# Certificates and keys for Kibana and Logstash with X-Pack

**URL:** <https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 28, 2018, 9:31pm UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390 "2018-09-28T21:31:19Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![lcui\_dxc](https://avatars.discourse-cdn.com/v4/letter/l/8edcca/32.png) [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Post date:** [September 28, 2018, 9:31pm UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/1 "2018-09-28T21:31:19Z")

</div>

Hello there,

I'm setting up the ELK security using X-Pack, I generated the CA and Certs as suggested by the docs:

bin/elasticsearch-certutil ca  
bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12

Shipped them to all the elasticseach nodes and worked fine.

On Kibana, per the document:  
[https://www.elastic.co/guide/en/kibana/6.3/configuring-tls.html](https://www.elastic.co/guide/en/kibana/6.3/configuring-tls.html)

It says:

" Generate a server certificate for Kibana.

You must either set the certificate’s `subjectAltName` to the hostname, fully-qualified domain name (FQDN), or IP address of the Kibana server, or set the CN to the Kibana server’s hostname or FQDN. Using the server’s IP address as the CN does not work."

My question is, how to generate this server certificate for Kibana? use the same tool on elasticsearch, elasticsearch-certutil ? could you please let me know how to use this tool to generate kibana server certificate?

Also, for logstash pipeline output to elasticsearch, what should we put in for "cacert =\>"?

I kept getting for following errors on logstash.log.... something to do with the setting for "cacert", in the pipeline. Please help.

[2018-09-28T20:07:08,459][ERROR][logstash.pipeline] Error registering plugin {:pipeline\_id=\>".monitoring-logstash", :plugin=\>"#LogStash::OutputDelegator:0x699a3513", :error=\>"signed fields invalid", :thread=\>"#\<Thread:0x75e04fbd run\>"}

[2018-09-28T20:07:08,461][ERROR][logstash.pipeline] Error registering plugin {:pipeline\_id=\>"main", :plugin=\>"#LogStash::OutputDelegator:0x4e79c8d8", :error=\>"signed fields invalid", :thread=\>"#\<Thread:0x2d9111c8@/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:48 run\>"}

Thanks a lot in adance

Li

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 1, 2018, 7:11am UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/2 "2018-10-01T07:11:28Z")

</div>

> My question is, how to generate this server certificate for Kibana?

This is slightly different. Users will access Kibana via their browser so the certificate that Kibana will use for https needs to be one that the browsers can trust. This usually means that you generate a CSR ( certificate signing request) and have it signed by a trusted (public or corporate) CA. You can use `elasticsearch-certutil` to create a CSR, see [elasticsearch-certutil | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/certutil.html#certutil-csr)

i.e

```auto
bin/elasticsearch-certutil csr --dns kibana.example.com 

```

Now, under certain circumstances ( i.e. if the number of users accessing Kibana is small, you can control the trust anchors in the users browsers or OSes, testing reasons, etc. ) you might want to use self signed certificates or certificates signed by a CA that the browsers do not trust by default. Keep in mind that this will cause the browser to show a warning.

You can use `elasticsearch-certutil` to create a server certificate for Kibana, but Kibana doesn't yet support the PKCS#12 format so you'd need to create a PEM encoded key and certificate ([by specifying the `--pem` parameter](https://www.elastic.co/guide/en/elasticsearch/reference/current/certutil.html#certutil-cert)). An example invocation would be:

```auto
bin/elasticsearch-certutil cert --pem -ca path/to/your.p12 --dns kibana.example.com

```

> Also, for logstash pipeline output to elasticsearch, what should we put in for "cacert =\>"?

You need to set the CA cert file that you have created with certutil. However, Elasticsearch output Logstash plugin doesn't support PKCS#12 format so you would need to export the CA certificate in PEM format as such :

```auto
openssl pkcs12 -in ca.p12 -clcerts -nokeys -chain -out ca.pem

```

and use that as the value of `cacert`

---

<div class="post-metadata">

**Author:** ![lcui\_dxc](https://avatars.discourse-cdn.com/v4/letter/l/8edcca/32.png) [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Post date:** [October 2, 2018, 7:54pm UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/3 "2018-10-02T19:54:18Z")

</div>

Thank you, I will try and see how it goes... this is very helpful.

