# Filebeat to Logstash TLS handshake failure

**URL:** <https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 5, 2017, 4:51pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345 "2017-04-05T16:51:51Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![tleif](https://avatars.discourse-cdn.com/v4/letter/t/87869e/32.png) [@tleif](https://discuss.elastic.co/u/tleif)\
**Post date:** [April 5, 2017, 4:51pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345/1 "2017-04-05T16:51:52Z")

</div>

EDIT: I'm running version 5.3 of everything.

I'm currently trying to get my filebeat to logstash connections using SSL, but I keep running into the error:

```
2017/04/05 16:42:16.045679 sync.go:53: DBG connect
2017/04/05 16:42:16.108391 single.go:140: ERR Connecting error publishing events (retrying): remote error: tls: handshake failure
2017/04/05 16:42:16.108424 single.go:156: DBG send fail

```

I can ship logs without SSL enabled fine. And I've confirmed that the connections are reaching the Logstash machine with SSL configured, just not actually able to establish a functioning connection. I can also create an openssl client connection from the beats machine to the logstash machine on port 5044 and the SSL certs and connection all checkout fine.

I have Logstash, Elasticsearch and Kibana all communicating via ssl connections just fine, but Filebeats just won't cooperate. My current filebeats config is:

```
name: "shipper"

filebeat:
  prospectors:
    - input_type: log
      tags: ["mylogs"]
      tail_files: true
      paths:
        - /path/to/logs
        - /path/to/logs
        - /path/to/logs

output:
  logstash:
    hosts: ["logstash.host:5044"]
    compression_level: 1
    ssl:
      certificate_authorities: ["/path/to/ca.crt"]

logging:
  level: warning
  to_files: true
  to_syslog: false
  files:
    path: /path/to/logs
    name: filebeats.log
    keepfiles: 7

```

My logstash input on the other end is:

```
input {
  beats {
    host => "xxx.xxx.xxx.xxx"
    port => 5044
    ssl => true
    ssl_certificate_authorities => ["/path/to/ca.crt"]
    ssl_certificate => "/path/to/logstash.crt"
    ssl_key => "/path/to/logstash.pkcs8"
  }
}
```

---

<div class="post-metadata">

**Author:** ![giuseppe](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@giuseppe](https://discuss.elastic.co/u/giuseppe)\
**Post date:** [April 5, 2017, 8:52pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345/2 "2017-04-05T20:52:29Z")

</div>

Are you sure the `host` setting in the Beats input in Logstash is what you want? Try removing that, perhaps it's not binding to the correct interface with the value you provided.

[https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-host](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-host)

---

<div class="post-metadata">

**Author:** ![tleif](https://avatars.discourse-cdn.com/v4/letter/t/87869e/32.png) [@tleif](https://discuss.elastic.co/u/tleif)\
**Post date:** [April 5, 2017, 8:56pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345/3 "2017-04-05T20:56:48Z")

</div>

No change in behavior if I remove the host setting.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 6, 2017, 6:02am UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345/4 "2017-04-06T06:02:57Z")

</div>

Why is it you have configured `ssl_certificate_authorities` in logstash? This is only required if client authentication is to be enabled.

Have you tried to validate your certificate e.g. with `curl` or `openssl client`? ([See FAQ](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-ssl-logstash.html#testing-ssl-logstash))

---

<div class="post-metadata">

**Author:** ![tleif](https://avatars.discourse-cdn.com/v4/letter/t/87869e/32.png) [@tleif](https://discuss.elastic.co/u/tleif)\
**Post date:** [April 6, 2017, 3:16pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345/5 "2017-04-06T15:16:30Z")

</div>

ssl\_certficate\_authorities is set because I was following the config instructions provided by elastic, and trying anything and everything to make the logstash -\> beat connection function.

I have tested the ssl cert via openssl as stated in my original post:

> [@tleif](#):
>
> I can also create an openssl client connection from the beats machine to the logstash machine on port 5044 and the SSL certs and connection all checkout fine.

This cert is also used to connect with elasticsearch and is working.

---

<div class="post-metadata">

**Author:** ![tleif](https://avatars.discourse-cdn.com/v4/letter/t/87869e/32.png) [@tleif](https://discuss.elastic.co/u/tleif)\
**Post date:** [April 6, 2017, 6:52pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345/6 "2017-04-06T18:52:08Z")

</div>

Example of working SSL connection via the FAQ troubleshooting example:

```
curl -v --cacert ca-bundle.crt https://<redacted>:5044
* About to connect() to <redacted> port 5044 (#0)
* Trying <redacted>... connected
* Connected to <redacted> (<redacted>) port 5044 (#0)
* Initializing NSS with certpath: sql:/etc/pki/nssdb
* CAfile: ca-bundle.crt
  CApath: none
* SSL connection using TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
* Server certificate:
* subject: E=<redacted>
* start date: Mar 18 22:45:04 2015 GMT
* expire date: Mar 19 22:45:04 2018 GMT
* common name: <redacted>
* issuer: <redacted>
> GET / HTTP/1.1
> User-Agent: curl/7.19.7 (x86_64-redhat-linux-gnu) libcurl/7.19.7 NSS/3.21 Basic ECC zlib/1.2.3 libidn/1.18 libssh2/1.4.2
> Host: <redacted>:5044
> Accept: */*
> 
* Empty reply from server
* Connection #0 to host <redacted> left intact
curl: (52) Empty reply from server
* Closing connection #0
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 6, 2017, 7:06pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345/7 "2017-04-06T19:06:22Z")

</div>

> [@tleif](#):
>
> --cacert ca-bundle.crt

This is a shot in the dark, but does `ca-bundle.crt` contain multiple certs? Have you tried splitting them into individual files and providing each file in the `certificate_authorities` list in Filebeat?

Also, does Filebeat work if you disable certificate verification using `verification_mode: none`?

---

<div class="post-metadata">

**Author:** ![tleif](https://avatars.discourse-cdn.com/v4/letter/t/87869e/32.png) [@tleif](https://discuss.elastic.co/u/tleif)\
**Post date:** [April 6, 2017, 7:34pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345/8 "2017-04-06T19:34:59Z")

</div>

YES! It was the bundled CA causing the issue. Split them out and added to the authorities setting and everything is joy.

Thank you so very much!

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 7, 2017, 4:42pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345/9 "2017-04-07T16:42:13Z")

</div>

Hm, that's funny. Which format is your `ca-bundle.crt`? If I remember correctly, the PEM-reader in stdlib will iterate and add all certificates to the CA-Certificate-Set (being a set, even order should not matter).

---

<div class="post-metadata">

**Author:** ![tleif](https://avatars.discourse-cdn.com/v4/letter/t/87869e/32.png) [@tleif](https://discuss.elastic.co/u/tleif)\
**Post date:** [April 7, 2017, 5:18pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345/10 "2017-04-07T17:18:33Z")

</div>

X.509v3 PEM format. It's the CA bundle that we use for everything that validates SSL, which is why it didn't even occur to me it might be the issue. Never had a problem before.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 10, 2017, 8:18am UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345/11 "2017-04-10T08:18:40Z")

</div>

hm, that's weird. I'd treat this as a bug. Can you open an issue with github including a fake-certificate bundle for testing ? Or shell commands to produce a fake certificate bundle matching your bundle in structure.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2017, 4:52pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-tls-handshake-failure/81345/12 "2017-04-26T16:52:15Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
