# About Logstash configuration using ssl

**URL:** <https://discuss.elastic.co/t/about-logstash-configuration-using-ssl/349628>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [December 19, 2023, 7:27am UTC](https://discuss.elastic.co/t/about-logstash-configuration-using-ssl/349628 "2023-12-19T07:27:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hamada](https://avatars.discourse-cdn.com/v4/letter/h/ac91a4/32.png) [@Hamada](https://discuss.elastic.co/u/Hamada)\
**Post date:** [December 19, 2023, 7:27am UTC](https://discuss.elastic.co/t/about-logstash-configuration-using-ssl/349628/1 "2023-12-19T07:27:29Z")

</div>

I have a question regarding Logstash configuration.

In order to connect to Elasticsearch from Logstash, enter the following into the Logstash configuration and execute.

# == output{ elasticsearch { hosts =\> ["[https://xxx:9200](https://xxx:9200)"] ssl\_certificate\_authorities =\> ["c:/work/xxx.crt"] ca\_trusted\_fingerprint =\> "xxxxxxxxxxxxxxxxxxxx" user =\> "elastic" password =\> "xxxxx" } }

When I run Logstash, the following error occurs.

==  
Invalid setting for a elasticsearch output plugin:

output{  
elasticsearch {  
#This setting must be a path  
# ["File dose not exist or connot be open /path/to/ca.cert"]  
ssl\_certificate\_authorities =\> "/path/to/ca.cert"  
...  
}  
}

Invalid setting for a elasticsearch output plugin:

output{  
elasticsearch {  
#This setting must be a sha\_256\_hex  
#["Expected a hex-encoded SHA-256 fingerprint, got `\"xxxxxxxx\"`"]  
ca\_trusted\_fingerprint =\> "xxxxxxxxxxxxxxxxxxxx"  
...  
}  
}

==

- Missing settings  
・Cause of error  
Anyone who knows something please help

The environment in which Logstash is running is a Windows environment,  
The permissions to the crt file's directory are fine.  
The fingerprint is also a hexadecimal number issued by Elasticsearch, so there is no problem with the value.

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [December 19, 2023, 12:59pm UTC](https://discuss.elastic.co/t/about-logstash-configuration-using-ssl/349628/2 "2023-12-19T12:59:12Z")

</div>

Hi,

the errors indicate issues with the `ssl_certificate_authorities` and `ca_trusted_fingerprint` settings.

1. `ssl_certificate_authorities`: Ensure the path to the CA certificate is correct and the file is accessible.
2. `ca_trusted_fingerprint`: Make sure it's the correct SHA-256 fingerprint of the CA certificate.

Regards.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2024, 1:00pm UTC](https://discuss.elastic.co/t/about-logstash-configuration-using-ssl/349628/3 "2024-01-16T13:00:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
