# X509 certificate signed by unknown authority error, even with --insecure flag

**URL:** <https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-error-even-with-insecure-flag/377467>\
**Category:** Elastic Agent\
**Created:** [April 23, 2025, 10:38pm UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-error-even-with-insecure-flag/377467 "2025-04-23T22:38:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nmcc1212](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nmcc1212/32/142805_2.png) [@nmcc1212](https://discuss.elastic.co/u/nmcc1212)\
**Post date:** [April 23, 2025, 10:38pm UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-error-even-with-insecure-flag/377467/1 "2025-04-23T22:38:37Z")

</div>

Hi,

I am installing the elastic agent with `sudo ./elastic-agent install --url=https://<FLEET URL> --enrollment-token=<token> --insecure`  
In the output of `sudo elastic-agent inspect` there is

```auto
ssl:
    renegotiation: never
    verification_mode: none

```

but in the output of `sudo elastic-agent logs` there are errors for `Error dialing x509: certificate signed by unknown authority` and no data is being ingested from any agents. I thought that adding --insecure would prevent these errors?

This is a brand new Elastic V9 stack on ECE 4.0

---

<div class="post-metadata">

**Author:** ![nmcc1212](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nmcc1212/32/142805_2.png) [@nmcc1212](https://discuss.elastic.co/u/nmcc1212)\
**Post date:** [April 23, 2025, 10:43pm UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-error-even-with-insecure-flag/377467/2 "2025-04-23T22:43:15Z")

</div>

Full Elastic Agent Errors

```auto
{
  "log.level": "error",
  "@timestamp": "2025-04-23T22:37:43.262Z",
  "message": "Failed to connect to backoff(elasticsearch(<fleet>)): Get \"<FLEET URL>\": x509: certificate signed by unknown authority",
  "component": {
    "binary": "filebeat",
    "dataset": "elastic_agent.filebeat",
    "id": "filestream-monitoring",
    "type": "filestream"
  },
  "log": {
    "source": "filestream-monitoring"
  },
  "log.origin": {
    "file.line": 149,
    "file.name": "pipeline/client_worker.go",
    "function": "github.com/elastic/beats/v7/libbeat/publisher/pipeline.(*netClientWorker).run"
  },
  "service.name": "filebeat",
  "ecs.version": "1.6.0",
  "log.logger": "publisher_pipeline_output",
  "ecs.version": "1.6.0"
}

```

```auto
{
  "log.level": "error",
  "@timestamp": "2025-04-23T22:37:43.291Z",
  "message": "Error dialing x509: certificate signed by unknown authority",
  "component": {
    "binary": "filebeat",
    "dataset": "elastic_agent.filebeat",
    "id": "filestream-monitoring",
    "type": "filestream"
  },
  "log": {
    "source": "filestream-monitoring"
  },
  "log.origin": {
    "file.line": 39,
    "file.name": "transport/logging.go",
    "function": "github.com/elastic/elastic-agent-libs/transport/httpcommon.(*HTTPTransportSettings).RoundTripper.LoggingDialer.func2"
  },
  "network.transport": "tcp",
  "server.address": "<FLEET URL>",
  "log.logger": "esclientleg",
  "service.name": "filebeat",
  "ecs.version": "1.6.0",
  "ecs.version": "1.6.0"
}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 24, 2025, 1:28am UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-error-even-with-insecure-flag/377467/3 "2025-04-24T01:28:44Z")

</div>

Hi @nmcc1212 Welcome to the community.

What Version of the Stack and Agent?

What integrations are part of the policy?

How did you set up Elasticsearch, Kibana and Fleet?

Did you run

`elastic-agent status`

Can you share that?

```auto
  "message": "Failed to connect to backoff(elasticsearch(<fleet>)): Get \"<FLEET URL>\"

```

And to be sure that is the Fleet URL and Port because it kind of looks like Elasticsearch meaning it may be the connection to Elasticsearch not Fleet. Agents get Policies from Fleet but send telemetry Directly to Elasticsearch

And that connection information is set as the Outputs In the Fleet Settings

Did you set that up correctly?

Basically you're going to need to include that CA fingerprint if you have a self-signed cert

> **Elasticsearch CA trusted fingerprint** HEX encoded SHA-256 of a CA certificate. If this certificate is present in the chain during the handshake, it will be added to the `certificate_authorities` list and the handshake will continue normally.

To learn more about trusted fingerprints, refer to the [Elasticsearch security documentation](https://www.elastic.co/guide/en/elasticsearch/reference/8.18/configuring-stack-security.html).

> **[Elasticsearch output settings | Fleet and Elastic Agent Guide \[8.18\] | Elastic](https://www.elastic.co/guide/en/fleet/8.18/es-output-settings.html#es-output-settings-yaml-config)**

 ![Screenshot 2025-04-23 at 6.26.59 PM](https://us1.discourse-cdn.com/elastic/original/3X/a/a/aadd30042fc741ff642cf8bdde6bdde0cd1fd1b7.png)

 ![Screenshot 2025-04-23 at 6.31.35 PM](https://us1.discourse-cdn.com/elastic/original/3X/6/1/61f8b75e8314c8e0a2bb0f469eb85d91ae672628.png)

> **[Start the Elastic Stack with security enabled automatically | Elasticsearch...](https://www.elastic.co/guide/en/elasticsearch/reference/8.18/configuring-stack-security.html#_use_the_ca_fingerprint_5)**

---

<div class="post-metadata">

**Author:** ![nmcc1212](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nmcc1212/32/142805_2.png) [@nmcc1212](https://discuss.elastic.co/u/nmcc1212)\
**Post date:** [April 24, 2025, 6:57am UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-error-even-with-insecure-flag/377467/4 "2025-04-24T06:57:14Z")

</div>

Hi,  
Thanks for this, adding the fingerprint to the output fixed the issue

And going back over the logs i realised this was the elasticsearch URL not the fleet URL

Thanks for your help! 😄
