# Regenerate the SSL Certificate that was auto-generated on setup of ElasticSearch

**URL:** <https://discuss.elastic.co/t/regenerate-the-ssl-certificate-that-was-auto-generated-on-setup-of-elasticsearch/377216>\
**Category:** Elastic Search\
**Created:** [April 16, 2025, 5:22pm UTC](https://discuss.elastic.co/t/regenerate-the-ssl-certificate-that-was-auto-generated-on-setup-of-elasticsearch/377216 "2025-04-16T17:22:56Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![frdh-samuelw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frdh-samuelw/32/142676_2.png) [@frdh-samuelw](https://discuss.elastic.co/u/frdh-samuelw)\
**Post date:** [April 16, 2025, 5:22pm UTC](https://discuss.elastic.co/t/regenerate-the-ssl-certificate-that-was-auto-generated-on-setup-of-elasticsearch/377216/1 "2025-04-16T17:22:56Z")

</div>

Hello!

We have been using Elasticsearch with Zammad on an Ubuntu server for several months, and we recently moved the server to a new IP address. Because Elasticsearch was set up with the former IP address, the auto-generated SSL Certificate, "/etc/elasticsearch/certs/http\_ca.crt", is not working with the new IP address. Specifically, it gives an error that the IP address does not match the one in the certificate.

We were wondering if there was a command to use that would regenerate this SSL Certificate based on the current IP settings? I tried using the

`bin/elasticsearch-certutil`

command but when I do that it says that there is "no such file or directory". I am unable to use that command, and based on my reading of the webpage:

> **[elasticsearch-certutil | Elastic Documentation](https://www.elastic.co/docs/reference/elasticsearch/command-line-tools/certutil#certutil)**
>
> The elasticsearch-certutil command simplifies the creation of certificates for use with Transport Layer Security (TLS) in the Elastic Stack. You can specify...

I do not know if that would solve our issue as we are not trying to create a new Certificate Authority or a whole new set of certificates and keys, just the one that was generated on setup.

Please let me know if there is any more information that you would need to get a better idea of our situation, and thank you in advance for your help.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 16, 2025, 5:29pm UTC](https://discuss.elastic.co/t/regenerate-the-ssl-certificate-that-was-auto-generated-on-setup-of-elasticsearch/377216/2 "2025-04-16T17:29:16Z")

</div>

Hi @frdh-samuelw

Seems a lot like this post

> [@Are the Self Signed Certs bound by IP / Hostname](https://discuss.elastic.co/t/are-the-self-signed-certs-bound-by-ip-hostname/377147/1):
>
> Hi, We have a cluster in which we have enabled TLS security. To enable the security we used the elastic cert utility to generate the cert and CA. While generation of the certs or the CA any of the prompts did not ask us about the Hostnames or IP. We generated just one certificate and used that cert in all the nodes. Now the machines are moving to new IP and we are confused if the previous cert which is working now will work or not. Are the certs generated with elasticsearch cert-util are bound …

What version are you on?

> [@frdh-samuelw](#):
>
> `bin/elasticsearch-certutil`
> 
> command but when I do that it says that there is "no such file or directory". I am unable to use that command, and based on my reading of the webpage:

Where are you running that from? /  
How did you install?

But yes you need to regenerate the Certs and then make sure if you created

> **[elasticsearch-certutil | Elastic Documentation](https://www.elastic.co/docs/reference/elasticsearch/command-line-tools/certutil#_examples_15)**
>
> The elasticsearch-certutil command simplifies the creation of certificates for use with Transport Layer Security (TLS) in the Elastic Stack. You can specify...

---

<div class="post-metadata">

**Author:** ![frdh-samuelw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frdh-samuelw/32/142676_2.png) [@frdh-samuelw](https://discuss.elastic.co/u/frdh-samuelw)\
**Post date:** [April 16, 2025, 7:29pm UTC](https://discuss.elastic.co/t/regenerate-the-ssl-certificate-that-was-auto-generated-on-setup-of-elasticsearch/377216/3 "2025-04-16T19:29:14Z")

</div>

Hello @stephenb !

Thank you for your response!

We are using elasticsearch version 8.17.1

Thank you for linking that post. The situation is very similar, however we have not used the cert utility at all yet, we have only used the auto-generated SSL certificate. I tried using the

```auto
bin/elasticsearch-certutil

```

from the home directory. Sorry, I haven't used commands with 'bin' at the beginning before, should I run that from the /etc/elasticsearch directory?

We installed by following the instructions here:

> **[Install Elasticsearch with a Debian package | Elastic documentation](https://www.elastic.co/docs/deploy-manage/deploy/self-managed/install-elasticsearch-with-debian-package)**
>
> The Debian package for Elasticsearch can be downloaded from our website or from our APT repository. It can be used to install Elasticsearch on any Debian-based...

