# \[elastic output\] Differences in SSL between 7.9.1 and 7.16.2

**URL:** <https://discuss.elastic.co/t/elastic-output-differences-in-ssl-between-7-9-1-and-7-16-2/293035>\
**Category:** Logstash\
**Created:** [December 28, 2021, 10:05am UTC](https://discuss.elastic.co/t/elastic-output-differences-in-ssl-between-7-9-1-and-7-16-2/293035 "2021-12-28T10:05:37Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rockandska](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rockandska/32/99603_2.png) [@rockandska](https://discuss.elastic.co/u/rockandska)\
**Post date:** [December 28, 2021, 10:05am UTC](https://discuss.elastic.co/t/elastic-output-differences-in-ssl-between-7-9-1-and-7-16-2/293035/1 "2021-12-28T10:05:37Z")

</div>

Hi,

Previously, on 7.9.1, I had a configuration like the one bellow for my output :

```auto
output {
  elasticsearch {
    hosts => "https://myhost:9200"
    index => "myindex"
    user => "myuser"
    password => "mypassword"
  }
}

```

`myhost` use a self signed certificate and the company CA is deployed on all hosts and available in system CA store ( RHE7: `/etc/pki/tls/certs/ca-bundle.crt -> /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem` )

Everything worked fine

After upgrading to 7.16.2, I had to add to my configuration :

```auto
    ca-cert => "/etc/pki/tls/certs/ca-bundle.crt"

```

Without adding this parameter, I had an SSL error handshake.  
I've seen another fix suggested as adding the CA to Java store but found this kind of fix less clean than having the CA specified in the configuration.

I've checked the elastic output plugin CHANGELOG but didn't see any change who seems related to this behavior.

Any ideas what changed ?  
Is it normal to have to specify the system CA store ? I was assuming that this one was lookup by default.

Regards,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 28, 2021, 2:29pm UTC](https://discuss.elastic.co/t/elastic-output-differences-in-ssl-between-7-9-1-and-7-16-2/293035/2 "2021-12-28T14:29:29Z")

</div>

> [@rockandska](#):
>
> Any ideas what changed ?

Maybe the jruby-openssl upgrade in [7.15.2](https://www.elastic.co/guide/en/logstash/current/logstash-7-15-2.html)?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [December 28, 2021, 7:39pm UTC](https://discuss.elastic.co/t/elastic-output-differences-in-ssl-between-7-9-1-and-7-16-2/293035/3 "2021-12-28T19:39:40Z")

</div>

How is Logstash finding Java? My best guess is that we are no longer using the system java (that has your cert store), and are instead using the bundled JDK (which doesn't have your certs loaded into its store).

- Logstash has bundled its own Java since Logstash 7.10, preferring the bundled JDK to the java available on your `PATH`.
- In 7.16, we introduced the `LS_JAVA_HOME` environment variable as the _preferred way_ to tell Logstash to use a Java other than the bundled JDK.
- In 7.16, we also _deprecated_ finding Java with `JAVA_HOME` -- this flag will be ignored in Logstash 8, but has been in use since at least Logstash 5.

---

<div class="post-metadata">

**Author:** ![rockandska](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rockandska/32/99603_2.png) [@rockandska](https://discuss.elastic.co/u/rockandska)\
**Post date:** [December 30, 2021, 10:41am UTC](https://discuss.elastic.co/t/elastic-output-differences-in-ssl-between-7-9-1-and-7-16-2/293035/4 "2021-12-30T10:41:38Z")

</div>

Thanks for the feedback.

Is there no way to let bundle JDK lookup in system CA store ?  
It is IMO more convenient than having to inject it in Java Store or specify ca in configuration.

Regards,

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [December 30, 2021, 5:07pm UTC](https://discuss.elastic.co/t/elastic-output-differences-in-ssl-between-7-9-1-and-7-16-2/293035/5 "2021-12-30T17:07:30Z")

</div>

You can also tell the jvm to load its truststore from a particular place by adding a directive to your `config/jvm.properties`:

```auto
-Djavax.net.ssl.trustStore=/path/to/truststore.jks

```

From what I read, when this system property is _not_ present, any Java installation will look in its _own_ `<JAVA_HOME>/lib/security` for the files `cacerts` or `jssecacerts `. How is your system truststore being added to your system java?

Note: If you are using `keytool` to add certs to your Java truststore, it is worth noting that the `keytool` on your `$PATH` is for the `java` that is also on your `$PATH`, and will by default install the certs into its own Java.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 27, 2022, 5:08pm UTC](https://discuss.elastic.co/t/elastic-output-differences-in-ssl-between-7-9-1-and-7-16-2/293035/6 "2022-01-27T17:08:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
