# Encrypting the certificate key for SSL

**URL:** <https://discuss.elastic.co/t/encrypting-the-certificate-key-for-ssl/100205>\
**Category:** Logstash\
**Created:** [September 12, 2017, 12:05pm UTC](https://discuss.elastic.co/t/encrypting-the-certificate-key-for-ssl/100205 "2017-09-12T12:05:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ihjaz](https://avatars.discourse-cdn.com/v4/letter/i/8baadc/32.png) [@Ihjaz](https://discuss.elastic.co/u/Ihjaz)\
**Post date:** [September 12, 2017, 12:05pm UTC](https://discuss.elastic.co/t/encrypting-the-certificate-key-for-ssl/100205/1 "2017-09-12T12:05:37Z")

</div>

Hi,

I've enabled SSL between Filebeat and Logstash. I have the following configuration  
in my logstash.conf

```
input {
      beats {
        host => "10.129.179.39"
        port => 5044
        ssl => true
        ssl_certificate => "/etc/logstash/certs/first-cert.pem"
        ssl_key => "/etc/logstash/certs/key.pk8"
      }
    }

```

The above configuration works and the logs are getting pushed from filebeat to logstash.  
But I can't store the private key without encryption on the server as anyone who has access to the server can get the private key and sign a certificate.

Is there a way I can pass the private key to logstash in an encrypted form ?

---

<div class="post-metadata">

**Author:** ![Ihjaz](https://avatars.discourse-cdn.com/v4/letter/i/8baadc/32.png) [@Ihjaz](https://discuss.elastic.co/u/Ihjaz)\
**Post date:** [September 12, 2017, 3:14pm UTC](https://discuss.elastic.co/t/encrypting-the-certificate-key-for-ssl/100205/2 "2017-09-12T15:14:48Z")

</div>

Hi,

I figured out that we can use ssl\_key\_passphrase to decrypt an encrypted private key.

`ssl_key_passphrase => "admin"`

But it seems like I need to give the passphrase in plain text as shown above and anyone who looks at this config file can see it.

Is there a way to hide this passphrase ?

---

<div class="post-metadata">

**Author:** ![Ihjaz](https://avatars.discourse-cdn.com/v4/letter/i/8baadc/32.png) [@Ihjaz](https://discuss.elastic.co/u/Ihjaz)\
**Post date:** [September 14, 2017, 4:29pm UTC](https://discuss.elastic.co/t/encrypting-the-certificate-key-for-ssl/100205/3 "2017-09-14T16:29:43Z")

</div>

Hi,

I have the following configuration now with ssl\_key\_passphrase.

```
input {
  beats {
    host => "10.129.179.39"
    port => 5044
    ssl => true
    ssl_certificate => "/etc/logstash/certs/first-cert.pem"
    ssl_key => "/etc/logstash/certs/enc_key.p8"
    ssl_key_passphrase => "admin"
  }

```

}

I have encrypted key.p8 as follows with admin as key phrase.

> openssl rsa -aes256 -in key.p8 -out enc\_key.p8

But with the encrypted key file and passphrase configured, I am seeing the following error in logstash logs.

`[2017-09-14T21:57:05,709][ERROR][logstash.inputs.beats] Looks like you either have an invalid key or your private key was not in PKCS8 format.`

Has anyone here run into this issue? Have you tried ssl\_key\_passphrase?

---

<div class="post-metadata">

**Author:** ![Ihjaz](https://avatars.discourse-cdn.com/v4/letter/i/8baadc/32.png) [@Ihjaz](https://discuss.elastic.co/u/Ihjaz)\
**Post date:** [September 21, 2017, 7:25am UTC](https://discuss.elastic.co/t/encrypting-the-certificate-key-for-ssl/100205/4 "2017-09-21T07:25:32Z")

</div>

Hi,

I figured this out. It has to be a PKCS#8 encryption. The ssl\_key\_passphrase works only for decrypting the PKCS#8 encryption.

`openssl pkcs8 -in key.pem -topk8 -passout pass:admin -out p8key.pem`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2017, 7:25am UTC](https://discuss.elastic.co/t/encrypting-the-certificate-key-for-ssl/100205/5 "2017-10-19T07:25:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
