# CA Signed Certificate Not Working

**URL:** <https://discuss.elastic.co/t/ca-signed-certificate-not-working/46523>\
**Category:** Logstash\
**Created:** [April 6, 2016, 12:24pm UTC](https://discuss.elastic.co/t/ca-signed-certificate-not-working/46523 "2016-04-06T12:24:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ltwarner](https://avatars.discourse-cdn.com/v4/letter/l/51bf81/32.png) [@ltwarner](https://discuss.elastic.co/u/ltwarner)\
**Post date:** [April 6, 2016, 12:24pm UTC](https://discuss.elastic.co/t/ca-signed-certificate-not-working/46523/1 "2016-04-06T12:24:37Z")

</div>

Hey there,

I am working to setup a Logstash and Beats (file and winlog). I have everything working for a self-signed certificate on LogStash and Beats , but if I try to create a CA signed Certificate I keep getting on the  
**ERR SSL client failed to connect with: x509: certificate is valid for RootCA not servername**  
I have copied the signed CRT and Key file to the Beats client but keep getting the same error. if I swap back to the Self-Signed cert works with no issues (logstash and beats)

I created dedicated CSR which was signed and the certificate is valid. This is the openssl command used to create the CSR.  
openssl req -new -key /etc/pki/tls/private/private.key -out /etc/pki/tls/certs/server.csr -subj '/C=UK/ST=State/L=Location/O=Company/CN=[server2.fqdn.com/emailAddress=mail@mail.com/subjectAltName=DNS.1=server1.fqdn.com,DNS.2=server3.fqdn.com,DNS.3=server4.fqdn.com](http://server2.fqdn.com/emailAddress=mail@mail.com/subjectAltName=DNS.1=server1.fqdn.com,DNS.2=server3.fqdn.com,DNS.3=server4.fqdn.com)'

I have included multiple SAN's as potentially there will be multiple logstash servers that the environment could c  
connect to.

Any help is appreciated

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 7, 2016, 12:03am UTC](https://discuss.elastic.co/t/ca-signed-certificate-not-working/46523/2 "2016-04-07T00:03:31Z")

</div>

You may want to move to filebeats, LSF is deprecated and will become unsupported at some point in the future.

---

<div class="post-metadata">

**Author:** ![ltwarner](https://avatars.discourse-cdn.com/v4/letter/l/51bf81/32.png) [@ltwarner](https://discuss.elastic.co/u/ltwarner)\
**Post date:** [April 7, 2016, 6:54am UTC](https://discuss.elastic.co/t/ca-signed-certificate-not-working/46523/3 "2016-04-07T06:54:36Z")

</div>

I am already using filebeats and not LSF. I have exactly the same issue with Winlogbeats.

I am only using LogStash on the ELK stack servers.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 7, 2016, 7:04am UTC](https://discuss.elastic.co/t/ca-signed-certificate-not-working/46523/4 "2016-04-07T07:04:41Z")

</div>

So this is a beats question, as you have posted it in the LSF area, hence my comment.

---

<div class="post-metadata">

**Author:** ![ltwarner](https://avatars.discourse-cdn.com/v4/letter/l/51bf81/32.png) [@ltwarner](https://discuss.elastic.co/u/ltwarner)\
**Post date:** [April 7, 2016, 7:18am UTC](https://discuss.elastic.co/t/ca-signed-certificate-not-working/46523/5 "2016-04-07T07:18:16Z")

</div>

Sorry, it is more a Logstash \<-\> Beats connection issue. I have updated accordingly.

---

<div class="post-metadata">

**Author:** ![mnhan](https://avatars.discourse-cdn.com/v4/letter/m/8baadc/32.png) [@mnhan](https://discuss.elastic.co/u/mnhan)\
**Post date:** [April 7, 2016, 2:07pm UTC](https://discuss.elastic.co/t/ca-signed-certificate-not-working/46523/6 "2016-04-07T14:07:04Z")

</div>

This is how I got it to work. I put both the CA cert thta signed my logstash cert and the logstash cert into the filebeat.yml like so:

certificate\_authorities: ["ca.cert", "logstash.cert"]

then my filebeat is able to validate my logtash server via its signed cert. my logstash input only has its cert and key.

Currently trying to upgrade to the latest filebeat/logstash/ES so I can do the client cert to further lock down my logstash. Got to get the latest version blessed by the powers-that-be before i can use it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:03am UTC](https://discuss.elastic.co/t/ca-signed-certificate-not-working/46523/7 "2017-07-06T05:03:19Z")

</div>