---

<div class="post-metadata">

**Author:** ![lcui\_dxc](https://avatars.discourse-cdn.com/v4/letter/l/8edcca/32.png) [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Post date:** [October 3, 2018, 5:53am UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/4 "2018-10-03T05:53:40Z")

</div>

I regenerated the keys can certs... also, converted to .pem as suggested above...

It seems Kibana works fine, but on logstash, I used the ca.pem file for cacert. Now I got the following error in logstash.log and logstash is not pulling any data using any of the beats

[2018-10-03T04:44:13,747][ERROR][logstash.pipeline] Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<Manticore::UnknownException: Host name 'elastichostname' does not match the certificate subject provided by the peer (CN=instance)\>.

//////////////

Here is the logstash pipeline conf:

output {  
elasticsearch {  
user =\> "logstash\_ingest"  
password =\> "changeme"  
ssl =\> true  
ssl\_certificate\_verification =\> true  
cacert =\> "/etc/logstash/keys/elastic-stack-ca.pem"  
action =\> "index"  
hosts =\> ["elasticnodehostname"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"

////////////////////////

Here is logstash yml:

xpack.monitoring.enabled: true  
xpack.monitoring.elasticsearch.url: ["elasticnodehostname:9200"]  
xpack.monitoring.elasticsearch.ssl.ca: "/etc/logstash/keys/elastic-stack-ca.pem"  
xpack.monitoring.elasticsearch.sniffing: false  
xpack.monitoring.collection.interval: 60s  
/////////////////

Please let me know what I missed or did wrong....

Thanks a lot

Li

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 3, 2018, 7:45am UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/5 "2018-10-03T07:45:03Z")

</div>

Hi

The issue is that Logstash's Elasticsearch output plugin performs validation of the Certificate that Elasticsearch uses for TLS, as instructed

```auto
ssl_certificate_verification => true

```

and it fails because

> [@lcui\_dxc](#):
>
> Host name 'elastichostname' does not match the certificate subject provided by the peer (CN=instance)

This is because of a control named hostname validation, i.e. a control that either the CN or one of the SANs that are included in an X509 certificate match the hostname of the host that uses that certificate for TLS.

In more concrete terms you have created your certificate with a SAN of `XXXXX` (presumably passing `--dns XXXXX` in the certutil command) but your Elasticsearch host uses a hostname of `YYYYY` ( check what you use in `hosts => []` param in your`logstash.yml`. You need to make sure these two are match by changing one of them.

---

<div class="post-metadata">

**Author:** ![lcui\_dxc](https://avatars.discourse-cdn.com/v4/letter/l/8edcca/32.png) [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Post date:** [October 3, 2018, 8:56pm UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/6 "2018-10-03T20:56:01Z")

</div>

Hi Ikakavas,

Thank you for your patience...  
I'm really stuck at logstash SSL setup.

I generated the certs and keys for Kibana and logstash (they are on the same host) like:

bin/elasticsearch-certutil cert --pem -ca path/to/your.p12 --dns   
then, use openssl to get the ca.pem and use this pem for the value of "cacert".

I'm still getting the same error as below:

Error registering plugin {:pipeline\_id=\>".monitoring-logstash", :plugin=\>"#LogStash::OutputDelegator:0x6a818f22", :error=\>"Host name '' does not match the certificate subject provided by the peer (CN=instance)

Should we use logstash/kibane hostname to generate in "bin/elasticsearch-certutil cert --pem -ca path/to/your.p12 --dns ".

What should we put for the value of --dns, logstash hostname or elasticsearch hostname?

