# X509: certificate signed by unknown authority

**URL:** <https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/378684>\
**Category:** Beats\
**Tags:** heartbeat\
**Created:** [May 29, 2025, 7:38am UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/378684 "2025-05-29T07:38:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![madhavsankarg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madhavsankarg/32/136239_2.png) [@madhavsankarg](https://discuss.elastic.co/u/madhavsankarg)\
**Post date:** [May 29, 2025, 7:38am UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/378684/1 "2025-05-29T07:38:39Z")

</div>

Hi All,

Hearbeat version - 8.14.1

The certificate is updated for the specific URL, still in Uptime monitor we are getting the error **x509: certificate signed by unknown authority**. I can confirm that the CHain of the certificate got changed and that was also updated.

When I externally did the `GET "url"`, I got the status **200 Ok**.  
Is there internally in the heartbeat its checking the authenticity using the old chain?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 30, 2025, 7:11pm UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/378684/2 "2025-05-30T19:11:10Z")

</div>

Hi @madhavsankarg

It is not clear which URL you are referring to the URL to Elasticsearch, A monitoring URL perhaps share your configurations heartbeat.yml and monitors config

---

<div class="post-metadata">

**Author:** ![madhavsankarg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madhavsankarg/32/136239_2.png) [@madhavsankarg](https://discuss.elastic.co/u/madhavsankarg)\
**Post date:** [June 3, 2025, 12:44pm UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/378684/3 "2025-06-03T12:44:12Z")

</div>

Hi @stephenb,

The URL was an internal application url, which was monitored using the Uptime in Kibana. That was showing the above error.

Solution  
The node were heartbeat is setup the trust certificates were not updated. This related to the issue of the new certificate chain getting authenticated by the heartbeat. SO just need to update the Trust certificate in the node.
