# Beats output to logstash using SSL and Cert Errors

**URL:** https://discuss.elastic.co/t/beats-output-to-logstash-using-ssl-and-cert-errors/324689
**Category:** Beats
**Tags:** winlogbeat
**Created:** [February 3, 2023, 8:28pm UTC](https://discuss.elastic.co/t/beats-output-to-logstash-using-ssl-and-cert-errors/324689 "2023-02-03T20:28:53Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)
#### Post date: [February 3, 2023, 8:28pm UTC](https://discuss.elastic.co/t/beats-output-to-logstash-using-ssl-and-cert-errors/324689/1 "2023-02-03T20:28:53Z")

</div>

I am testing SSL from 7.x Beats clients to logstash. Logstash is configured for a wildcard cert to my domain, call it \*.acme.com. Connection works fine if Beats is configured to use a FQDN entry in the output, like [log.acme.com](http://log.acme.com). But I have remote locations where I can't control DNS, so I currently use just IP's for the Beats output to logstash. The Beats output is thus like:  
output.logstash:  
hosts: ["10.1.1.100:5045", "[log.acme.com:5045](http://log.acme.com:5045)"]  
ssl.enabled: true  
ssl:  
verification\_mode: none  
client\_authentication: none

This fails for the 10.1.1.100 logger but not the FQDN host. This is the beats log: x509: cannot validate certificate for 10.1.1.100 because it doesn't contain any IP SANs.  
This is tcpdump from logstash org.logstash.beats.BeatsHandler][main][[local: 10.1.1.100:5045, remote: 10.1.1.2:5782] Handling exception: io.netty.handler.codec.DecoderException: [javax.net](http://javax.net/).ssl.SSLHandshakeException: Received fatal alert: bad\_certificate (caused by: [javax.net](http://javax.net/).ssl.SSLHandshakeException: Received fatal alert: bad\_certificate)

Per the description at [Configure SSL | Winlogbeat Reference [7.17] | Elastic](https://www.elastic.co/guide/en/beats/winlogbeat/7.17/configuration-ssl.html#configuration-ssl),  
ssl:  
verification\_mode: none  
SHOULD allow this to work but it definitely is not. Of course, Elastic provides no examples so I can't tell if there might be a syntax issue or what.

Can anyone tell me if this SHOULD work and/or if there is a fix for it?  
Thanks

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 3, 2023, 10:29pm UTC](https://discuss.elastic.co/t/beats-output-to-logstash-using-ssl-and-cert-errors/324689/2 "2023-03-03T22:29:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