Thanks a lot

Li

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 4, 2018, 7:35am UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/7 "2018-10-04T07:35:45Z")

</div>

> [@lcui\_dxc](#):
>
> I generated the certs and keys for Kibana and logstash (they are on the same host) like:
> 
> bin/elasticsearch-certutil cert --pem -ca path/to/your.p12 --dns

Kibana is a server and requires a certificate to use for https when clients connect to it. This is what we were discussing [above](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/2?) but why did you create a certificate and key for Logstash. The only reason you need this is to do TLS client authentication of Logstash to Elasticsearch but your logstash's Elasticsearch output plugin configuration shows you don't do that.

> [@lcui\_dxc](#):
>
> Error registering plugin {:pipeline\_id=\>".monitoring-logstash", :plugin=\>"#LogStash::OutputDelegator:0x6a818f22", :error=\>"Host name '' does not match the certificate subject provided by the peer (CN=instance)

This is exactly the same error you encountered before and I explained above what that means:

> [@ikakavas](#):
>
> This is because of a control named hostname validation, i.e. a control that either the CN or one of the SANs that are included in an X509 certificate match the hostname of the host that uses that certificate for TLS.

> [@lcui\_dxc](#):
>
> Should we use logstash/kibane hostname to generate in "bin/elasticsearch-certutil cert --pem -ca path/to/your.p12 --dns ".

When you use this command to generate a key and certificate for Kibana, then you need to use the hostname or FQDN of kibana. This is however irrelevant to your logstash problem, see again my [answer](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/2) with regards to the the kibana certificate and if there are any questions on that we can discuss in a separate answer.

Take a step back from the above and let's focus on your logstash issues. Logstash attempts to communicate to Elasticsearch over https on port 9200. Elasticsearch is configured for TLS on the http layer ( you never showed your config but I assume from the errors ) with:

```auto
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: certs/elastic-certificates.p12 
xpack.security.http.ssl.truststore.path: certs/elastic-certificates.p12 

```

This `elastic-certificates.p12` contains the cert and the key that Elasticsearch uses for TLS on the http layer. Since you didn't provide a dns name when you ran the

```auto
bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12

```

command, the certificate was created with a default subject of `CN=instance` .  
For TLS, that means that when a client connects over https, Elasticsearch says "Hi, I'm `CN=instance`, this is my certificate"

Que to Logstash now. Same applies for monitoring and the Elasticsearch output plugin as your config is similar, but lets look at the output plugin as an example. You have it configured with

```auto
sl => true
ssl_certificate_verification => true
cacert => "/etc/logstash/keys/elastic-stack-ca.pem"
action => "index"
hosts => ["elasticnodehostname"]

```

This tells the plugin to connect to `https://elasticnodehostname:9200` and use `etc/logstash/keys/elastic-stack-ca.pem` to verify Elasticsearch's certificate. What happens is that the plugin connects to `https://elasticnodehostname:9200` and Elasticsearch replies with "Hi, I'm `CN=instance`, this is my certificate". The plugin can verify the certificate's authenticity as it _is_ signed by the `/etc/logstash/keys/elastic-stack-ca.pem` CA certificate, but hostname verification fails. The plugin connects to `elasticnodehostname` and Elasticsearch presents a certificate that says it is `CN=instance`.

Hope the above helps with understanding what the issue is.

To solve it, you need to make sure that the certificate that is included in the `certs/elastic-certificates.p12` that Elasticsearch uses have a correct DNS SAN in it so that it matches its hostname/FQDN. So for example if your Elasticsearch is reached at `https://my.elasticsearch.com:9200`, recreate `elastic-certificates.p12` with

```auto
bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12 --dns my.elasticsearch.com

```

---

<div class="post-metadata">

**Author:** ![lcui\_dxc](https://avatars.discourse-cdn.com/v4/letter/l/8edcca/32.png) [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Post date:** [October 4, 2018, 7:59pm UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/8 "2018-10-04T19:59:12Z")

</div>

Thank you very very much, indeed.  
I followed your suggestion, and now things are a lot of better.

