# Beats SSL question

**URL:** https://discuss.elastic.co/t/beats-ssl-question/50316
**Category:** Beats
**Created:** [May 18, 2016, 8:29am UTC](https://discuss.elastic.co/t/beats-ssl-question/50316 "2016-05-18T08:29:36Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)
#### Post date: [May 18, 2016, 8:29am UTC](https://discuss.elastic.co/t/beats-ssl-question/50316/1 "2016-05-18T08:29:36Z")

</div>

Hello all,

I would just like to clarify if I understand this correctly. In the documentation it states that to use client certificate validation the SSL certificates need to be signed directly by the root ca.

So, if I have a client certificate with the path (Root CA) -\> (Issuing CA) -\> (Client Certificate) this is not going to work?

First, I used an SSL client certificate on the logstash side, with the winlogbeat side config using only certificate\_authorities for ssl checking. It was working ok. Now I'm trying to setup a client certificate for the winlogbeat, but it´s not connecting anymore. I'm trying to figure out if it is normal since my certificate is not signed directly by the rootCA or is my understanding of how to set it up somehow wrong. I'm using the same IssuerCA for all examples. I also tested the connectivity with curl and it looks ok.

Thank you in advance for help.

Kind regards,

Uros

---

<div class="post-metadata">

### Author: ![dickepa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dickepa/32/8069_2.png) [@dickepa](https://discuss.elastic.co/u/dickepa)
#### Post date: [May 18, 2016, 9:26am UTC](https://discuss.elastic.co/t/beats-ssl-question/50316/2 "2016-05-18T09:26:42Z")

</div>

Hi Uros,

Have you had a look at anti virus or firewall apps on the Windows machine? Try excluding the Winlogbeat folder. This worked for me.

IMO: I do not believe the documentation is aimed at enterprise solutions and I think certs are best served by an existing CA within your network. Manually copying and moving certificates is clumbersum.

Logstash or Elasticsearch and encryption? Not sure what your set-up is and I'm new to this myself but I was advised to send Windows beats direct to Elasticsearch on the ELK stack. However yet to get that working because I am stuck in template hell! The reason why I mention it, is because I think this can use HTTPS. [https://www.elastic.co/guide/en/beats/winlogbeat/master/securing-communication-elasticsearch.html](https://www.elastic.co/guide/en/beats/winlogbeat/master/securing-communication-elasticsearch.html)

Paul

---

<div class="post-metadata">

### Author: ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)
#### Post date: [May 18, 2016, 10:42am UTC](https://discuss.elastic.co/t/beats-ssl-question/50316/3 "2016-05-18T10:42:26Z")

</div>

Hey Paul,

thanks for your answer.

After some more troubleshooting, I found out that the problem was with ssl\_verify\_mode in my logstash config. I have set it to force\_peer and it somehow doesn't like my settings. Probably something not resolving or I have to add something like the IP or something to the client certificate. If I set it to just "peer" it works. Yey.

I don't quite understand what the difference regarding the certificate checking between the settings "force\_peer" and only "peer" is.

Kind regards,  
Uros

---

<div class="post-metadata">

### Author: ![dickepa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dickepa/32/8069_2.png) [@dickepa](https://discuss.elastic.co/u/dickepa)
#### Post date: [May 18, 2016, 11:24am UTC](https://discuss.elastic.co/t/beats-ssl-question/50316/4 "2016-05-18T11:24:48Z")

</div>

No problem Uros glad to know that you fixed it. Any chance of sharing your logstash config? I haven't come across the "peer" setting yet, might be good to share.

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [May 18, 2016, 11:39am UTC](https://discuss.elastic.co/t/beats-ssl-question/50316/5 "2016-05-18T11:39:18Z")

</div>

There are 3 different modes for client auth. 'none', 'peer' and 'force\_peer'. The 'peer' option is kind of optional, but ignores client\_authentication at will.

I think the jruby SSL implementation has a bug not correctly verifying certificates if intermediates are used.

---

<div class="post-metadata">

### Author: ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)
#### Post date: [May 18, 2016, 12:08pm UTC](https://discuss.elastic.co/t/beats-ssl-question/50316/6 "2016-05-18T12:08:31Z")

</div>

@steffens: So, if I set it to peer it will not use SSL client authentication, but the transport is still encrypted. Not quite the solution I was looking for. I need to have client authentication working. I will try to set up my own CA (without any intermediates) and test the config with new certs and force\_peer.

@dickepa: the setting is ssl\_verify\_mode for the beats input plugin. This is my test logstash config just for testing this ssl stuff. It is quite basic:

beats {  
port =\> 5044  
ssl =\> true  
ssl\_verify\_mode =\> peer  
ssl\_certificate\_authorities =\> ["/etc/pki/root-ca.cer", "/etc/pki/xxxxxx.cer"]  
ssl\_certificate =\> "/etc/pki/xxxxxxxx.xxx.local.cer"  
ssl\_key =\> "/etc/pki/xxxxxxxxx.xxxx.local.key"

}

---

<div class="post-metadata">

### Author: ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)
#### Post date: [May 20, 2016, 8:22am UTC](https://discuss.elastic.co/t/beats-ssl-question/50316/7 "2016-05-20T08:22:00Z")

</div>

Just a follow up...

I set up my own CA and behold everything started to work as expected. Even with the force\_peer option set. The only problem I stumbled upon was self inflicted, because I issued the certificate got winlogbeat as a server certificate and it failed at handshake. Reissued as a client certificate and voila. Everything perfect.

On the intermediate CA regard, when is this going to be supported in jruby? Anyone knows? There seems to be a lot of docs that state that using intermediate CAs to sign certificates is best practise.

Kind regards,

Uros

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [May 20, 2016, 9:52am UTC](https://discuss.elastic.co/t/beats-ssl-question/50316/8 "2016-05-20T09:52:59Z")

</div>

No idea about the jruby part. I was told there has been a pull request fixing the issue, but it was not merged.

It's a [known issue taken care of by logstash team](https://github.com/logstash-plugins/logstash-input-beats/issues/64), but I've no idea when this will be fixed.

---

<div class="post-metadata">

### Author: ![Uros\_Meglic](https://avatars.discourse-cdn.com/v4/letter/u/edb3f5/32.png) [@Uros\_Meglic](https://discuss.elastic.co/u/Uros_Meglic)
#### Post date: [May 23, 2016, 1:57pm UTC](https://discuss.elastic.co/t/beats-ssl-question/50316/9 "2016-05-23T13:57:17Z")

</div>

Just an update (again). 🙂

Your link actually took me to the solution for my problem. There is a ticket open for clarification of this behaviour and there is also a workaround (sort of) posted in the ticket. If you merge all the certificates in the chain to one file it works even if you are using intermediate CAs.

I have tested it in my environment and it works!

Thanks.

Kind regards,  
Uros

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [May 23, 2016, 4:07pm UTC](https://discuss.elastic.co/t/beats-ssl-question/50316/10 "2016-05-23T16:07:52Z")

</div>

Awesome, thanks!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 9:51pm UTC](https://discuss.elastic.co/t/beats-ssl-question/50316/11 "2017-07-05T21:51:37Z")

</div>


