# Filebeat encryption error

**URL:** <https://discuss.elastic.co/t/filebeat-encryption-error/243227>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 30, 2020, 1:29pm UTC](https://discuss.elastic.co/t/filebeat-encryption-error/243227 "2020-07-30T13:29:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![elk6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk6/32/72282_2.png) [@elk6](https://discuss.elastic.co/u/elk6)\
**Post date:** [July 30, 2020, 1:29pm UTC](https://discuss.elastic.co/t/filebeat-encryption-error/243227/1 "2020-07-30T13:29:39Z")

</div>

I'm trying to get filebeat to send encrypted data to logstash.

In filebeat.yml, this is my output.logstash:

```
output.logstash:
  hosts: ["91.242.11.220:5044"] # Not the real IP
  ssl.enabled: true
  ssl.certificate_authorities: ["/etc/elk/certs/ca.crt"] # Same as ca.crt in logstah config
  ssl.certificate: "/etc/elk/beatcert/beats.crt"
  ssl.key: "/etc/elk/beatcert/beats.key"
  ssl.key_passphrase: "password" #Not the real password
  ssl.verification_mode: full

```

Logstash's config:

```
input{ beats{
port => 5044
ssl => true
ssl_certificate_authorities => ["/usr/share/elasticsearch/ca/ca.crt"] # Same as ca.crt in filebeat.yml
ssl_certificate => "/usr/share/elasticsearch/elk/elk.crt"
ssl_key => "/usr/share/elasticsearch/elk/elkpkcs8.key"
ssl_key_passphrase => "password" # Not the real password
ssl_verify_mode => "force_peer"
}}

```

When I start filebeat, I get this error:

```
 2020-07-30T12:54:10.082Z ERROR [publisher_pipeline_output] pipeline/output.go:155 Failed to connect to backoff(async(tcp://91.242.11.220:5044)): x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "Elastic Certificate Tool Autogenerated CA")

```

Does anyone happen to know what's wrong? Huge thanks ahead.

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [July 30, 2020, 1:36pm UTC](https://discuss.elastic.co/t/filebeat-encryption-error/243227/2 "2020-07-30T13:36:43Z")

</div>

Try to enable debug mode and see if it tells you more. Does the certificate match the domain you're referring to?

---

<div class="post-metadata">

**Author:** ![elk6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk6/32/72282_2.png) [@elk6](https://discuss.elastic.co/u/elk6)\
**Post date:** [July 30, 2020, 1:39pm UTC](https://discuss.elastic.co/t/filebeat-encryption-error/243227/3 "2020-07-30T13:39:29Z")

</div>

Thanks for the response, the domain is just an IP address.

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [July 30, 2020, 1:51pm UTC](https://discuss.elastic.co/t/filebeat-encryption-error/243227/4 "2020-07-30T13:51:07Z")

</div>

I'm not quite sure if this can be root cause of your problems. Did you try with domain name?

---

<div class="post-metadata">

**Author:** ![elk6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk6/32/72282_2.png) [@elk6](https://discuss.elastic.co/u/elk6)\
**Post date:** [July 30, 2020, 4:32pm UTC](https://discuss.elastic.co/t/filebeat-encryption-error/243227/5 "2020-07-30T16:32:32Z")

</div>

Sovled. Just redid everything. One of the .crts wasnt made with the original CA.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2020, 6:32pm UTC](https://discuss.elastic.co/t/filebeat-encryption-error/243227/6 "2020-08-27T18:32:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