Here is what I did:

On Elasticsearch node 1:

1. bin/elasticsearch-certutil ca
2. bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12 --dns\<[elasticnode1.com](http://elasticnode1.com)\>
3. bin /elasticsearch-certutil cert --pem -ca /path to/elastic-stack-ca.p12 --dns 
4. openssl pkcs12 -in elastic-stack-ca.p12 -clcerts -nokeys -chain -out elastic-stack-ca.pem
5. Copied the certs/pem/crts to kibana and logstash node (they are co-located on the same server).
6. Modified the kibnana.yml, it started fine
7. Mofdified the logstash.yml and pipeline.conf.

Here I have an issue. I have 2 elasticserch nodes, node1 and node2, I generated all the certs and crts on node1. Now, in the logstash.yml, if I put 2 nodes for xpack.monitoring.elasticsearch.url, logstash will complain about the node2, says it can connect to node2. If I remove only put node1 for xpack.monitoring.elasticsearch.url, it will work fine...  
I tried the set xpack.monitoring.elasticsearch.ssl.verification\_mode to none, still the same  
In the pipleline.conf for the value to 'Hosts", I can only use node1 there... cannot put node2 (didn't work for node2 either).

Here is the errors I got:

[2018-10-04T19:24:52,958][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"https://logstash\_ingest:xxxxxx@**[elasticnode1.com](http://elasticnode1.com)**:9200/"}  
[2018-10-04T19:24:53,015][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-10-04T19:25:03,047][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"https://logstash\_ingest:xxxxxx@ **elasticnode2**.com:9200/", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[https://logstash\_ingest:xxxxxx@elasticnode2.com:9200/](https://logstash_ingest:xxxxxx@elasticnode2.com:9200/)][Manticore::ConnectTimeout] Read timed out"}  
...  
[2018-10-04T20:21:50,389][WARN][logstash.outputs.elasticsearch] Error while performing resurrection {:error\_message=\>"Host name '**[elasticnode2.com](http://elasticnode2.com)**' does not match the certificate subject provided by the peer (CN=instance)", :class=\>"Manticore::UnknownException", :backtrace=\>

Here is the logstash.yml:

xpack.monitoring.enabled: true  
xpack.monitoring.elasticsearch.username: logstash\_system  
xpack.monitoring.elasticsearch.password: changeme  
xpack.monitoring.elasticsearch.url: ["[https://elasticnode1.com:9200](https://elasticnode1.com:9200)", "[https://elasticnode2.com:9200](https://elasticnode2.com:9200)"]  
#xpack.monitoring.elasticsearch.url: ["[https://elasticnode1.com:9200](https://elasticnode1.com:9200)"]  
xpack.monitoring.elasticsearch.ssl.ca: "/etc/logstash/keys/elastic-stack-ca.pem"  
xpack.monitoring.elasticsearch.ssl.verification\_mode: none  
xpack.monitoring.elasticsearch.sniffing: false  
xpack.monitoring.collection.interval: 60s  
#xpack.monitoring.collection.pipeline.details.enabled: true

Here is the pipeline.conf:

output {  
elasticsearch {  
user =\> "logstash\_system"  
password =\> "changeme"  
ssl =\> true  
ssl\_certificate\_verification =\> true  
cacert =\> "/etc/logstash/keys/elastic-stack-ca.pem"  
action =\> "index"  
hosts =\> ["[elasticnode1.com](http://elasticnode1.com)","[elasticnode2.com](http://elasticnode2.com)"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"

Here is the elasticsearch.yml (both nodes are same):

