Skip to content

Renew TLS certificates

Renew customer-provided TLS certificates before they expire.

Certificate renewal uses the same supported workflow as initial certificate configuration:

https://copilot.ivedha.cloud

The platform generates the private key and certificate signing request (CSR). The private key remains inside the managed platform.

Before you begin

Review:

  • the current certificate expiration date;
  • the service hostnames covered by the certificate;
  • the certificate authority that will issue the replacement;
  • any internal approval or renewal process required by your organization.

Start renewal early enough to allow time for certificate approval, issuance, upload, and validation.

Request a new CSR

  1. Sign in to the iVedha AI chat application.
  2. Select or identify the deployment.
  3. Ask the assistant to renew the TLS certificate.
  4. Complete identity verification when requested.
  5. Request a new CSR.
  6. Save the CSR provided by the platform.

The platform generates a single CSR that covers all required service hostnames for the deployment, including:

  • Kibana;
  • Elasticsearch;
  • Fleet;
  • Logstash.

The required hostnames are included as Subject Alternative Names (SANs) in the CSR.

Do not generate your own CSR or private key. The private key associated with the CSR remains inside the managed platform.

Sign the CSR

Submit the CSR to your approved certificate authority.

The issued certificate must:

  • match the CSR;
  • include the required service hostnames;
  • include the required intermediate certificate chain;
  • be trusted by the clients that access the platform.

Upload the renewed certificate

After the certificate is issued:

  1. Return to the iVedha AI chat.
  2. Select the same deployment.
  3. Continue the certificate-renewal workflow.
  4. Upload the issued certificate and required intermediate certificates.
  5. Confirm the change.
  6. Wait for confirmation that the certificate has been applied.

Allow a few minutes for the renewed certificate to synchronize across the platform.

Verify the renewed certificate

Verify each service hostname that uses the renewed certificate.

SERVICE_HOSTNAME="<service-hostname>"

openssl s_client \
  -connect "${SERVICE_HOSTNAME}:443" \
  -servername "${SERVICE_HOSTNAME}" \
  -verify_return_error </dev/null

Confirm:

  • Verify return code: 0 (ok);
  • the expected hostname is covered;
  • the issuer is correct;
  • the new expiration date is present;
  • the expected certificate chain is served.

Then verify:

  • Kibana sign-in;
  • Elasticsearch access;
  • Fleet connectivity when applicable;
  • Logstash connectivity when applicable;
  • Elastic Agents return to or remain Healthy.

If the old certificate is still served

Allow a few minutes for synchronization and test again.

If the old certificate remains after the expected propagation period, use:

  • AI chat: https://copilot.ivedha.cloud
  • Support portal: https://support.ivedha.com/

Provide the deployment reference and the affected hostname.

Do not include private keys or other secrets.

Plan the next renewal

Record the new expiration date in your organization's certificate-management process.

Schedule the next renewal early enough to avoid an emergency certificate replacement.

Return to operations

Return to the operations overview to choose the next supported platform task.