# Filebeat and Logstash certificate and key

**URL:** https://discuss.elastic.co/t/filebeat-and-logstash-certificate-and-key/53990
**Category:** Beats
**Tags:** filebeat
**Created:** [June 27, 2016, 2:29am UTC](https://discuss.elastic.co/t/filebeat-and-logstash-certificate-and-key/53990 "2016-06-27T02:29:47Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![fjiang212](https://avatars.discourse-cdn.com/v4/letter/f/76d3ee/32.png) [@fjiang212](https://discuss.elastic.co/u/fjiang212)
#### Post date: [June 27, 2016, 2:29am UTC](https://discuss.elastic.co/t/filebeat-and-logstash-certificate-and-key/53990/1 "2016-06-27T02:29:47Z")

</div>

I follow the doc ([https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-14-04](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-14-04)) to generate certificate and private key, then use them in both filebeat and logstash to make the TSL connection work. But I am still confuse here:

- Why the filebeat and logstash use the same certificate here, Originally I thought client and server have different certificate: client.crt and server.crt
- Why we copy server private key file to filebeat. I always think we should keep private key on the server side only.
- Does it mean in this case we only verify logstash not filebeat

Could someone knowing TLS shed some light on it? Or explain how TLS work here.

Thanks

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [June 27, 2016, 10:09am UTC](https://discuss.elastic.co/t/filebeat-and-logstash-certificate-and-key/53990/2 "2016-06-27T10:09:00Z")

</div>

I didn't read through this tutorial, but:

1. do not copy the private file. It's called private for a reason
2. When you're using self-signed certificates (no CA), the client needs to have certificate in its CA list. Using certificate-authorities, the client only requires the CAs certificate to verify the server certificate (this is how it should be done when managing multiple servers). For testing and simple setups self-signed certificates are a little more convenient
3. I didn't see any client certificate configured for client-authentication. This means, filebeat will check logstash being ok, but not the other way around.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 18, 2016, 2:29am UTC](https://discuss.elastic.co/t/filebeat-and-logstash-certificate-and-key/53990/3 "2016-07-18T02:29:47Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
