X509: certificate signed by unknown authority + fleet "Set up encryption key" in kibana > fleet

I am not sure if this is typos but you have spaces so that is not correct in several places ... the last 3 values

--fleet-server-es-ca= /etc/elastic_certs/elasticsearch-ca.pem
.....................^

Is the fleet server on the same server as elastic and kibana or are the the on different servers

Also are you following the directions here an putting in the correct host name and ip your command in the first post does not.

Also assuming that you followed these instructions carefully

Can you show the entire agent install output please