# Unable to set Certificate Authority in Elastic APM

**URL:** <https://discuss.elastic.co/t/unable-to-set-certificate-authority-in-elastic-apm/165132>\
**Category:** APM\
**Created:** [January 21, 2019, 11:05pm UTC](https://discuss.elastic.co/t/unable-to-set-certificate-authority-in-elastic-apm/165132 "2019-01-21T23:05:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![aqdaniels](https://avatars.discourse-cdn.com/v4/letter/a/59ef9b/32.png) [@aqdaniels](https://discuss.elastic.co/u/aqdaniels)\
**Post date:** [January 21, 2019, 11:05pm UTC](https://discuss.elastic.co/t/unable-to-set-certificate-authority-in-elastic-apm/165132/1 "2019-01-21T23:05:31Z")

</div>

Hello,

APM error message - UNABLE\_TO\_VERIFY\_LEAF\_SIGNATURE (Certificate Authority)

It is important to state that I am not using x-pack security on my elastic cluster.

I am running elastic apm 6.5.4 and using elastic-apm-node (2.1.0). I am able to get the server to start, but there appear to be some issues with SSL. I have added the required code for configuring apm agents in my node project.

When I access a route on the server, I receive this error message.  
APM Server transport error (UNABLE\_TO\_VERIFY\_LEAF\_SIGNATURE): unable to verify the first certificate

I used elasticsearch-certutil to generate a ca certificate and apm certificate and key. I have then, in my docker file placed the ca.crt, apm.crt, and apm.key in the apm-server folder. If I run the following command:

`curl -v https://[hostname]:8200/v1/transactions`

I receive the below response

> CAfile: /etc/pki/tls/certs/ca-bundle.crt  
> CApath: none  
> Server certificate:  
> subject: CN=apm  
> start date: Jan 21 12:20:43 2019 GMT  
> expire date: Jan 20 12:20:43 2022 GMT  
> common name: apm  
> issuer: CN=Elastic Certificate Tool Autogenerated CA  
> NSS error -8179 (SEC\_ERROR\_UNKNOWN\_ISSUER)  
> Peer's Certificate issuer is not recognized.
> 
> - Closing connection 0

If I curl this passing the ca certificate then I get a positive response.

Any insights into what I've done wrong? I am also pasting my apm-docker.yaml file below:

```
 apm-server.host: "0.0.0.0:8200"
 apm-server.ssl.enabled: true
 apm-server.ssl.certificate: "/usr/share/apm-server/apm.crt"
 apm-server.ssl.key: "/usr/share/apm-server/apm.key"

 output.elasticsearch:
  hosts: ['http:// **redacted** :4200']
  protocol: "http"
  username: elastic
  password: " **redacted**"
  ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]

```

---

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [January 22, 2019, 2:29am UTC](https://discuss.elastic.co/t/unable-to-set-certificate-authority-in-elastic-apm/165132/2 "2019-01-22T02:29:56Z")

</div>

At present, the Node.js agent does not support verifying self-signed certificates. If you configure the APM Server for HTTPS, then you must configure the Node.js agent to disable server certificate verification per [https://www.elastic.co/guide/en/apm/agent/nodejs/current/configuration.html#validate-server-cert](https://www.elastic.co/guide/en/apm/agent/nodejs/current/configuration.html#validate-server-cert).

In a future version we should have support for certificate pinning. I've just opened [https://github.com/elastic/apm-agent-nodejs/issues/815](https://github.com/elastic/apm-agent-nodejs/issues/815) to keep track of this.

---

<div class="post-metadata">

**Author:** ![aqdaniels](https://avatars.discourse-cdn.com/v4/letter/a/59ef9b/32.png) [@aqdaniels](https://discuss.elastic.co/u/aqdaniels)\
**Post date:** [January 22, 2019, 9:58pm UTC](https://discuss.elastic.co/t/unable-to-set-certificate-authority-in-elastic-apm/165132/3 "2019-01-22T21:58:20Z")

</div>

Thank you!

I was able to add that property and communicate successfully with APM.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 12, 2019, 6:07pm UTC](https://discuss.elastic.co/t/unable-to-set-certificate-authority-in-elastic-apm/165132/4 "2019-02-12T18:07:23Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
