# X509: certificate signed by unknown authority , elastic agent + Tenable SC

**URL:** <https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-elastic-agent-tenable-sc/383835>\
**Category:** Elastic Agent\
**Created:** [December 3, 2025, 9:23am UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-elastic-agent-tenable-sc/383835 "2025-12-03T09:23:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alaeddine\_khadraoui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alaeddine_khadraoui/32/141064_2.png) [@Alaeddine\_khadraoui](https://discuss.elastic.co/u/Alaeddine_khadraoui)\
**Post date:** [December 3, 2025, 9:23am UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-elastic-agent-tenable-sc/383835/1 "2025-12-03T09:23:42Z")

</div>

dear elastic community

Im working on integrating Tenable Security Center via elastic agent , and getting **x509: certificate signed by unknown** ,

can please advise what actions to check also if the certificate signed by untrusted CA or generated as selfsigned what we need to do on elastic agent side

thanks

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 3, 2025, 10:45am UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-elastic-agent-tenable-sc/383835/2 "2025-12-03T10:45:59Z")

</div>

Would `ssl.verification_mode: none` work for you?  
Have a look at:

> **[Configure SSL/TLS for standalone Elastic Agents | Elastic Docs](https://www.elastic.co/docs/reference/fleet/elastic-agent-ssl-configuration)**
>
> There are a number of SSL configuration settings available depending on whether you are configuring a client, server, or both. See the following tables...

> `ssl.verification_mode`
> 
> (string) Controls the verification of server certificates. Valid values are:
> 
> - `full`  
> Verifies that the provided certificate is signed by a trusted authority (CA) and also verifies that the server’s hostname (or IP address) matches the names identified within the certificate.
> - `strict`  
> Verifies that the provided certificate is signed by a trusted authority (CA) and also verifies that the server’s hostname (or IP address) matches the names identified within the certificate. If the Subject Alternative Name is empty, it returns an error.
> - `certificate`  
> Verifies that the provided certificate is signed by a trusted authority (CA), but does not perform any hostname verification.
> - `none`  
> Performs _no verification_ of the server’s certificate. This mode disables many of the security benefits of SSL/TLS and should only be used after cautious consideration. It is primarily intended as a temporary diagnostic mechanism when attempting to resolve TLS errors; its use in production environments is strongly discouraged.
> 
> **Default:** `full`

---

<div class="post-metadata">

**Author:** ![Alaeddine\_khadraoui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alaeddine_khadraoui/32/141064_2.png) [@Alaeddine\_khadraoui](https://discuss.elastic.co/u/Alaeddine_khadraoui)\
**Post date:** [December 3, 2025, 11:10am UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-elastic-agent-tenable-sc/383835/3 "2025-12-03T11:10:46Z")

</div>

Hi @dadoonet

Thank for your replay

i want go by trust the CA on the integration how to proceed i have to add on this side ?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4c22c9556109b0f5b60819b7766a782effcc6e0f.png)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 3, 2025, 11:31am UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-elastic-agent-tenable-sc/383835/4 "2025-12-03T11:31:39Z")

</div>

Not an expert, but from the same documentation I linked to, you have `ssl.certificate_authorities`. May be that's what you are looking for.