Using the apt repository. I did not set up additional nodes as we only have the one server running Elastic Search.

For the certutil command page, would the certificate I want to regenerate be an "HTTP" certificate? There doesn't seem to be anything there about the default http\_ca.crt or how to get it to regenerate, but if creating a new one is the way to go then I would definitely try that if I can get the command to work.

Thank you again for your help!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 16, 2025, 8:23pm UTC](https://discuss.elastic.co/t/regenerate-the-ssl-certificate-that-was-auto-generated-on-setup-of-elasticsearch/377216/4 "2025-04-16T20:23:35Z")

</div>

If you installed as a Deb package you need to go to

`cd /usr/share/elasticsearch`

The Home directory as detailed at the bottom of the page you linked and run commands from there

---

<div class="post-metadata">

**Author:** ![Rafa\_Silva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rafa_silva/32/147814_2.png) [@Rafa\_Silva](https://discuss.elastic.co/u/Rafa_Silva)\
**Post date:** [April 18, 2025, 3:07am UTC](https://discuss.elastic.co/t/regenerate-the-ssl-certificate-that-was-auto-generated-on-setup-of-elasticsearch/377216/5 "2025-04-18T03:07:03Z")

</div>

This happens because the original certificate includes the **old IP** or hostname. Here's how to regenerate it correctly:

1. **Go to the Elasticsearch installation path**

cd /usr/share/elasticsearch

1. **Run certutil in interactive mode**

sudo bin/elasticsearch-certutil http

1. Follow the prompts:

- Generate a new certificate
- Enter the **new server IP or hostname**
- Save the `.zip` file

1. **Extract the new certs**

unzip elasticsearch-ssl-http.zip -d certs/

```auto

5. **Replace the old certs**

sudo mv /etc/elasticsearch/certs /etc/elasticsearch/certs.bak
sudo mv certs/ /etc/elasticsearch/certs

```

1. **Update elasticsearch.yml if needed**

yaml

```auto
xpack.security.http.ssl:
  enabled: true
  key: /etc/elasticsearch/certs/elasticsearch.key
  certificate: /etc/elasticsearch/certs/elasticsearch.crt
  certificate_authorities: ["/etc/elasticsearch/certs/ca.crt"]

```

1. **Restart Elasticsearch**

sudo systemctl restart elasticsearch

```auto

---

Hope this helps anyone facing the same issue!
If you're using Docker or Elastic Cloud, the steps are slightly different — happy to help if needed.

—
*Contributed by [Rafael Silva](https://www.linkedin.com/in/rafael-silva-observabilidade/), Observability Specialist & Elastic Enthusiast*
[GitHub: @rafasilva1984](https://github.com/rafasilva1984
```

---

<div class="post-metadata">

**Author:** ![Yaser\_Amini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaser_amini/32/145931_2.png) [@Yaser\_Amini](https://discuss.elastic.co/u/Yaser_Amini)\
**Post date:** [November 27, 2025, 10:10am UTC](https://discuss.elastic.co/t/regenerate-the-ssl-certificate-that-was-auto-generated-on-setup-of-elasticsearch/377216/6 "2025-11-27T10:10:21Z")

</div>

I’m facing the same issue. I had a 3 node cluster and the IP address of all nodes has been changed. What are the exact steps to generate certificates with new SANs which should include the new IP address of server?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 27, 2025, 4:32pm UTC](https://discuss.elastic.co/t/regenerate-the-ssl-certificate-that-was-auto-generated-on-setup-of-elasticsearch/377216/7 "2025-11-27T16:32:26Z")

</div>

Hi @Yaser_Amini Welcome to the community

1st place to start is the official documentation

> **[Update TLS certificates | Elastic Docs](https://www.elastic.co/docs/deploy-manage/security/updating-certificates)**
>
> You might need to update your TLS certificates if your current node certificates expire soon, you’re adding new nodes to your secured cluster, or a security...

And here are details on using the cert util

> **[elasticsearch-certutil | Reference](https://www.elastic.co/docs/reference/elasticsearch/command-line-tools/certutil)**
>
> The elasticsearch-certutil command simplifies the creation of certificates for use with Transport Layer Security (TLS) in the Elastic Stack. You can specify...

I like using the Silent Mode with instances.yml to create new certs with the correct SANs / IPs etc

> **[elasticsearch-certutil | Reference](https://www.elastic.co/docs/reference/elasticsearch/command-line-tools/certutil#certutil-silent)**
>
> The elasticsearch-certutil command simplifies the creation of certificates for use with Transport Layer Security (TLS) in the Elastic Stack. You can specify...
