# Bad certificate error

**URL:** <https://discuss.elastic.co/t/bad-certificate-error/146240>\
**Category:** Logstash\
**Created:** [August 27, 2018, 8:06pm UTC](https://discuss.elastic.co/t/bad-certificate-error/146240 "2018-08-27T20:06:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nina\_brown](https://avatars.discourse-cdn.com/v4/letter/n/ecccb3/32.png) [@Nina\_brown](https://discuss.elastic.co/u/Nina_brown)\
**Post date:** [August 27, 2018, 8:06pm UTC](https://discuss.elastic.co/t/bad-certificate-error/146240/1 "2018-08-27T20:06:26Z")

</div>

Hi, I want to create a self-signed certificate based on the IP of the logstash server, so my filebeat connection to logstash would be secure. I used the following command to generate the certificate:  
`openssl req -config /etc/ssl/openssl.cnf -x509 -days 3650 -batch -nodes -newkey rsa:2048 -keyout /etc/logstash/ssl/logstash-forwarder.key -out /etc/logstash/ssl/logstash-forwarder.crt`

when I check the certificate from the filebeat client by :  
curl -v --cacert /etc/filebeat/logstash-forwarder.crt [https://142.245.169.21:5443](https://142.245.169.21:5443)  
I get the following error:  
\* About to connect() to 142.245.169.21 port 5443 (#0)  
\* Trying 142.245.169.21... connected  
\* Connected to 142.245.169.21 (142.245.169.21) port 5443 (#0)  
\* Initializing NSS with certpath: sql:/etc/pki/nssdb  
\* CAfile: /etc/filebeat/logstash-forwarder.crt  
CApath: none  
\* SSL connection using TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256  
\* Server certificate:  
\* subject: O=Internet Widgits Pty Ltd,ST=Some-State,C=AU  
\* start date: Aug 27 03:11:47 2018 GMT  
\* expire date: Aug 24 03:11:47 2028 GMT  
\* common name: (nil)  
\* issuer: O=Internet Widgits Pty Ltd,ST=Some-State,C=AU  
\> GET / HTTP/1.1  
\> User-Agent: curl/7.19.7 (x86\_64-redhat-linux-gnu) libcurl/7.19.7 NSS/3.27.1 zlib/1.2.3 libidn/1.18 libssh2/1.4.2  
\> Host: 142.245.169.21:5443  
\> Accept: _/_  
\>  
\* SSL read: errno -5961  
\* Closing connection #0  
curl: (56) SSL read: errno -5961

and file beat log shows this error:  
filebeat -c filebeat.yml -e -v  
error: Failed to publish events: write tcp 192.168.0.190:47258-\>142.245.169.21:5443: write: connection reset by peer

I don't know how to create a valid self-signed certificate for the server such that logstash accepts it. Can someone please help me with that?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 28, 2018, 4:04am UTC](https://discuss.elastic.co/t/bad-certificate-error/146240/2 "2018-08-28T04:04:10Z")

</div>

I have moved this from the Elasticsearch forum to Logstash.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 28, 2018, 8:44am UTC](https://discuss.elastic.co/t/bad-certificate-error/146240/3 "2018-08-28T08:44:17Z")

</div>

What does your Logstash configuration look like? What does your Filebeat configuration look like? Format all log files as preformatted text.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2018, 8:44am UTC](https://discuss.elastic.co/t/bad-certificate-error/146240/4 "2018-09-25T08:44:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
