# X509 Certificate Error for Fleet Enrollment

**URL:** <https://discuss.elastic.co/t/x509-certificate-error-for-fleet-enrollment/264461>\
**Category:** Elastic Security\
**Tags:** elastic-stack-security, fleet\
**Created:** [February 16, 2021, 5:28pm UTC](https://discuss.elastic.co/t/x509-certificate-error-for-fleet-enrollment/264461 "2021-02-16T17:28:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![secopsgeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/secopsgeek/32/83957_2.png) [@secopsgeek](https://discuss.elastic.co/u/secopsgeek)\
**Post date:** [February 16, 2021, 5:28pm UTC](https://discuss.elastic.co/t/x509-certificate-error-for-fleet-enrollment/264461/1 "2021-02-16T17:28:17Z")

</div>

Hello friends, I am needing some help with setting up the fleet enrollment for my clients on windows systems. Am having an issue with this EDR portion of the SIEM build.

Any help would be nice, I have the cert, but not connection.

```auto
The Elastic Agent is currently in BETA and should not be used in production

Error: fail to enroll: fail to execute request to Kibana: Post "https://172.16.100.10:5601/api/fleet/agents/enroll?": x509: cannot validate certificate for 172.16.100.10 because it doesn't contain any IP SANs
Error: enroll command failed with exit code: 1

```

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 17, 2021, 2:35am UTC](https://discuss.elastic.co/t/x509-certificate-error-for-fleet-enrollment/264461/2 "2021-02-17T02:35:20Z")

</div>

The certificate you are using in Kibana cannot be trusted by Agent because it isn't valid for the `172.16.100.10` IP address (or any IP address).

It may be as simple as configuring Fleet to use a different URL to access Kibana, or it may require generating a new certificate for Kibana.

---

<div class="post-metadata">

**Author:** ![secopsgeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/secopsgeek/32/83957_2.png) [@secopsgeek](https://discuss.elastic.co/u/secopsgeek)\
**Post date:** [February 17, 2021, 3:30am UTC](https://discuss.elastic.co/t/x509-certificate-error-for-fleet-enrollment/264461/3 "2021-02-17T03:30:32Z")

</div>

Is there a way to generate that certificate to add that information into It? Am looking for a command to generate that certificate.

---

<div class="post-metadata">

**Author:** ![finbarr996](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Post date:** [February 27, 2021, 6:29pm UTC](https://discuss.elastic.co/t/x509-certificate-error-for-fleet-enrollment/264461/4 "2021-02-27T18:29:25Z")

</div>

Hi Ronnie,  
You can do that with this command:

'sudo /usr/share/elasticsearch/bin/elasticsearch-certutil cert -name "server.name.here" --ip 172.16.100.10 --dns server.name.here --pem'

This will create a certificate bundle zip file in the '/usr/share/elasticsearch/' folder.  
The zip file will contain a .crt and a .key file that should solve your issue.

---

<div class="post-metadata">

**Author:** ![secopsgeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/secopsgeek/32/83957_2.png) [@secopsgeek](https://discuss.elastic.co/u/secopsgeek)\
**Post date:** [February 27, 2021, 6:59pm UTC](https://discuss.elastic.co/t/x509-certificate-error-for-fleet-enrollment/264461/5 "2021-02-27T18:59:26Z")

</div>

Thanks, blessings to ya.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2021, 7:00pm UTC](https://discuss.elastic.co/t/x509-certificate-error-for-fleet-enrollment/264461/6 "2021-03-27T19:00:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
