 30, 2020, 2:16am UTC](https://discuss.elastic.co/t/manage-ca-certificate-in-go-and-java-apm-agents/230394/3 "2020-04-30T02:16:04Z")

</div>

One of my colleagues pointed out that on UNIX(-like) systems, you can also set the `SSL_CERT_FILE` environment variable to override the system default location for certs. This would be effectively the same as setting the future `ELASTIC_APM_SERVER_CA_CERT` environment variable.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2020, 10:16pm UTC](https://discuss.elastic.co/t/manage-ca-certificate-in-go-and-java-apm-agents/230394/4 "2020-05-20T22:16:55Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
