# Filebeat & Logstash with intermediate CA (cert chain) Issues

**URL:** <https://discuss.elastic.co/t/filebeat-logstash-with-intermediate-ca-cert-chain-issues/105675>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 29, 2017, 6:41pm UTC](https://discuss.elastic.co/t/filebeat-logstash-with-intermediate-ca-cert-chain-issues/105675 "2017-10-29T18:41:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mark\_Clarke](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@Mark\_Clarke](https://discuss.elastic.co/u/Mark_Clarke)\
**Post date:** [October 29, 2017, 6:41pm UTC](https://discuss.elastic.co/t/filebeat-logstash-with-intermediate-ca-cert-chain-issues/105675/1 "2017-10-29T18:41:58Z")

</div>

Hi all,

I have an intermediate CA sign the certs for the filebeat client. I have entered the chain file in logstash configuration for the filebeat input stanza in the certificates-authorities entry.

> input {  
> beats {  
> port =\> 5044  
> ssl =\> true  
> ssl\_certificate\_authorities =\> ["/usr/local/share/ca-certificates/MySubCA-chain.pem"]  
> ssl\_certificate =\> "/etc/ssl/certs/logger.abc.co.za.co.za.pem"  
> ssl\_key =\> "/etc/ssl/private/logger.abc.co.za.key"  
> ssl\_verify\_mode =\> "force\_peer"  
> }  
> }

On the client I have set up the client certificates and the root CA certificate in the filebeat certificates-authorities.

> output.logstash:  
> hosts: ["logger.abc.co.za:5044"]  
> ssl.certificate\_authorities: ["/usr/local/share/ca-certificates/MySubCA-chain.pem"]  
> ssl.certificate: "/etc/ssl/certs/client.abc.co.za.pem"  
> ssl.key: "/etc/ssl/private/client.abc.co.za.key"

I get on the logstash server

> "][org.logstash.beats.BeatsHandler] Exception: javax.net.ssl.SSLHandshakeException: General OpenSslEngine problem"

=\> on the filebeat client.

> "ERR Connecting error publishing events (retrying): remote error: tls: internal error"

Running

> "openssl s\_client -CAfile /usr/local/share/ca-certificates/MySubCA-chain.pem -servername logger.abc.co.za -connect logger.abc.co.za:5044 -cert /etc/ssl/certs/client.abc.co.za.pem -key /etc/ssl/private/client.abc.co.za..key"

I get

> "verify return:1  
> 139717980804760:error:14094438:SSL routines:ssl3\_read\_bytes:tlsv1 alert internal error:s3\_pkt.c:1487:SSL alert number 80  
> 139717980804760:error:140790E5:SSL routines:ssl23\_write:ssl handshake failure:s23\_lib.c:177:"

Running it without the client certs it works.

> "openssl s\_client -CAfile /usr/local/share/ca-certificates/MySubCA-chain.pem -servername logger.abc.co.za -connect logger.abc.co.za:5044"

Any ideas whats wrong? According to goolge alert 80 is

> internal\_error  
> An internal error unrelated to the peer or the correctness of the
> 
> ```
> protocol makes it impossible to continue (such as a memory
> allocation failure). This message is always fatal.
> 
> ```

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [October 30, 2017, 1:25pm UTC](https://discuss.elastic.co/t/filebeat-logstash-with-intermediate-ca-cert-chain-issues/105675/2 "2017-10-30T13:25:48Z")

</div>

Can you turn on the debug log on Logstash and retry the same scenario and add the output to this issue?

You can do that with this command:

`bin/logstash --log.level debug`

I am currently assuming that the certificates are correctly signed by the authority and the the CA contains the full chain to correctly validating the certificate.

---

<div class="post-metadata">

**Author:** ![Mark\_Clarke](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@Mark\_Clarke](https://discuss.elastic.co/u/Mark_Clarke)\
**Post date:** [October 31, 2017, 5:42am UTC](https://discuss.elastic.co/t/filebeat-logstash-with-intermediate-ca-cert-chain-issues/105675/3 "2017-10-31T05:42:24Z")

</div>

Thanks for the response. I am confident that the certs are signed properly but with everything in IT I don't rule out the possibility that there is a problem. THe cert and chain work fine with the apache server.

I must be doing something wrong because when I add "--log.level debug" to the systemd service file I get the following error below: (SSL is enabled and the serv ice starts up without the log.level debug option.

> ] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>250}  
> [2017-10-31T07:39:19,232][ERROR][logstash.pipeline] Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash. {"exception"=\>"undefined method `to_hash' for []:Array", "backtrace"=>["(eval):957:in `filter\_func'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:398:in `filter_batch'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:379:in `worker\_loop'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:342:in `start_workers'"]} [2017-10-31T07:39:19,240][ERROR][logstash.pipeline] Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash. {"exception"=>"undefined method `to\_hash' for :Array", "backtrace"=\>["(eval):957:in `filter_func'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:398:in `filter\_batch'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:379:in `worker_loop'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:342:in `start\_workers'"]}  
> [2017-10-31T07:39:19,280][FATAL][logstash.runner] An unexpected error occurred! {:error=\>#\<NoMethodError: undefined method `to_hash' for []:Array>, :backtrace=>["(eval):957:in `filter\_func'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:398:in `filter_batch'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:379:in `worker\_loop'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:342:in `start\_workers'"]}

---

<div class="post-metadata">

**Author:** ![Makenai](https://avatars.discourse-cdn.com/v4/letter/m/8797f3/32.png) [@Makenai](https://discuss.elastic.co/u/Makenai)\
**Post date:** [October 31, 2017, 4:15pm UTC](https://discuss.elastic.co/t/filebeat-logstash-with-intermediate-ca-cert-chain-issues/105675/4 "2017-10-31T16:15:14Z")

</div>

Hello,  
I just encountered the same issue. In my case, it was caused by the fact that the certificate on Filebeat client had  
`X509v3 Extended Key Usage: TLS Web Server Authentication`  
Which means that the certificate is to be used with server, not client.

I've changed the Extended Key Usage to  
`X509v3 Extended Key Usage: TLS Web Client Authentication`  
and everything is working flawlessly now!

Let me know if this resolves your issue and have a nice day 🙂

---

<div class="post-metadata">

**Author:** ![Mark\_Clarke](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@Mark\_Clarke](https://discuss.elastic.co/u/Mark_Clarke)\
**Post date:** [November 1, 2017, 9:50pm UTC](https://discuss.elastic.co/t/filebeat-logstash-with-intermediate-ca-cert-chain-issues/105675/5 "2017-11-01T21:50:57Z")

</div>

Sorry for the delayed response. I had to refactor our scripts and work out some details with out CA manager to get everything set up for clientAuth extended key usage settings etc but it appears to be working now. thanks for the assistance. Probably a good idea to handle the expectation gracefully in the code?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2017, 9:50pm UTC](https://discuss.elastic.co/t/filebeat-logstash-with-intermediate-ca-cert-chain-issues/105675/6 "2017-11-29T21:50:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
