# Configuring TLS on a Logstash Docker container

**URL:** https://discuss.elastic.co/t/configuring-tls-on-a-logstash-docker-container/62580
**Category:** Logstash
**Created:** [October 9, 2016, 3:47pm UTC](https://discuss.elastic.co/t/configuring-tls-on-a-logstash-docker-container/62580 "2016-10-09T15:47:00Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)
#### Post date: [October 9, 2016, 3:47pm UTC](https://discuss.elastic.co/t/configuring-tls-on-a-logstash-docker-container/62580/1 "2016-10-09T15:47:00Z")

</div>

Hello, maybe this is a dumb question.  
I'm in the situation in which I want to use TLS between Filebeat and Logstash, the latter being on a Docker container.  
To enable TLS on Logstash, I'm supposed to configure it as follows (with a self-signed certificate):

```
input {
  beats {
    port => 5044
    ssl => true
    ssl_certificate => "/etc/server.crt"
    ssl_key => "/etc/server.key"
  }
}

```

The server.crt file is supposed to be used by Filebeat, too.  
However, how is it possible to manage the situation in which I need to replace the Docker container? I should re-generate the certificate on the Logstash container and send it back to Filebeat?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [October 9, 2016, 5:40pm UTC](https://discuss.elastic.co/t/configuring-tls-on-a-logstash-docker-container/62580/2 "2016-10-09T17:40:14Z")

</div>

"Replace the Docker _container_"? Are you talking about the Docker _image_?

Since the certificate is tied to the host it's probably a good idea to store the certificate in the host file system and bind-mount it into containers as necessary.

---

<div class="post-metadata">

### Author: ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)
#### Post date: [October 9, 2016, 6:03pm UTC](https://discuss.elastic.co/t/configuring-tls-on-a-logstash-docker-container/62580/3 "2016-10-09T18:03:16Z")

</div>

Yes, I was referring to container image replacement.  
That was the suggestion I was looking for, thanks 🙂

BTW, could someone confirm me that if the host certificate is self-signed (and thus, I'm using the `insecure` option for Filebeat TLS) it is not necessary to pass the .crt and .key files to the Filebeat clients?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:34am UTC](https://discuss.elastic.co/t/configuring-tls-on-a-logstash-docker-container/62580/4 "2017-07-06T04:34:59Z")

</div>


