# Beats stopped working after enabled TLS/SSL on Elasticsearch and Kibana

**URL:** <https://discuss.elastic.co/t/beats-stopped-working-after-enabled-tls-ssl-on-elasticsearch-and-kibana/249354>\
**Category:** Beats\
**Tags:** packetbeat, winlogbeat, auditbeat\
**Created:** [September 21, 2020, 12:31pm UTC](https://discuss.elastic.co/t/beats-stopped-working-after-enabled-tls-ssl-on-elasticsearch-and-kibana/249354 "2020-09-21T12:31:31Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [September 21, 2020, 12:31pm UTC](https://discuss.elastic.co/t/beats-stopped-working-after-enabled-tls-ssl-on-elasticsearch-and-kibana/249354/1 "2020-09-21T12:31:32Z")

</div>

Winlogbeat,packetbeat,auditbeat stopped working right after enabling TLS/SSL between Elasticsearch and Kibana. Attached image is my configuration for winlogbeat.yml. I tried putting http **s** also but it is not working. Do I required to give SSL/TLS certificate to each client(host) ?

Also, I activated API and tried doing authentication through API `id:key` but no success.

 ![Selection_023](https://us1.discourse-cdn.com/elastic/original/3X/f/a/faaf112da8f0867e70fccc9ee661dccee00a5d2e.png)

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [September 21, 2020, 1:40pm UTC](https://discuss.elastic.co/t/beats-stopped-working-after-enabled-tls-ssl-on-elasticsearch-and-kibana/249354/2 "2020-09-21T13:40:18Z")

</div>

The following guide can help you with configuring TLS for all of the Beats you are using: [https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-ssl.html](https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-ssl.html)

Let me know if you need more guidance.

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [September 21, 2020, 2:14pm UTC](https://discuss.elastic.co/t/beats-stopped-working-after-enabled-tls-ssl-on-elasticsearch-and-kibana/249354/3 "2020-09-21T14:14:28Z")

</div>

I checked that documentation, I am not sure which files I should put there in `ssl.certificate` and `ssl.key` because I got only two files(http.p12 andelasticsearch-ca.pem ) while generating certificates for kibana and elasticsearch

 ![Selection_024](https://us1.discourse-cdn.com/elastic/original/3X/3/0/301a893f066f4464892dc02b71710cf7ce0bc927.png)

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [September 22, 2020, 6:50am UTC](https://discuss.elastic.co/t/beats-stopped-working-after-enabled-tls-ssl-on-elasticsearch-and-kibana/249354/4 "2020-09-22T06:50:08Z")

</div>

@kvch can you help on this ?

---

<div class="post-metadata">

**Author:** ![emahdij](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emahdij/32/73570_2.png) [@emahdij](https://discuss.elastic.co/u/emahdij)\
**Post date:** [September 22, 2020, 7:26am UTC](https://discuss.elastic.co/t/beats-stopped-working-after-enabled-tls-ssl-on-elasticsearch-and-kibana/249354/5 "2020-09-22T07:26:04Z")

</div>

Hi,  
You can generate ca.crt certificate and use it like below

```auto
output.elasticsearch:
  hosts: ["node-1:9200"]
  ssl.certificate_authorities: "C:/ProgramData/Elastic/Beats/winlogbeat/ca.crt"
  protocol: "https"
  username: "elastic"
  password: "ChangeMe"

```

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [September 22, 2020, 9:14am UTC](https://discuss.elastic.co/t/beats-stopped-working-after-enabled-tls-ssl-on-elasticsearch-and-kibana/249354/6 "2020-09-22T09:14:01Z")

</div>

I tried this but not working.

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [September 22, 2020, 10:30am UTC](https://discuss.elastic.co/t/beats-stopped-working-after-enabled-tls-ssl-on-elasticsearch-and-kibana/249354/7 "2020-09-22T10:30:16Z")

</div>

This is resolved. I stopped my all beats agent to verify ssl certificate all the time. It will accept any certificate happily by adding `ssl.verification_mode: none` in all `winlogbeat.yml,packetbeat.yml,auditbeat.yml`.

**Note : this is for development purpose only, please dont use it in production stack.**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2020, 12:30pm UTC](https://discuss.elastic.co/t/beats-stopped-working-after-enabled-tls-ssl-on-elasticsearch-and-kibana/249354/8 "2020-10-20T12:30:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
