# Haproxy module does not honour ssl.verification\_mode: 'none'

**URL:** <https://discuss.elastic.co/t/haproxy-module-does-not-honour-ssl-verification-mode-none/206906>\
**Category:** Beats\
**Created:** [November 7, 2019, 6:32am UTC](https://discuss.elastic.co/t/haproxy-module-does-not-honour-ssl-verification-mode-none/206906 "2019-11-07T06:32:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cafuego](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cafuego/32/25146_2.png) [@cafuego](https://discuss.elastic.co/u/cafuego)\
**Post date:** [November 7, 2019, 6:32am UTC](https://discuss.elastic.co/t/haproxy-module-does-not-honour-ssl-verification-mode-none/206906/1 "2019-11-07T06:32:28Z")

</div>

Our hosting provider runs haproxy for us and we have access to the stats interface. We have been using a custom script to extract stats, but since metricbeat has a haproxy module, it would be nice to use that instead.

The stats backend is available over HTTPS with authentication and a self-signed certificate. I have no control over that. I found the various options I should use to configure that, and even appended the trailing slash on the URL so that the port number does not get ";csv" appended, but I cannot get it to work.

It looks as if the **ssl.verification\_mode: none** is ignored, as the error I get when testing the config is: _x509: cannot validate certificate for 10.5.101.1 because it doesn't contain any IP SANs_

Config:

```
- module: haproxy
  metricsets: ["stat"]
  hosts: ["https://10.5.101.1:7500/"]
  ssl.verification_mode: 'none'
  username: 'user'
  password: 'pass'
  period: 10s
  enabled: true

```

Output:

```
haproxy...
  stat...
    error... ERROR failed fetching haproxy stat: couldn't connect: Get https://user:pass@10.5.101.1:7500/;csv: x509: cannot validate certificate for 10.5.101.1 because it doesn't contain any IP SANs

```

To the best of my understanding, it should not be trying to validate the cert at all! This is metricbeat 6.8.4 running in a docker container. The other modules I have enabled work fine (but don't get their data off a HTTPS url)

---

<div class="post-metadata">

**Author:** ![cafuego](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cafuego/32/25146_2.png) [@cafuego](https://discuss.elastic.co/u/cafuego)\
**Post date:** [November 7, 2019, 10:03pm UTC](https://discuss.elastic.co/t/haproxy-module-does-not-honour-ssl-verification-mode-none/206906/2 "2019-11-07T22:03:11Z")

</div>

Update: using docker ip/hostname mapping to assign short (and then full) hostnames to check produces different errors, eventually culminating in "x509: certificate signed by unknown authority" so most definitely the module tries to verify the cert, despite being told not to.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [November 15, 2019, 9:03am UTC](https://discuss.elastic.co/t/haproxy-module-does-not-honour-ssl-verification-mode-none/206906/3 "2019-11-15T09:03:52Z")

</div>

Hi @cafuego,

I think you are right, haproxy doesn't allow for SSL settings. Could you please open a new issue to request this in our repo? [https://github.com/elastic/beats/issues/new?template=feature-request.md](https://github.com/elastic/beats/issues/new?template=feature-request.md)

As a workaround, have you considered using unix sockets for this?

Best regards

---

<div class="post-metadata">

**Author:** ![cafuego](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cafuego/32/25146_2.png) [@cafuego](https://discuss.elastic.co/u/cafuego)\
**Post date:** [November 18, 2019, 5:09am UTC](https://discuss.elastic.co/t/haproxy-module-does-not-honour-ssl-verification-mode-none/206906/4 "2019-11-18T05:09:38Z")

</div>

Hi @exekias,

I have no access (except via https) to the haproxy instances, so I can't access the socket file on the haproxy hosts.

Issue is [https://github.com/elastic/beats/issues/14579](https://github.com/elastic/beats/issues/14579)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 16, 2019, 7:10am UTC](https://discuss.elastic.co/t/haproxy-module-does-not-honour-ssl-verification-mode-none/206906/5 "2019-12-16T07:10:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