discovery.zen.ping.unicast.hosts: ["[elasticnode1.com](http://elasticnode1.com)", "[elasticnode2.com](http://elasticnode2.com)"]  
xpack.monitoring.enabled: true  
xpack.monitoring.collection.enabled: true  
xpack.monitoring.collection.interval: 60s  
xpack.monitoring.collection.cluster.stats.timeout: 60s  
xpack.monitoring.history.duration: 90d  
xpack.watcher.history.cleaner\_service.enabled: true  
xpack.http.proxy.host: '[ourproxyhostname.com](http://ourproxyhostname.com)'  
xpack.http.proxy.port: 3128  
xpack.watcher.enabled: true  
xpack.security.enabled: true  
xpack.security.http.ssl.enabled: true  
xpack.security.http.ssl.keystore.path: /etc/elasticsearch/keys/elastic-certificates.p12  
xpack.security.http.ssl.truststore.path: /etc/elasticsearch/keys/elastic-certificates.p12  
xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/keys/elastic-certificates.p12  
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/keys/elastic-certificates.p12  
xpack:  
security:  
authc:  
realms:  
active\_directory:  
type: active\_directory  
order: 0  
domain\_name: [xxx.yyy.com](http://xxx.yyy.com)  
files.role\_mapping: /etc/elasticsearch/role\_mapping.yml  
bind\_dn: CN=admin,CN=Users,DC=xxx,DC=yyy,DC=com  
bind\_password: password

The problem is that if elasticnode1 goes down, we will be losing connection between logstash and elasticsearch cluster (all the beats come in via the logstash). Could you please take a look and help?

Again, thank you very much for your help, indeed

Li

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 5, 2018, 10:00am UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/9 "2018-10-05T10:00:34Z")

</div>

> [@lcui\_dxc](#):
>
> 2 bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12 --dns\<[elasticnode1.com](http://elasticnode1.com)\>

This, as we discussed above, creates a PKCS12 store that contains the certificate that Elasticsearch will use for TLS. Since each Elasticsearch node has a different hostname you need to do this on each node with the correct `--dns` parameter each time. Copy _only_ the elastic-stack-ca.p12 to the second node and run

```auto
bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12 --dns elasticnode2.com 

```

on the second node. Then use that for setting

```auto
xpack.security.http.ssl.keystore.path: /etc/elasticsearch/keys/elastic-certificates.p12
xpack.security.http.ssl.truststore.path: /etc/elasticsearch/keys/elastic-certificates.p12

```

instead of the `elastic-certificates.p12` you had copied over from the first node.

> [@lcui\_dxc](#):
>
> 1. bin /elasticsearch-certutil cert --pem -ca /path to/elastic-stack-ca.p12 --dns

Do you do this to create the Kibana certificate ? If so, as I have mentioned already above:

1. You need to add something after `--dns`, and that is the hostname of Kibana, i.e. how your users will access it.
2. I'm just reiterating that this will be a certificate signed by a local CA and your users browsers won't trust it (Every user will get a warning and they'll need to add a security exception just to reach kibana). If this is an issue for you, I have already explained how you can generate a CSR [above](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/2) and then you can use that to get a certificate from a Trusted Certificate Authority.

---

<div class="post-metadata">

**Author:** ![lcui\_dxc](https://avatars.discourse-cdn.com/v4/letter/l/8edcca/32.png) [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Post date:** [October 5, 2018, 7:28pm UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/10 "2018-10-05T19:28:07Z")

</div>

Thank you very much for your help. This indeed helped me a lot..  
I think there will be more people facing the similar questions as I had, this post would help a lot...

Thanks a lot

Li

---

<div class="post-metadata">

**Author:** ![lcui\_dxc](https://avatars.discourse-cdn.com/v4/letter/l/8edcca/32.png) [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Post date:** [October 9, 2018, 5:06pm UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/11 "2018-10-09T17:06:08Z")

</div>

Hello again,

I set up the SSL /TLS on logstash/elasticsearch and kibnana as indicated above.  
Everything looks fine, all are up and running, and I can see the beats(file/metric/etc...) are sending data on Kibana (Discover) via logstash to elasticseach nodes.  
However, I still can see the following errors in the logstash-plain.log as blow. It complains all elastic nodes but beats pipeline seems working fine.

