# Set up remote cluster CA certificate in Elasticsearch 8.8.1

**URL:** <https://discuss.elastic.co/t/set-up-remote-cluster-ca-certificate-in-elasticsearch-8-8-1/351889>\
**Category:** Elasticsearch\
**Created:** [January 26, 2024, 2:53pm UTC](https://discuss.elastic.co/t/set-up-remote-cluster-ca-certificate-in-elasticsearch-8-8-1/351889 "2024-01-26T14:53:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rachelyang](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Post date:** [January 26, 2024, 2:53pm UTC](https://discuss.elastic.co/t/set-up-remote-cluster-ca-certificate-in-elasticsearch-8-8-1/351889/1 "2024-01-26T14:53:03Z")

</div>

I have a local cluster. Now I would like to set up a remote cluster to connect to the local cluster. How do I set up the CA certificate on the remote cluster node to make these two cluster to trust each other?  
Here is my local cluster Elasticsearch node conf (elasticsearch service has started):

```auto
cluster.name: ElasticSearch
node.name: node01
node.roles: [master, data, ingest, remote_cluster_client]
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
bootstrap.memory_lock: true
network.host: 0.0.0.0
http.port: 9200
xpack.security.enabled: true
xpack.security.enrollment.enabled: true
xpack.security.http.ssl:
  enabled: true
  keystore.path: certs/http.p12
xpack.security.transport.ssl:
  enabled: true
  verification_mode: certificate
  keystore.path: certs/transport.p12
  truststore.path: certs/transport.p12
xpack.monitoring.exporters.my_local:
  type: local
  use_ingest: false
discovery.seed_hosts: ["node01", "node02"]
http.host: 0.0.0.0
transport.host: 0.0.0.0

```

And this is my remote cluster node conf (elasticsearch service has not started, yet):

```auto
cluster.name: remote-elasticsearch
node.name: remote01
node.roles: [master, data, ingest, remote_cluster_client]
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
network.host: 0.0.0.0
http.port: 9200
xpack.security.enabled: true
xpack.security.enrollment.enabled: true
xpack.security.http.ssl:
  enabled: true
  keystore.path: certs/http.p12
xpack.security.transport.ssl:
  enabled: true
  verification_mode: full
  keystore.path: certs/transport.p12
  truststore.path: certs/transport.p12
cluster.initial_master_nodes: ["remote01"]
xpack.monitoring.exporters.my_local:
  type: local
  use_ingest: false
http.host: 0.0.0.0
transport.host: 0.0.0.0

```

Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 23, 2024, 2:58pm UTC](https://discuss.elastic.co/t/set-up-remote-cluster-ca-certificate-in-elasticsearch-8-8-1/351889/3 "2024-02-23T14:58:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
