# Creating Certificate using Certutil

**URL:** <https://discuss.elastic.co/t/creating-certificate-using-certutil/234502>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [May 27, 2020, 9:39am UTC](https://discuss.elastic.co/t/creating-certificate-using-certutil/234502 "2020-05-27T09:39:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [May 27, 2020, 9:39am UTC](https://discuss.elastic.co/t/creating-certificate-using-certutil/234502/1 "2020-05-27T09:39:02Z")

</div>

Hi,

I've used this commands to generate CA and Cert:

```auto
bin/elasticsearch-certutil ca
bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12

```

But in logstash and beats a p12 is not supported and I MUST use

```auto
ssl.certificate_authorities: ["/etc/ca.crt"]
ssl.certificate: "/etc/client.crt"
ssl.key: "/etc/client.key"

```

So what is the command that I should use to generate:  
1- ca.crt  
2- client.crt  
3- client.key

P.S: The CA and CERT are password protected

Please help.

Regards,

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 29, 2020, 8:30am UTC](https://discuss.elastic.co/t/creating-certificate-using-certutil/234502/2 "2020-05-29T08:30:29Z")

</div>

You don't need

```auto
ssl.certificate: "/etc/client.crt"
ssl.key: "/etc/client.key"

```

unless you want to configure mutual TLS authentication between logstash and elasticsearch. If you just want to authenticate logstash to elasticsearch with a username and password and only need that logstash can verify the certificate of elasticsearch, keep only

```auto
ssl.certificate_authorities: ["/etc/ca.crt"]

```

You can get that from `elastic-stack-ca.p12` with `openssl` as follows:

```auto
openssl pkcs12 -in elastic-stack-ca.p12 -clcerts -nokeys | sed '/-----BEGIN CERTIFICATE-----/,$!d'> ca.crt

```

---

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [May 30, 2020, 5:39am UTC](https://discuss.elastic.co/t/creating-certificate-using-certutil/234502/3 "2020-05-30T05:39:34Z")

</div>

> [@ikakavas](#):
>
> hat logstash can verify the certificate of elasti

Many thanks, Worked fine!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2020, 5:41am UTC](https://discuss.elastic.co/t/creating-certificate-using-certutil/234502/4 "2020-06-27T05:41:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
