# Recreate the automatically generated certificates

**URL:** <https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987>\
**Category:** Elasticsearch\
**Created:** [January 12, 2024, 8:15pm UTC](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987 "2024-01-12T20:15:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pxeedust](https://avatars.discourse-cdn.com/v4/letter/p/3da27b/32.png) [@pxeedust](https://discuss.elastic.co/u/pxeedust)\
**Post date:** [January 12, 2024, 8:15pm UTC](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987/1 "2024-01-12T20:15:42Z")

</div>

Sorry for the beginner question, but I am having trouble regenerating the certificates that were made at deployment. I'm not familiar with how certificates work so I was hoping there might be a script that just regenerates them? I changed the ip of my elasticsearch server and the certificate was apparently bound to the initial ips. I prematurely deleted the certs inside the /config/certs directory and now I'm stuck. Anyone know how I can fix this without a full reinstall?

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 12, 2024, 9:48pm UTC](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987/2 "2024-01-12T21:48:49Z")

</div>

Hi,

Regenerating certificates for Elasticsearch can be done using the Elasticsearch certutil tool.

> **[elasticsearch-certutil | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/certutil.html#certutil)**

Regards

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 12, 2024, 10:25pm UTC](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987/3 "2024-01-12T22:25:55Z")

</div>

The basic steps are

Create CA

```auto
./bin/elasticsearch-certutil ca

```

Create Transport Certs

```auto
./bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12

```

Create http certs

```auto
./bin/elasticsearch-certutil http

```

Move all the certs to the correct directories and make sure they are readable.

Detailed Steps are [Here](https://www.elastic.co/guide/en/elasticsearch/reference/current/manually-configure-security.html) as well

And i have some examples [here](https://github.com/bvader/howtos/tree/master/basic-security-elasticsearch-targz)...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2024, 10:26pm UTC](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987/4 "2024-02-09T22:26:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
