# How to use the ingress certificates in place of all the random generated certificates

**URL:** <https://forum.search-guard.com/t/how-to-use-the-ingress-certificates-in-place-of-all-the-random-generated-certificates/1589>\
**Category:** Search Guard\
**Created:** [July 12, 2019, 8:14am UTC](https://forum.search-guard.com/t/how-to-use-the-ingress-certificates-in-place-of-all-the-random-generated-certificates/1589 "2019-07-12T08:14:13Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ntsh999](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/ntsh999/32/597_2.png) [@ntsh999](https://forum.search-guard.com/u/ntsh999)\
**Post date:** [July 12, 2019, 8:14am UTC](https://forum.search-guard.com/t/how-to-use-the-ingress-certificates-in-place-of-all-the-random-generated-certificates/1589/1 "2019-07-12T08:14:13Z")

</div>

Hi,

I am setting up searchguard elastic stack on kubernetes (Azure Kubernetes Service). Search guard version sg-sgadmin:7.1.0-35.0.0. I want to expose search guard kibana through ingress. How should I use the same ingress certificate as the Node, Admin, REST certificate? Is this possible? Please provide detailed answer on the steps that will help in achieving the same.

Regard,  
Nitesh

---

<div class="post-metadata">

**Author:** ![hsaly](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/hsaly/32/21_2.png) [@hsaly](https://forum.search-guard.com/u/hsaly)\
**Post date:** [July 12, 2019, 2:57pm UTC](https://forum.search-guard.com/t/how-to-use-the-ingress-certificates-in-place-of-all-the-random-generated-certificates/1589/2 "2019-07-12T14:57:02Z")

</div>



---

<div class="post-metadata">

**Author:** ![cstaley](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/cstaley/32/463_2.png) [@cstaley](https://forum.search-guard.com/u/cstaley)\
**Post date:** [July 12, 2019, 2:57pm UTC](https://forum.search-guard.com/t/how-to-use-the-ingress-certificates-in-place-of-all-the-random-generated-certificates/1589/3 "2019-07-12T14:57:31Z")

</div>

I recommend to have a look how we do it in our helm charts: [GitHub - floragunncom/search-guard-helm: Search Guard Helm Chart for Kubernetes](https://github.com/floragunncom/search-guard-helm)

That said you can have the same certificates for nodes and REST but the admin certificvate needs to be a different one. If you update the certs you must restart the pod.

---

<div class="post-metadata">

**Author:** ![ntsh999](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/ntsh999/32/597_2.png) [@ntsh999](https://forum.search-guard.com/u/ntsh999)\
**Post date:** [July 12, 2019, 6:47pm UTC](https://forum.search-guard.com/t/how-to-use-the-ingress-certificates-in-place-of-all-the-random-generated-certificates/1589/4 "2019-07-12T18:47:10Z")

</div>

1. Can you please help in understanding why do I need a different certificate for admin? I mean what different details do I need to pass while generating this admin certificate? Is there any specific set of values to be given for CN, OU, O etc. I generated my ingress certificate using Lets Encrypt certbot in which I just had to pass my desired DNS name.

2. You said that I need to restart my pod on updating the secrets but wont the pod restart let to generation of new demo certificates and subsequent modification of my Prod secrets? Plz refer the below code in the link [https://github.com/floragunncom/search-guard-helm/blob/master/sg-helm/templates/sgadmin-deployment.yaml](https://github.com/floragunncom/search-guard-helm/blob/master/sg-helm/templates/sgadmin-deployment.yaml) here in Init container a new certificate will be generated. Is not it? ```` cat \>“{{ template “fullname” . }}-root-ca.yml” \<\<EOL  
ca:  
root:  
dn: CN={{ template “fullname” . }}-root-ca,OU=CA,O=Example Com, Inc.,DC=example,DC=com  
keysize: 2048  
validityDays: 365  
pkPassword: none  
file: root-ca.pem  
EOL

---

<div class="post-metadata">

**Author:** ![cstaley](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/cstaley/32/463_2.png) [@cstaley](https://forum.search-guard.com/u/cstaley)\
**Post date:** [July 12, 2019, 7:45pm UTC](https://forum.search-guard.com/t/how-to-use-the-ingress-certificates-in-place-of-all-the-random-generated-certificates/1589/5 "2019-07-12T19:45:40Z")

</div>

Pls refer to the documentation where the various certificate types are explained:

> **[Production environments](https://docs.search-guard.com/latest/tls-in-production#types-of-certificates)**
>
> We explaining the different certificate types of Search Guard and how to generate them for a production system.

> **[Configuring TLS](https://docs.search-guard.com/latest/configuring-tls#configuring-admin-certificates)**
>
> Search Guard TLS configuration settings for the REST and the transport layer. Extended security options for hostname verification and DNS lookups.

> **[Production environments](https://docs.search-guard.com/latest/tls-in-production#client-and-admin-certificates)**
>
> We explaining the different certificate types of Search Guard and how to generate them for a production system.

And yes, in the helm charts we regenerate the node certificates because the hostname is different for every unique pod. The root-ca will only created once of course.

---

<div class="post-metadata">

**Author:** ![ntsh999](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/ntsh999/32/597_2.png) [@ntsh999](https://forum.search-guard.com/u/ntsh999)\
**Post date:** [July 14, 2019, 9:27pm UTC](https://forum.search-guard.com/t/how-to-use-the-ingress-certificates-in-place-of-all-the-random-generated-certificates/1589/6 "2019-07-14T21:27:05Z")

</div>

Hi,

Thanks for the response. I went through it but I am still unclear where and how should I put my generated certificates (generated from Lets encrypt certbot) so that they are picked up by kubernetes on helm install. I did not see any key in the values.yml file that hold certificates. 1. Are they to be placed in install\_demo\_configuration.sh, which then requires creating the docker image for elasticsearch+search guard elastic search plugin or 2. Should I edit the respective secrets and run sgadmin.sh or is there some other correct way of doing it ? Please help. Request you to be elaborative.

Regards,  
Nitesh

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/system/32/1870_2.png) [@system](https://forum.search-guard.com/u/system)\
**Post date:** [August 4, 2019, 9:31pm UTC](https://forum.search-guard.com/t/how-to-use-the-ingress-certificates-in-place-of-all-the-random-generated-certificates/1589/7 "2019-08-04T21:31:24Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