[2018-10-09T11:21:02,810][ERROR][logstash.licensechecker.licensereader] Unable to retrieve license information from license server {:message=\>"Host name 'elastiocnode1 IP' does not match the certificate subject provided by the peer (CN=instance)", :class=\>"Manticore::UnknownException", :backtrace=\>["/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/manticore-0.6.4-java/lib/manticore/response.rb:37:in `block in initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/manticore-0.6.4-java/lib/manticore/response.rb:79:in`call'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.2.0-java/lib/logstash/outputs/elasticsearch/http\_client/manticore\_adapter.rb:74:in `perform_request'" ... [2018-10-09T11:21:32,810][ERROR][logstash.licensechecker.licensereader] Unable to retrieve license information from license server {:message=>"Host name 'elastiocnode2 IP' does not match the certificate subject provided by the peer (CN=instance)", :class=>"Manticore::UnknownException", :backtrace=>["/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/manticore-0.6.4-java/lib/manticore/response.rb:37:in`block in initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/manticore-0.6.4-java/lib/manticore/response.rb:79:in `call'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-output-

...............

Here is the logstash.yml

# ============ xpack.monitoring.enabled: true xpack.monitoring.elasticsearch.username: logstash\_system xpack.monitoring.elasticsearch.password: changeme xpack.monitoring.elasticsearch.url: ["[https://elasticnode1:9200](https://elasticnode1:9200)", "[https://elasticnode2.hls.dxc.com:9200](https://elasticnode2.hls.dxc.com:9200)" ] xpack.monitoring.elasticsearch.ssl.truststore.path: "/etc/logstash/elastic-certificates.p12" xpack.monitoring.elasticsearch.ssl.truststore.password: password xpack.monitoring.elasticsearch.ssl.keystore.path: "/etc/logstash/elastic-certificates.p12" xpack.monitoring.elasticsearch.ssl.keystore.password: password xpack.monitoring.elasticsearch.ssl.verification\_mode: certificate xpack.monitoring.elasticsearch.sniffing: true xpack.monitoring.collection.interval: 60s xpack.monitoring.collection.pipeline.details.enabled: true

Here is the elasticsearch config on both elasticsearch nodes (each node has their own elastic-certificates.p12 corresponding to their own hostnames)

xpack.monitoring.enabled: true  
xpack.monitoring.collection.enabled: true  
xpack.monitoring.collection.interval: 60s  
xpack.monitoring.collection.cluster.stats.timeout: 60s  
xpack.monitoring.history.duration: 90d  
xpack.watcher.history.cleaner\_service.enabled: true  
xpack.http.proxy.host: 'proxy host'  
xpack.http.proxy.port: 3128  
xpack.watcher.enabled: true  
xpack.security.enabled: true  
xpack.security.http.ssl.enabled: true  
xpack.security.http.ssl.verification\_mode: certificate  
xpack.security.http.ssl.keystore.path: /etc/elasticsearch/keys/elastic-certificates.p12  
xpack.security.http.ssl.truststore.path: /etc/elasticsearch/keys/elastic-certificates.p12  
xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/keys/elastic-certificates.p12  
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/keys/elastic-certificates.p1

===================================

here is the beats pipeline config (beat-pipeline.conf):

# ================= input { beats { port =\> 5044 client\_inactivity\_timeout =\> 120 #ssl =\> false } } output { elasticsearch { user =\> "logstash\_ingest" password =\> "password" ssl =\> true ssl\_certificate\_verification =\> true cacert =\> "/etc/logstash/elastic-stack-ca.pem" action =\> "index" hosts =\> ["elactisnode1", "elasticnode2"] manage\_template =\> false index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}" document\_type =\> "%{[@metadata][type]}" } }

Please help and see if there is anything missing or incorrect, help is needed here, indeed.

Thanks a lot

Li

---

<div class="post-metadata">

**Author:** ![lcui\_dxc](https://avatars.discourse-cdn.com/v4/letter/l/8edcca/32.png) [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Post date:** [October 11, 2018, 5:00am UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/12 "2018-10-11T05:00:29Z")

</div>

Turned xpack.monitoring.elasticsearch.sniffing to false, the errors are gone.

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2018, 5:00am UTC](https://discuss.elastic.co/t/certificates-and-keys-for-kibana-and-logstash-with-x-pack/150390/13 "2018-11-08T05:00:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
