# Certificate issues lumberjack as output plugin

**URL:** <https://discuss.elastic.co/t/certificate-issues-lumberjack-as-output-plugin/72836>\
**Category:** Logstash\
**Created:** [January 25, 2017, 11:49pm UTC](https://discuss.elastic.co/t/certificate-issues-lumberjack-as-output-plugin/72836 "2017-01-25T23:49:06Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhinigam](https://avatars.discourse-cdn.com/v4/letter/a/e495f1/32.png) [@abhinigam](https://discuss.elastic.co/u/abhinigam)\
**Post date:** [January 25, 2017, 11:49pm UTC](https://discuss.elastic.co/t/certificate-issues-lumberjack-as-output-plugin/72836/1 "2017-01-25T23:49:06Z")

</div>

I am using a self signed client certificate and configuring the same in my lumberjack output plugin. However, when my logstash forwarder on the client machines tries to talk to the logstash aggregator I am getting the following error:  
"OpenSSL::SSL::SSLError: Socket closed\>, :backtrace=\>["org/jruby/ext/openssl/SSLSocket.java:215:in `connect'""

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 29, 2017, 6:50pm UTC](https://discuss.elastic.co/t/certificate-issues-lumberjack-as-output-plugin/72836/2 "2017-01-29T18:50:29Z")

</div>

What's do the Logstash configurations look like (both instances)? Is there anything in the log of the receiving Logstash?

---

<div class="post-metadata">

**Author:** ![abhinigam](https://avatars.discourse-cdn.com/v4/letter/a/e495f1/32.png) [@abhinigam](https://discuss.elastic.co/u/abhinigam)\
**Post date:** [January 30, 2017, 6:28pm UTC](https://discuss.elastic.co/t/certificate-issues-lumberjack-as-output-plugin/72836/3 "2017-01-30T18:28:38Z")

</div>

Thanks for checking back with me. I added the certificates to the list of accepted CAs using keytool and also  
made sure the client certificate contained the IP address of the logstash forwarder which I was using to emit the logstash entries through lumberjack and it worked.

I have a followup question though. We are using this setup in AWS environment and since the IP addresses are  
dynamic how do I manage client certificates. It seems lumberjack plugin requires client side certificates. It is not  
optional.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 31, 2017, 6:39am UTC](https://discuss.elastic.co/t/certificate-issues-lumberjack-as-output-plugin/72836/4 "2017-01-31T06:39:53Z")

</div>

> It seems lumberjack plugin requires client side certificates.

No. What gives you that idea?

---

<div class="post-metadata">

**Author:** ![abhinigam](https://avatars.discourse-cdn.com/v4/letter/a/e495f1/32.png) [@abhinigam](https://discuss.elastic.co/u/abhinigam)\
**Post date:** [January 31, 2017, 6:37pm UTC](https://discuss.elastic.co/t/certificate-issues-lumberjack-as-output-plugin/72836/5 "2017-01-31T18:37:42Z")

</div>

Magnus,  
[https://www.elastic.co/guide/en/logstash/current/plugins-outputs-lumberjack.html](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-lumberjack.html)  
I saw that "ssl\_certificate" is required. Can you please give more insight into what this certificate represents.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 1, 2017, 7:01am UTC](https://discuss.elastic.co/t/certificate-issues-lumberjack-as-output-plugin/72836/6 "2017-02-01T07:01:46Z")

</div>

That's the server's certificate, not the client's.

---

<div class="post-metadata">

**Author:** ![AbhiMedallia](https://avatars.discourse-cdn.com/v4/letter/a/b5e925/32.png) [@AbhiMedallia](https://discuss.elastic.co/u/AbhiMedallia)\
**Post date:** [February 1, 2017, 11:48pm UTC](https://discuss.elastic.co/t/certificate-issues-lumberjack-as-output-plugin/72836/7 "2017-02-01T23:48:17Z")

</div>

Magnus,  
I just want to make sure I understand. The log stash lumberjack input plugin has a server certificate.  
Log stash lumberjack output plugin (the forwarder) also needs to have the exact same server certificate.

Is this right? I thought the output plugin would have the client certificate if we needed bidirectional authentication.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 2, 2017, 6:31am UTC](https://discuss.elastic.co/t/certificate-issues-lumberjack-as-output-plugin/72836/8 "2017-02-02T06:31:58Z")

</div>

> I just want to make sure I understand. The log stash lumberjack input plugin has a server certificate.  
> Log stash lumberjack output plugin (the forwarder) also needs to have the exact same server certificate.

Yes. This allows the client to authenticate the server it's connecting to.

> I thought the output plugin would have the client certificate if we needed bidirectional authentication.

Bidirectional authentication isn't supported.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2017, 6:32am UTC](https://discuss.elastic.co/t/certificate-issues-lumberjack-as-output-plugin/72836/9 "2017-03-02T06:32:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
