# Trouble Installing Fleet with Self-managed Certificates

**URL:** <https://discuss.elastic.co/t/trouble-installing-fleet-with-self-managed-certificates/380091>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [July 14, 2025, 7:27am UTC](https://discuss.elastic.co/t/trouble-installing-fleet-with-self-managed-certificates/380091 "2025-07-14T07:27:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohammad\_syaugi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammad_syaugi/32/144144_2.png) [@mohammad\_syaugi](https://discuss.elastic.co/u/mohammad_syaugi)\
**Post date:** [July 14, 2025, 7:27am UTC](https://discuss.elastic.co/t/trouble-installing-fleet-with-self-managed-certificates/380091/1 "2025-07-14T07:27:44Z")

</div>

Hello guys,

I've been installing fleet with self-managed SSL Certificates following this docs: [Configure SSL/TLS for self-managed Fleet Servers | Fleet and Elastic Agent Guide [8.14] | Elastic](https://www.elastic.co/guide/en/fleet/8.14/secure-connections.html)

But i find my fleet always updating and then offline with status 'never checked in'

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73cde17e48d0584a98d1734a05074dc8985edd6d.png)

i used this specific commands on the server:

```auto
sudo ./elastic-agent install \
  --url=https://IP:8220 \
  --fleet-server-es=https://IP:9200 \
  --fleet-server-service-token=<token> \
  --fleet-server-policy=fleet-server-policy \
  --fleet-server-es-ca=/etc/elasticsearch/certs/http_ca.crt \
  --certificate-authorities=/etc/elasticsearch/certs/ca.crt \
  --fleet-server-cert=/etc/elasticsearch/certs/fleet-server.crt \
  --fleet-server-cert-key=/etc/elasticsearch/certs/fleet-server.key \
  --fleet-server-es-cert=/tmp/fleet-server.crt \
  --fleet-server-es-cert-key=/tmp/fleet-server.key \
  --elastic-agent-cert=/tmp/fleet-server.crt \
  --elastic-agent-cert-key=/tmp/fleet-server.key \
  --fleet-server-port=8220 \
  --fleet-server-client-auth=required

```

is it right?

---

<div class="post-metadata">

**Author:** ![MichelLaterman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michellaterman/32/110221_2.png) [@MichelLaterman](https://discuss.elastic.co/u/MichelLaterman)\
**Post date:** [July 15, 2025, 2:23pm UTC](https://discuss.elastic.co/t/trouble-installing-fleet-with-self-managed-certificates/380091/2 "2025-07-15T14:23:58Z")

</div>

`--fleet-server-client-auth=required` is only required if you need mTLS, otherwise it can be removed.

Are you able to provide any logs or a diagnostics bundle from the instance to help with debugging?

---

<div class="post-metadata">

**Author:** ![mohammad\_syaugi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammad_syaugi/32/144144_2.png) [@mohammad\_syaugi](https://discuss.elastic.co/u/mohammad_syaugi)\
**Post date:** [July 22, 2025, 7:21am UTC](https://discuss.elastic.co/t/trouble-installing-fleet-with-self-managed-certificates/380091/3 "2025-07-22T07:21:46Z")

</div>

Thanks for the insight michel, im using a lot of ways possible including your suggestion. But i still got 'offline' status in my fleet with description "Never checked in".

I've ended up reinstalling the fleet using the quickstart option with this commands:

```auto
curl -L -O https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.14.3-linux-x86_64.tar.gz
tar xzvf elastic-agent-8.14.3-linux-x86_64.tar.gz
cd elastic-agent-8.14.3-linux-x86_64
sudo ./elastic-agent install \
  --fleet-server-es=https://<ip>:9200 \
  --fleet-server-service-token=<token>\
  --fleet-server-policy=fleet-server-policy \
  --fleet-server-es-ca-trusted-fingerprint=<print> \
  --fleet-server-port=8220

```

My initial problem was my agent can't connect to my fleet because of the self-signed certificate, since the quickstart agent installation only told me to run this commands:

```auto
curl -L -O https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.14.3-linux-x86_64.tar.gz
tar xzvf elastic-agent-8.14.3-linux-x86_64.tar.gz
cd elastic-agent-8.14.3-linux-x86_64
sudo ./elastic-agent install \
--url=https://<host>:8220 \
--enrollment-token=<token>

```

And i found out the self signed certificate in fleet server can be extracted to be used in addition of the agent installation commands as:

```auto
--certificate-authorities=/path/to/fleet_ca.crt

```

For anyone who wonder how to extract it, im using this command:

```auto
openssl s_client -connect <fleet-ip>:8220 -showcerts </dev/null 2>/dev/null | awk '/-----BEGIN/,/-----END/' > /tmp/fleet_ca.crt

```

Copy the fleet\_ca.crt to any agent installation vm, then just add the extra commands i told before in agent installation. It works.
