# Regarding clarification in ca

**URL:** <https://discuss.elastic.co/t/regarding-clarification-in-ca/359743>\
**Category:** Elasticsearch\
**Created:** [May 18, 2024, 6:26am UTC](https://discuss.elastic.co/t/regarding-clarification-in-ca/359743 "2024-05-18T06:26:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yogesh\_AS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_as/32/131781_2.png) [@Yogesh\_AS](https://discuss.elastic.co/u/Yogesh_AS)\
**Post date:** [May 18, 2024, 6:26am UTC](https://discuss.elastic.co/t/regarding-clarification-in-ca/359743/1 "2024-05-18T06:26:08Z")

</div>

Hi Team,

We are in the process of adding a self-signed certificate to our Elasticsearch or Kibana setup. I have a couple of questions:

1. Without a CA, can I use only the `elastic.crt` and `elastic.key` files?
2. If I have a certificate that is signed by an organization, will it work without adding the CA?

Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 18, 2024, 3:27pm UTC](https://discuss.elastic.co/t/regarding-clarification-in-ca/359743/2 "2024-05-18T15:27:35Z")

</div>

Hi @Yogesh_AS

> 1. Without a CA, can I use only the `elastic.crt` and `elastic.key` files?
> 2. If I have a certificate that is signed by an organization, will it work without adding the CA?

It depends if all your machines have your company CAs installed properly in each machine's trust store then it should work... if not then you will need to provide the CA in the elasticsearch / Kibana and Client configs..

Pretty Easy To Test...

Setup Elastic with the pem/ct and key without setting the CA configs and then try to curl and check for the result

`curl -v -u elastic https://<clusteriporhost>:9200`

---

<div class="post-metadata">

**Author:** ![Yogesh\_AS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_as/32/131781_2.png) [@Yogesh\_AS](https://discuss.elastic.co/u/Yogesh_AS)\
**Post date:** [May 18, 2024, 3:33pm UTC](https://discuss.elastic.co/t/regarding-clarification-in-ca/359743/3 "2024-05-18T15:33:59Z")

</div>

Hi @stephenb ,

Thanks for the clarification 😊

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 18, 2024, 5:22pm UTC](https://discuss.elastic.co/t/regarding-clarification-in-ca/359743/4 "2024-05-18T17:22:49Z")

</div>

In the end Certs are Certs and all the issues that come with them 🙂 ... Elasticsearch Products handle them pretty much like any other app... but that does not mean they are always easy to setup / configure etc..
