# Using single certificate which contains multiple SANs

**URL:** <https://discuss.elastic.co/t/using-single-certificate-which-contains-multiple-sans/148469>\
**Category:** Elasticsearch\
**Created:** [September 13, 2018, 3:18pm UTC](https://discuss.elastic.co/t/using-single-certificate-which-contains-multiple-sans/148469 "2018-09-13T15:18:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pprasad](https://avatars.discourse-cdn.com/v4/letter/p/e19b73/32.png) [@pprasad](https://discuss.elastic.co/u/pprasad)\
**Post date:** [September 13, 2018, 3:18pm UTC](https://discuss.elastic.co/t/using-single-certificate-which-contains-multiple-sans/148469/1 "2018-09-13T15:18:50Z")

</div>

Is it possible to use a single certificate (which contains multiple SANs) in all the nodes in 6.3 Elasticsearch cluster? (I want to use `xpack.ssl.verification_mode`=full)

For example, I have a 5 node cluster and my certificate's Subject Alternative Name looks like this  
DNS [Name=myesnode1.xxx.com](http://Name=myesnode1.xxx.com)  
DNS [Name=myesnode2.xxx.com](http://Name=myesnode2.xxx.com)  
DNS [Name=myesnode3.xxx.com](http://Name=myesnode3.xxx.com)  
DNS [Name=myesnode4.xxx.com](http://Name=myesnode4.xxx.com)  
DNS [Name=myesnode5.xxx.com](http://Name=myesnode5.xxx.com)

---

<div class="post-metadata">

**Author:** ![Peter\_Steenbergen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_steenbergen/32/22888_2.png) [@Peter\_Steenbergen](https://discuss.elastic.co/u/Peter_Steenbergen)\
**Post date:** [September 13, 2018, 3:54pm UTC](https://discuss.elastic.co/t/using-single-certificate-which-contains-multiple-sans/148469/2 "2018-09-13T15:54:33Z")

</div>

If the certificate contains all the domains mentioned. Then yes it should be possible.

---

<div class="post-metadata">

**Author:** ![pprasad](https://avatars.discourse-cdn.com/v4/letter/p/e19b73/32.png) [@pprasad](https://discuss.elastic.co/u/pprasad)\
**Post date:** [September 13, 2018, 5:37pm UTC](https://discuss.elastic.co/t/using-single-certificate-which-contains-multiple-sans/148469/3 "2018-09-13T17:37:27Z")

</div>

> [@Peter\_Steenbergen](#):
>
> hould b

Thank you Peter. I will try it and will reply back if see issues.

---

<div class="post-metadata">

**Author:** ![pprasad](https://avatars.discourse-cdn.com/v4/letter/p/e19b73/32.png) [@pprasad](https://discuss.elastic.co/u/pprasad)\
**Post date:** [September 17, 2018, 8:42pm UTC](https://discuss.elastic.co/t/using-single-certificate-which-contains-multiple-sans/148469/4 "2018-09-17T20:42:32Z")

</div>

Cluster setup is complete and everything seems to be working except a warning which is shown on the elasticsearch server.

Here are the details of my cluster

- 5 nodes (4 masters, 1 data)
- Gold subscription license applied
- SSL and HTTPS configured (Godaddy)
- Single certificate with multiple SAN used
- Testing from browser displays ok (Browser shows certificate is valid)
- Testing using openssl shows ok (No validation errors)  
[openssl s\_client -showcerts -host [mynode1.xxx.com](http://mynode1.xxx.com) -port 9200]

Below warning is shown on the elasticsearch server. Interesting factor is that the IP (10.10.171.205) shown below is not from my cluster. What is the reason for this warning and how can I avoid this?

## Exception at server:

## caught exception while handling client http traffic, closing connection [id: 0x6c20770e, L:0.0.0.0/0.0.0.0:9200 ! R:/10.10.171.205:63966] io.netty.handler.codec.DecoderException: javax.net.ssl.SSLException: Received fatal alert: bad\_certificate

Caused by: javax.net.ssl.SSLException: Received fatal alert: bad\_certificate

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2018, 8:42pm UTC](https://discuss.elastic.co/t/using-single-certificate-which-contains-multiple-sans/148469/5 "2018-10-15T20:42:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
