# "bad\_certificate" error on elasticsearch input plugin

**URL:** <https://discuss.elastic.co/t/bad-certificate-error-on-elasticsearch-input-plugin/288812>\
**Category:** Logstash\
**Created:** [November 9, 2021, 7:09pm UTC](https://discuss.elastic.co/t/bad-certificate-error-on-elasticsearch-input-plugin/288812 "2021-11-09T19:09:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![plubbs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/plubbs/32/96926_2.png) [@plubbs](https://discuss.elastic.co/u/plubbs)\
**Post date:** [November 9, 2021, 7:09pm UTC](https://discuss.elastic.co/t/bad-certificate-error-on-elasticsearch-input-plugin/288812/1 "2021-11-09T19:09:59Z")

</div>

Hello,

TLDR - Our certificate we use with the output-Elasticsearch plugin does not work on the input-Elasticsearch plugin despite being a valid certificate

We are currently attempting to connect to an existing index in our ES setup to grab already-parsed logs for reprocessing/dedupe operations. However using the following ES input configuration:

```auto
input {
  elasticsearch {
    hosts => ["<ES hosts we are connecting to>"]
    ssl => true
    ca_file => "/etc/logstash/certs/ca-chain.cert.pem"
    user => "<username"
    password => "<password>"
    index => "<source index>"
    query => '{ "sort": ["_doc"] }'
  }
}

```

we run into the following error stack despite the specified .pem file being used in output directives without issue in other configurations:

```auto
[2021-11-09T17:53:37,972][ERROR][logstash.javapipeline][cf_dedupe][a13600946a868fde8267e8615aee0f8243ae83d056df9647cc61e26ede6849f8] A plugin had an unrecoverable error. Will restart this plugin.
[SNIP]
  Error: Received fatal alert: bad_certificate

```

and on the source ES server we see the following:

```auto
[2021-11-09T18:03:21,991][WARN][o.e.h.AbstractHttpServerTransport] [dev-elastic-1] caught exception while handling client http traffic, closing connection Netty4HttpChannel{localAddress=XXX, remoteAddress=XXX}
io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: Empty client certificate chain
        at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:471) ~[netty-codec-4.1.49.Final.jar:4.1.49.Final]

```

the .pem file being referenced for the input path has been successfully used in our output plugins to write to ES in perpetuity and when examining the file in question it has both root and intermediate CAs with valid/non-expired dates so it seems very puzzling that this is not working.

Has anyone experienced this particular issue or a variation on it and, if so, what did you end up doing to make it work?

Thank you,  
Peter

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 9, 2021, 7:23pm UTC](https://discuss.elastic.co/t/bad-certificate-error-on-elasticsearch-input-plugin/288812/2 "2021-11-09T19:23:03Z")

</div>

> [@plubbs](#):
>
> `Empty client certificate chain`

That seems to be the elasticsearch server complaining that a client did not send a certificate to authenticate the client. I do not know whether logstash can be configured to send a client certificate.

---

<div class="post-metadata">

**Author:** ![plubbs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/plubbs/32/96926_2.png) [@plubbs](https://discuss.elastic.co/u/plubbs)\
**Post date:** [November 9, 2021, 7:39pm UTC](https://discuss.elastic.co/t/bad-certificate-error-on-elasticsearch-input-plugin/288812/3 "2021-11-09T19:39:21Z")

</div>

I figured with the [ca-file option](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-elasticsearch.html#plugins-inputs-elasticsearch-ca_file) that it would send a certificate. Taking a step back to give some context we're attempting to scan an existing index for duplicates and then port the dupes into a new index per [this documentation](https://www.elastic.co/blog/how-to-find-and-remove-duplicate-documents-in-elasticsearch) which suggested the `elasticsearch` plugin for gathering the existing dataset, running the `fingerprint` filter, and then pushing tagged entries to a new index. Typically our logs on our infrastructure are using Kafka and then porting into ES so this is our first attempt to use the `elasticsearch` plugin to reprocess existing logs as oppose to ingesting from another source.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 9, 2021, 7:46pm UTC](https://discuss.elastic.co/t/bad-certificate-error-on-elasticsearch-input-plugin/288812/4 "2021-11-09T19:46:19Z")

</div>

> [@plubbs](#):
>
> I figured with the [ca-file option](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-elasticsearch.html#plugins-inputs-elasticsearch-ca_file) that it would send a certificate.

No, it just configures the chain used to verify the certificate that the elasticsearch server presents.

---

<div class="post-metadata">

**Author:** ![plubbs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/plubbs/32/96926_2.png) [@plubbs](https://discuss.elastic.co/u/plubbs)\
**Post date:** [November 10, 2021, 2:25pm UTC](https://discuss.elastic.co/t/bad-certificate-error-on-elasticsearch-input-plugin/288812/5 "2021-11-10T14:25:07Z")

</div>

Is there any way to provide a client certificate within the options of this plugin so that reads against the cluster for reprocessing on existing/filtered logs are secure? From the outline in [here](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-elasticsearch.html) the `ca_file` option seemed like it was the option I was looking for, but if there is another option (or plugin, for that matter) to pull indexed logs back in for reprocessing then any pointers would be helpful. It seems like a major limitation if Logstash can't pull from ES if it's secured without an option to provide a key/cert...

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 10, 2021, 2:40pm UTC](https://discuss.elastic.co/t/bad-certificate-error-on-elasticsearch-input-plugin/288812/6 "2021-11-10T14:40:22Z")

</div>

> [@plubbs](#):
>
> Is there any way to provide a client certificate within the options of this plugin

I do not think so. See [here](https://github.com/logstash-plugins/logstash-input-elasticsearch/issues/115), [here](https://github.com/logstash-plugins/logstash-input-elasticsearch/issues/96), [here](https://github.com/logstash-plugins/logstash-input-elasticsearch/issues/71) and [here](https://github.com/logstash-plugins/logstash-input-elasticsearch/pull/80).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2021, 2:41pm UTC](https://discuss.elastic.co/t/bad-certificate-error-on-elasticsearch-input-plugin/288812/7 "2021-12-08T14:41:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
