# Expected behavior of tcp/input/ssl\_verify=true?

**URL:** <https://discuss.elastic.co/t/expected-behavior-of-tcp-input-ssl-verify-true/333835>\
**Category:** Logstash\
**Created:** [May 19, 2023, 3:48am UTC](https://discuss.elastic.co/t/expected-behavior-of-tcp-input-ssl-verify-true/333835 "2023-05-19T03:48:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bennbrian65](https://avatars.discourse-cdn.com/v4/letter/b/ce73a5/32.png) [@bennbrian65](https://discuss.elastic.co/u/bennbrian65)\
**Post date:** [May 19, 2023, 3:48am UTC](https://discuss.elastic.co/t/expected-behavior-of-tcp-input-ssl-verify-true/333835/1 "2023-05-19T03:48:38Z")

</div>

logstash 8.7.1, tcp input w/ssl\_verify=true. I expect that a sender using a cert w/no SANS and the sender’s host name does not match the cert’s CN would be rejected, but it is accepted. What does ssl\_verify=true govern?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2023, 3:48am UTC](https://discuss.elastic.co/t/expected-behavior-of-tcp-input-ssl-verify-true/333835/2 "2023-06-16T03:48:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
