# Apm-server configuration problem

**URL:** <https://discuss.elastic.co/t/apm-server-configuration-problem/244813>\
**Category:** APM\
**Tags:** server\
**Created:** [August 13, 2020, 7:19am UTC](https://discuss.elastic.co/t/apm-server-configuration-problem/244813 "2020-08-13T07:19:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![d.silwon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/d.silwon/32/65853_2.png) [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Post date:** [August 13, 2020, 7:19am UTC](https://discuss.elastic.co/t/apm-server-configuration-problem/244813/1 "2020-08-13T07:19:14Z")

</div>

Dears,

I need your help. I have problem with configuration apm-server. This is my configuration file:

```auto
apm-server:
  host: "node-01:8200"
output.elasticsearch:
  hosts: ["https://node-01:9200", "https://node-02:9200", "https://node-03:9200"]
  username: "elastic"
  password: "${ES_PWD}"
  ssl.certificate: "/etc/apm-server/certs/node-01.crt"
  ssl.key: "/etc/apm-server/certs/node-01.key"
logging.level: debug
logging.to_files: true
logging.files:
  path: /var/log/apm-server
  name: apm-server
  keepfiles: 7
  permissions: 0600

```

Log file show errors:

```auto
2020-08-13T09:14:44.538+0200 INFO [publisher_pipeline_output] pipeline/output.go:99 Attempting to reconnect to backoff(elasticsearch(https://node-02:9200)) with 11 reconnect attempt(s)
2020-08-13T09:14:44.538+0200 DEBUG [esclientleg] eslegclient/connection.go:239 ES Ping(url=https://node-02:9200)
2020-08-13T09:14:44.542+0200 DEBUG [esclientleg] eslegclient/connection.go:243 Ping request failed with: Get https://node-02:9200: x509: certificate signed by unknown authority
2020-08-13T09:14:58.458+0200 ERROR [publisher_pipeline_output] pipeline/output.go:106 Failed to connect to backoff(elasticsearch(https://node-03:9200)): Get https://node-03:9200: x509: certificate signed by unknown authority
2020-08-13T09:14:58.458+0200 INFO [publisher_pipeline_output] pipeline/output.go:99 Attempting to reconnect to backoff(elasticsearch(https://node-03:9200)) with 11 reconnect attempt(s)
2020-08-13T09:14:58.458+0200 DEBUG [esclientleg] eslegclient/connection.go:239 ES Ping(url=https://node-03:9200)
2020-08-13T09:14:58.474+0200 DEBUG [esclientleg] eslegclient/connection.go:243 Ping request failed with: Get https://node-03:9200: x509: certificate signed by unknown authority

```

Certs are OK. I use them for nodes communication, logstash configuration, metricbeat configuration.

I do not have any idea what is wrong. Do you have any idea what is wrong? Any help?

Best Regards,  
Dan

---

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [August 13, 2020, 7:51am UTC](https://discuss.elastic.co/t/apm-server-configuration-problem/244813/2 "2020-08-13T07:51:19Z")

</div>

It looks to me like you're using self-signed certificates. If that is the case, you should also set `output.elasticsearch.ssl.certificate_authorities`, as shown in [https://www.elastic.co/guide/en/apm/server/current/elasticsearch-output.html#elasticsearch-output](https://www.elastic.co/guide/en/apm/server/current/elasticsearch-output.html#elasticsearch-output)

---

<div class="post-metadata">

**Author:** ![d.silwon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/d.silwon/32/65853_2.png) [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Post date:** [August 13, 2020, 8:03am UTC](https://discuss.elastic.co/t/apm-server-configuration-problem/244813/3 "2020-08-13T08:03:27Z")

</div>

> [@axw](#):
>
> ssl.certificate\_authorities

@axw

Thanks for reply.

I changed the configuration:

```auto
apm-server:
  host: "node-01:8200"
output.elasticsearch:
  hosts: ["https://node-01:9200"]
  username: "elastic"
  password: "${ES_PWD}"
  ssl.certificate_authorities: "/etc/apm-server/certs/ca.crt"
  ssl.certificate: "/etc/apm-server/certs/node-01.crt"
  ssl.key: "/etc/apm-server/certs/node-01.key"
logging.level: debug
logging.to_files: true
logging.files:
  path: /var/log/apm-server
  name: apm-server
  keepfiles: 7
  permissions: 0600

```

but errors there are still:

```auto
2020-08-13T10:01:07.618+0200 INFO [publisher_pipeline_output] pipeline/output.go:99 Attempting to reconnect to backoff(elasticsearch(https://node-01:9200)) with 5 reconnect attempt(s)
2020-08-13T10:01:07.618+0200 DEBUG [esclientleg] eslegclient/connection.go:239 ES Ping(url=https://node-01:9200)
2020-08-13T10:01:07.623+0200 DEBUG [esclientleg] eslegclient/connection.go:243 Ping request failed with: Get https://node-01:9200: x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "Elastic Certificate Tool Autogenerated CA")
2020-08-13T10:01:59.626+0200 ERROR [publisher_pipeline_output] pipeline/output.go:106 Failed to connect to backoff(elasticsearch(https://node-01:9200)): Get https://node-01:9200: x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "Elastic Certificate Tool Autogenerated CA")
2020-08-13T10:01:59.626+0200 INFO [publisher_pipeline_output] pipeline/output.go:99 Attempting to reconnect to backoff(elasticsearch(https://node-01:9200)) with 6 reconnect attempt(s)
2020-08-13T10:01:59.626+0200 DEBUG [esclientleg] eslegclient/connection.go:239 ES Ping(url=https://node-01:9200)
2020-08-13T10:01:59.629+0200 DEBUG [esclientleg] eslegclient/connection.go:243 Ping request failed with: Get https://node-01:9200: x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "Elastic Certificate Tool Autogenerated CA")

```

Dan

---

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [August 13, 2020, 8:27am UTC](https://discuss.elastic.co/t/apm-server-configuration-problem/244813/4 "2020-08-13T08:27:41Z")

</div>

Is that the `ca.crt` the one that you used to sign `node-01.crt`?

I suggest taking apm-server out of the equation for a moment, and verifying the certificate with curl or similar. What happens if you run this?

```
curl --cacert /etc/apm-server/certs/ca.crt https://node-01:9200
```

---

<div class="post-metadata">

**Author:** ![d.silwon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/d.silwon/32/65853_2.png) [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Post date:** [August 13, 2020, 8:49am UTC](https://discuss.elastic.co/t/apm-server-configuration-problem/244813/5 "2020-08-13T08:49:40Z")

</div>

@axw

This is very important notice in log:

```auto
2020-08-13T10:01:07.623+0200 DEBUG [esclientleg] eslegclient/connection.go:243 Ping request failed with: Get https://node-01:9200: x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "Elastic Certificate Tool Autogenerated CA")

```

I comparated logstash and apm-server certs again and find that weren't the same. Creation date was different. I copied all certs from Logstash catalog to apm-server catalog and now every thing works well.

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2020, 8:50am UTC](https://discuss.elastic.co/t/apm-server-configuration-problem/244813/6 "2020-09-10T08:50:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
