# Configuring aerospike metricbeat module with TLS

**URL:** https://discuss.elastic.co/t/configuring-aerospike-metricbeat-module-with-tls/294729
**Category:** Beats
**Tags:** beats-module, metricbeat
**Created:** [January 18, 2022, 7:14pm UTC](https://discuss.elastic.co/t/configuring-aerospike-metricbeat-module-with-tls/294729 "2022-01-18T19:14:17Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![sentient](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sentient/32/34996_2.png) [@sentient](https://discuss.elastic.co/u/sentient)
#### Post date: [January 18, 2022, 7:14pm UTC](https://discuss.elastic.co/t/configuring-aerospike-metricbeat-module-with-tls/294729/1 "2022-01-18T19:14:17Z")

</div>

I am looking at the code

> <https://github.com/elastic/beats/blob/master/metricbeat/module/aerospike/aerospike.go>

and trying to figure out how I should configure TLS certificates to get access to the aerospike service endpoint with TLS configured.

Does anybody have a successful module configuration example for this?

I tried

```auto
   - module: aerospike
     metricsets: ["namespace"]
     enabled: true
     period: 10s
     hosts: ["localhost:3000"]
     ssl.certificate: /my_aerospike_certs/cert.pem
     ssl.key: /my_aerospike_certs/key.pem
     ssl.certificate_authorities: /my_aerospike_certs/ca.pem

```

but I keep getting this error

127.0.0.1:3000: read: connection reset by peer

Not sure when these ssl. are being applied in the module code

Thanks for any help

---

<div class="post-metadata">

### Author: ![sentient](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sentient/32/34996_2.png) [@sentient](https://discuss.elastic.co/u/sentient)
#### Post date: [January 28, 2022, 5:12pm UTC](https://discuss.elastic.co/t/configuring-aerospike-metricbeat-module-with-tls/294729/2 "2022-01-28T17:12:04Z")

</div>

Looking at the elastic code implementation and the aerospike client api,  
this functionality is not implemented.  
It should be something like this:

```auto
	serverCertPool, clientCertPool := readCertificates(*serverCertDir, *clientCertFile, *clientKeyFile)

	clientPolicy := as.NewClientPolicy()

	if len(*tlsName) > 0 || *encryptOnly == true {
		// Setup TLS Config
		tlsConfig := &tls.Config{
			Certificates: clientCertPool,
			RootCAs: serverCertPool,
			InsecureSkipVerify: *encryptOnly,
			PreferServerCipherSuites: true,
		}
		tlsConfig.BuildNameToCertificate()

		clientPolicy.TlsConfig = tlsConfig
	}

	client, err := as.NewClientWithPolicy(clientPolicy, *host, *port)
	if err != nil {
		log.Fatalln("Failed to connect to the server cluster: ", err)
	}

	log.Println("Connection successful. Discovered nodes:", client.Cluster().GetNodes())

```

---

<div class="post-metadata">

### Author: ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)
#### Post date: [February 8, 2022, 11:45am UTC](https://discuss.elastic.co/t/configuring-aerospike-metricbeat-module-with-tls/294729/3 "2022-02-08T11:45:19Z")

</div>

Hi @sentient would you mind open a PR for this? It will be very appreciated. Thanks!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 8, 2022, 1:45pm UTC](https://discuss.elastic.co/t/configuring-aerospike-metricbeat-module-with-tls/294729/4 "2022-03-08T13:45:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
