# Filebeat PKI certificate authentication not working to es

**URL:** <https://discuss.elastic.co/t/filebeat-pki-certificate-authentication-not-working-to-es/309239>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 9, 2022, 1:18am UTC](https://discuss.elastic.co/t/filebeat-pki-certificate-authentication-not-working-to-es/309239 "2022-07-09T01:18:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fformoso](https://avatars.discourse-cdn.com/v4/letter/f/b3f665/32.png) [@fformoso](https://discuss.elastic.co/u/fformoso)\
**Post date:** [July 9, 2022, 1:18am UTC](https://discuss.elastic.co/t/filebeat-pki-certificate-authentication-not-working-to-es/309239/1 "2022-07-09T01:18:26Z")

</div>

Dear all,

Im trying to setup ssl to connect filebeat to elastic

Elastic service is running in xxxxx.yy:9200

filebeat.yml  
hosts: ["xxxxx.yy:9200"]  
protocol: "https"  
ssl.certificate\_authorities: "/etc/filebeat/security/es-ca.crt"  
ssl.certificate: "/etc/filebeat/security/es-crt.crt"  
ssl.key: "/etc/filebeat/security/es.key"

I created the cert using the following commands  
Obtain key  
openssl pkcs12 -in /etc/elasticsearch/security/elastic-certificates.p12 -nocerts -nodes | sed -ne '/-BEGIN PRIVATE KEY-/,/-END PRIVATE KEY-/p' \> es.key  
Obtain the CA:  
openssl pkcs12 -in /etc/elasticsearch/security/elastic-certificates.p12 -cacerts -nokeys -chain | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' \> es-ca.crt  
Obtain the node certificate:  
openssl pkcs12 -in /etc/elasticsearch/security/elastic-certificates.p12 -clcerts -nokeys | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' \> es-cert.crt

The cluster and kibana are up and running and connected via ssl

Im trying to use certs to authenticate no basic authentication to ES

When starting filebeat I have

{"log.level":"error","@timestamp":"2022-07-08T21:55:12.183-0300","log.logger":"esclientleg","log.origin":{"file.name":"eslegclient/connection.go","file.line":235},"message":"error connecting to Elasticsearch at [https://xxxxx.yy:9200](https://xxxxx.yy:9200): 401 Unauthorized: {"error":{"root\_cause":[{"type":"security\_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":["Basic realm=\"security\" charset=\"UTF-8\"","Bearer realm=\"security\"","ApiKey"]}}],"type":"security\_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":["Basic realm=\"security\" charset=\"UTF-8\"","Bearer realm=\"security\"","ApiKey"]}},"status":401}","service.name":"filebeat","ecs.version":"1.6.0"}

Please help to understand what is missing.

Thanks!!!

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 11, 2022, 6:01am UTC](https://discuss.elastic.co/t/filebeat-pki-certificate-authentication-not-working-to-es/309239/2 "2022-07-11T06:01:38Z")

</div>

- What does your `elasticsearc.yml` look like?
- What license are you running with?
- Where did `/etc/elasticsearch/security/elastic-certificates.p12` come from?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2022, 6:02am UTC](https://discuss.elastic.co/t/filebeat-pki-certificate-authentication-not-working-to-es/309239/3 "2022-08-08T06:02:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
