# ELK upgrade to 6.8.23

**URL:** <https://discuss.elastic.co/t/elk-upgrade-to-6-8-23/297892>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [February 22, 2022, 12:17pm UTC](https://discuss.elastic.co/t/elk-upgrade-to-6-8-23/297892 "2022-02-22T12:17:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![arun.kumar92](https://avatars.discourse-cdn.com/v4/letter/a/e5b9ba/32.png) [@arun.kumar92](https://discuss.elastic.co/u/arun.kumar92)\
**Post date:** [February 22, 2022, 12:17pm UTC](https://discuss.elastic.co/t/elk-upgrade-to-6-8-23/297892/1 "2022-02-22T12:17:20Z")

</div>

Hi Team

Currently I'm working on ELK upgrade. When I upgrade lostash from 5.X to 6.8.23.I got below error

```auto
------------------------------------------------------------------------------------------------------------------------------
Caused by: java.security.cert.CertificateException: No subject alternative names present
        at sun.security.util.HostnameChecker.matchIP(HostnameChecker.java:156)
        at sun.security.util.HostnameChecker.match(HostnameChecker.java:100)
        at sun.security.ssl.X509TrustManagerImpl.checkIdentity(X509TrustManagerImpl.java:457)
        at sun.security.ssl.X509TrustManagerImpl.checkIdentity(X509TrustManagerImpl.java:431)
        at sun.security.ssl.X509TrustManagerImpl.checkTrusted(X509TrustManagerImpl.java:285)
        at sun.security.ssl.X509TrustManagerImpl.checkServerTrusted(X509TrustManagerImpl.java:141)
        at sun.security.ssl.CertificateMessage$T12CertificateConsumer.checkServerCerts(CertificateMessage.java:632)
        ... 43 more
[2022-02-22T10:33:36,155][ERROR][logstash.pipeline] A plugin had an unrecoverable error. Will restart this plugin.
 
[2022-02-22T10:33:36,343][FATAL][logstash.runner] An unexpected error occurred! {:error=>org.apache.kafka.common.errors.SslAuthenticationException: SSL handshake failed, :backtrace=>[]
----------------------------------------------------------------------------------------------

Conf file example
===============================================================
input {
      kafka {
            bootstrap_servers => "xxxxxxxxxx:9093,xxxxxxxxxxxxxx:9093,xxxxxxxxxxxxxxxx:9093"
            client_id => "logstash-uu786v1026"
                        topics => ["test_log"]
                        group_id => "logstash_log"
            consumer_threads => 3
            codec => "json"
            security_protocol => "SSL"
            ssl_truststore_location => "/usr/share/logstash/config/client.truststore.jks"
            ssl_truststore_password => "xxxxxxxxx"
    }
}
=========================================================

```

Noticed in breaking changes \* The `ssl` option is now obsolete.

Could you please help us how to resolve this issue.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2022, 5:24pm UTC](https://discuss.elastic.co/t/elk-upgrade-to-6-8-23/297892/2 "2022-02-22T17:24:32Z")

</div>

> [@arun.kumar92](#):
>
> `Caused by: java.security.cert.CertificateException: No subject alternative names present`

I believe this is telling you that the certificate of one of the brokers does not match the name you are using to connect to it. If "xxxxxxxxxxxxxxxx" does not match the CN in the certificate, then the client looks for SAN entries. If there are no SAN entries then it throws this exception.

The [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/trb-security-sslhandshake.html) suggests this is specific to attempts to connect using an IP address, but I am not convinced that is true.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2022, 5:24pm UTC](https://discuss.elastic.co/t/elk-upgrade-to-6-8-23/297892/3 "2022-03-22T17:24:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
