# Set custom CA Certificate for Self Hosted Repository

**URL:** <https://discuss.elastic.co/t/set-custom-ca-certificate-for-self-hosted-repository/355199>\
**Category:** Endpoint Security\
**Created:** [March 12, 2024, 1:06am UTC](https://discuss.elastic.co/t/set-custom-ca-certificate-for-self-hosted-repository/355199 "2024-03-12T01:06:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jason4](https://avatars.discourse-cdn.com/v4/letter/j/a5b964/32.png) [@jason4](https://discuss.elastic.co/u/jason4)\
**Post date:** [March 12, 2024, 1:06am UTC](https://discuss.elastic.co/t/set-custom-ca-certificate-for-self-hosted-repository/355199/1 "2024-03-12T01:06:02Z")

</div>

Hello,

Is it possible to set a ca cert along with the `advanced.artifacts.global.base_url` in the advanced settings for Elastic Defend, to be used when downloading from the security artifacts repository. Following the guide described here:  
[Configure offline endpoints and air-gapped environments | Elastic Security Solution [8.12] | Elastic](https://www.elastic.co/guide/en/security/current/offline-endpoint.html)

I only see options for ca cert options for "elasticsearch" and "users" (for fleet server), but non for the artifacts repo.

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [March 18, 2024, 5:19pm UTC](https://discuss.elastic.co/t/set-custom-ca-certificate-for-self-hosted-repository/355199/2 "2024-03-18T17:19:27Z")

</div>

You are correct, unfortunately. There is no way to provide ca cert for security artifacts repository URL.

Note however, the artifacts themselves are RSA-signed so Elastic Defend won't accept any "untrusted" artifacts.

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [March 18, 2024, 5:32pm UTC](https://discuss.elastic.co/t/set-custom-ca-certificate-for-self-hosted-repository/355199/3 "2024-03-18T17:32:35Z")

</div>

The only workaround for now to use https with custom self-signed ca would be to import it into cert store / key chain on all machines.

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [March 22, 2024, 3:26pm UTC](https://discuss.elastic.co/t/set-custom-ca-certificate-for-self-hosted-repository/355199/4 "2024-03-22T15:26:23Z")

</div>

[Configuration option](https://github.com/elastic/kibana/pull/179138) will be provided in Kibana in 8.14.0

---

<div class="post-metadata">

**Author:** ![jason4](https://avatars.discourse-cdn.com/v4/letter/j/a5b964/32.png) [@jason4](https://discuss.elastic.co/u/jason4)\
**Post date:** [April 3, 2024, 5:24pm UTC](https://discuss.elastic.co/t/set-custom-ca-certificate-for-self-hosted-repository/355199/5 "2024-04-03T17:24:27Z")

</div>

Awesome, thank you for the confirmation and progress!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2024, 5:24pm UTC](https://discuss.elastic.co/t/set-custom-ca-certificate-for-self-hosted-repository/355199/6 "2024-05-01T17:24:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
