# Encrypt filebeat to logstash

**URL:** https://discuss.elastic.co/t/encrypt-filebeat-to-logstash/242944
**Category:** Logstash
**Tags:** elastic-stack-security
**Created:** [July 28, 2020, 4:44pm UTC](https://discuss.elastic.co/t/encrypt-filebeat-to-logstash/242944 "2020-07-28T16:44:07Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![elk6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk6/32/72282_2.png) [@elk6](https://discuss.elastic.co/u/elk6)
#### Post date: [July 28, 2020, 4:44pm UTC](https://discuss.elastic.co/t/encrypt-filebeat-to-logstash/242944/1 "2020-07-28T16:44:07Z")

</div>

I have a small setup. Filebeat was able to successfully send logs to logstash. I was then asked to encrypt communication between filebeat to logstash.

On logstash I've added to the following to the `input{ }` block:

```
ssl_certificate => "/usr/share/elasticsearch/elk.crt"
ssl_key => "/usr/share/elasticsearch/elk.key"

```

I've copied the `elk.crt` and `elk.key` to one of the servers that ship logs with filebeat under `/etc/elk/certs`, and then, in filebeat.yml, under `output.logstash:`, I've added the following:

```
hosts: ["91.239.19.210:5044"] # this line was there before. also not the real ip
ssl.certificate: "/etc/elk/certs/elk.crt"
ssl.key: "/etc/elk/certs/elk.key"

```

When I start filebeat, I endlessly get the following message:

```
 2020-07-28T16:36:19.644Z ERROR [publisher_pipeline_output] pipeline/output.go:155 Failed to connect to backoff(async(tcp://91.239.19.210:5044)): x509: cannot validate certificate for 91.239.19.210 because it doesn't contain any IP SANs

```

I thought that maybe it wanted to have a hostname instead of IP, so I added to /etc/hosts:

```
  91.239.19.210 elk.com

```

And in filebeat.yml replace the IP with:

```
 hosts: ["elk.com:5044"]

```

Which results this error:

```
 2020-07-28T16:42:12.174Z ERROR [publisher_pipeline_output] pipeline/output.go:155 Failed to connect to backoff(async(tcp://elk.com:5044)): x509: certificate is not valid for any names, but wanted to match elk.com

```

I'm sitting on this forever and I can't seem to crack it. Does anyone know what's wrong? I feel like I'm missing something. Thanks ahead.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 28, 2020, 5:26pm UTC](https://discuss.elastic.co/t/encrypt-filebeat-to-logstash/242944/2 "2020-07-28T17:26:09Z")

</div>

> [@elk6](#):
>
> `cannot validate certificate for 91.239.19.210 because it doesn't contain any IP SANs`

OK, that is saying that you cannot use that certificate when you configure hosts as an IP address because the certificate does not have a Subject Alternate Name that contains an IP address.

> [@](#):
>
> certificate is not valid for any names, but wanted to match [elk.com](http://elk.com)

I wonder if that could be something like [this issue](https://github.com/docker/for-linux/issues/248). Hard to tell without seeing all the (non-secret) parts of the certificate.

---

<div class="post-metadata">

### Author: ![elk6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk6/32/72282_2.png) [@elk6](https://discuss.elastic.co/u/elk6)
#### Post date: [July 29, 2020, 2:51pm UTC](https://discuss.elastic.co/t/encrypt-filebeat-to-logstash/242944/3 "2020-07-29T14:51:39Z")

</div>

Thanks for the response.

> the certificate does not have a Subject Alternate Name that contains an IP address.

I didn't really get this part, does it mean it only accepts hostnames, instead of IPs?

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 29, 2020, 5:04pm UTC](https://discuss.elastic.co/t/encrypt-filebeat-to-logstash/242944/4 "2020-07-29T17:04:37Z")

</div>

Well the RFCs allow a certificate to be issued in the name of an IP address, but issuing certificate authorities impose strict conditions on these, and not all clients support them. The more common way to use an IP address in TLS is SAN. Subject Alternate Name records allow a certificate to list multiple alternate hostnames and/or IP address that the certificate should also match.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 26, 2020, 5:04pm UTC](https://discuss.elastic.co/t/encrypt-filebeat-to-logstash/242944/5 "2020-08-26T17:04:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
