# Heartbeat can't connect to endpoint with cert and key

**URL:** <https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436>\
**Category:** Beats\
**Tags:** heartbeat\
**Created:** [November 19, 2019, 5:56am UTC](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436 "2019-11-19T05:56:19Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![rdaimler](https://avatars.discourse-cdn.com/v4/letter/r/46a35a/32.png) [@rdaimler](https://discuss.elastic.co/u/rdaimler)\
**Post date:** [November 19, 2019, 5:56am UTC](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436/1 "2019-11-19T05:56:19Z")

</div>

Hello,

I'm trying to check an endpoint that requires a cert and key. I get a Client.Timeout exceeded while awaiting headers error.

```
- type: http
  id: Bitbucket
  schedule: '@every 20s'
  urls: ["https://bark.tgyu.com/bitbucket"]
  # ssl.verification_mode: none
  ssl:
    certificate: /root/A/public-cert.pem
    key: /root/A/key.pem
  check.response.status: 302
  check.request.method: HEAD
  timeout: 20

```

I can successfully curl the endpoint from the same server.

I'm running elastic 7.1.1

Thanks,  
Rob

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [November 26, 2019, 12:21pm UTC](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436/2 "2019-11-26T12:21:50Z")

</div>

That's a bit mysterious. We tests around that behavior that run successfully.

Can you run heartbeat without no client cert/key specified and let me know what error that gives?

---

<div class="post-metadata">

**Author:** ![rdaimler](https://avatars.discourse-cdn.com/v4/letter/r/46a35a/32.png) [@rdaimler](https://discuss.elastic.co/u/rdaimler)\
**Post date:** [November 26, 2019, 6:05pm UTC](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436/3 "2019-11-26T18:05:24Z")

</div>

Sure,

```
"message": "Head https://asdf.com/bitbucket: dial tcp 123.122.33.33:443: i/o timeout (Client.Timeout exceeded while awaiting headers)"
```

---

<div class="post-metadata">

**Author:** ![rdaimler](https://avatars.discourse-cdn.com/v4/letter/r/46a35a/32.png) [@rdaimler](https://discuss.elastic.co/u/rdaimler)\
**Post date:** [November 26, 2019, 6:13pm UTC](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436/4 "2019-11-26T18:13:35Z")

</div>

I tried with a ca.crt as well with the same result.

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [November 26, 2019, 8:41pm UTC](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436/5 "2019-11-26T20:41:30Z")

</div>

This is very strange behavior. Can you reproduce this behavior against a public endpoint? At this point to debug it I'll need:

1. A way to reproduce it locally
2. To dive into packet capture to see what's going on.

---

<div class="post-metadata">

**Author:** ![rdaimler](https://avatars.discourse-cdn.com/v4/letter/r/46a35a/32.png) [@rdaimler](https://discuss.elastic.co/u/rdaimler)\
**Post date:** [November 26, 2019, 10:37pm UTC](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436/6 "2019-11-26T22:37:25Z")

</div>

Sure, Andrew. Can we set up a conference call? The endpoint is tightly controlled and I can't disclose how it is configured publicly.

Thanks,  
Rob

---

<div class="post-metadata">

**Author:** ![rdaimler](https://avatars.discourse-cdn.com/v4/letter/r/46a35a/32.png) [@rdaimler](https://discuss.elastic.co/u/rdaimler)\
**Post date:** [December 16, 2019, 10:39pm UTC](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436/7 "2019-12-16T22:39:29Z")

</div>

It looks like it's attempting to connect with the ip address instead of the hostname.

```
"message": "Head https://asd.com:443/bitbucket: dial tcp 141.118.21.67:443: i/o timeout (Client.Timeout exceeded while awaiting headers)"

```

I'm guessing it has to go through some extra negotiation process with the ip and can't manage to get through. There is also a reverse proxy in front of the app.

Rob

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [December 17, 2019, 1:45am UTC](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436/8 "2019-12-17T01:45:39Z")

</div>

Sorry for the delay here. It sounds like this is a really detailed TLS issue that might involve an out-of-spec middle-box. Can you share the exact cURL command you're using? That may help.

Our usage of TLS isn't anything special I should mention, it's just the standard golang TLS lib, so I doubt that's the issue here. If there's anything you can do to temporarily test without middleboxes as well that would be a great way to help solve this issue.

WRT to the conference call, we can't provide that level of support through the forum. If you do have a subscription that is something you can reach out to our support engineers about.

---

<div class="post-metadata">

**Author:** ![rdaimler](https://avatars.discourse-cdn.com/v4/letter/r/46a35a/32.png) [@rdaimler](https://discuss.elastic.co/u/rdaimler)\
**Post date:** [December 17, 2019, 1:56am UTC](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436/9 "2019-12-17T01:56:03Z")

</div>

No problem. Holidays are holidays.

I'll probably follow up with support.

curl -v --cert /root/asdf/cert.pem --key /root/asdf/key.pem [https://asdf.com:443/bitbucket](https://asdf.com:443/bitbucket)

That works without errors.

Rob

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2020, 1:56am UTC](https://discuss.elastic.co/t/heartbeat-cant-connect-to-endpoint-with-cert-and-key/208436/10 "2020-01-14T01:56:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
