Receiver nodes does not get an updated certificate after adding custom fqdn to fleet configuration #15002
-
Version2.4.170 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM32 Storage for /64G Storage for /nsm128G Network Traffic Collectionother (please provide detail below) Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailSetup: The 2 receiver nodes are meant for external access for elastic agents. When we provide a fqdn in the GUI with advanced settings enabled - Administration -> Configuration -> elasticfleet -> config -> server -> custom_fqdn the fleet node and the manager node are getting updated certificates in /etc/pki/elasticfleet-logstash.crt and /etc/pki/elasticfleet-logstash.key but the receiver nodes does not get any updated certificates. Have i missed anything regarding receiver nodes? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 3 replies
-
https://docs.securityonion.net/en/2.4/hostname.html#hostname Certificates are generated based on hostnames. |
Beta Was this translation helpful? Give feedback.
-
To clarify a couple things:
|
Beta Was this translation helpful? Give feedback.
@mikkelotharholm This is a bug and has been fixed: #15022
Will be included in our next release.