Migrating the Certificate Authority (CA) for Elasticsearch Service to Let’s Encrypt
Scheduled for Oct 4, 00:00 UTC  -  Nov 3, 00:00 UTC
At Elastic Cloud we are committed to offering our customers the most secure way to run their workloads in the cloud. To help ensure this commitment, we are migrating our TLS certificates to Let’s Encrypt to best support sustainable and fully automated certificate management as our product offerings and available regions continue to expand.

These changes will begin rolling out to Elastic Cloud regions beginning October 4, 2021, and are expected to be completed in all regions by October 29, 2021.

The first region will be Azure southcentralus on October 4, 2021. After updating this region, we will pause the rollout to other regions for 14 days to allow for client validation. The remaining regions will begin being updated on October 18, 2021. We will post updates on this page as the roll out happens across regions.

What is the change?

We are migrating the TLS certificate on Elastic Cloud from DigiCert to Let’s Encrypt. The change in the Certification Authority (CA) might have an impact on some clients.

What is the impact on me?

If you use clients that are not compatible with the Let’s Encrypt ISRG Root X1 certificate, you must upgrade the clients or your certificate stores in order to trust the new certificates.

Find more details in our blog https://www.elastic.co/blog/migrating-ess-certs-letsencrypt
Posted Jul 15, 2021 - 05:01 UTC
