# Heartbeat TLS ServerName not being set correctly

**URL:** <https://discuss.elastic.co/t/heartbeat-tls-servername-not-being-set-correctly/224280>\
**Category:** Beats\
**Tags:** heartbeat\
**Created:** [March 19, 2020, 2:42pm UTC](https://discuss.elastic.co/t/heartbeat-tls-servername-not-being-set-correctly/224280 "2020-03-19T14:42:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![michael.russell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael.russell/32/27889_2.png) [@michael.russell](https://discuss.elastic.co/u/michael.russell)\
**Post date:** [March 19, 2020, 2:42pm UTC](https://discuss.elastic.co/t/heartbeat-tls-servername-not-being-set-correctly/224280/1 "2020-03-19T14:42:08Z")

</div>

When trying to monitor an SSL enabled endpoint it seems like Heartbeat is setting the ServerName to the IP address instead of the hostname. For setups where the certificate is only signed with the domain (and not all IP addresses) this causes verification to fail. For setups where different certificates are served depending on hostname (Kubernetes nginx-ingress being a popular example) it means that Heartbeat tries to verify the invalid fake certificate that is returned when no matching domains are found.

Looking through the code and docs I can't find a way to have the verified ServerName be the domain instead of the resolved IP address.

Example configuration:

```auto
- type: "tcp"
  name: "elastic.co"
  schedule: "@every 60s"
  hosts: ["tls://elastic.co:443"]
  ssl:
    enabled: true

```

Error message:

```auto
x509: cannot validate certificate for 151.101.194.217 because it doesn't contain any IP SANs"

```

Here is the section which is setting the ServerName

> <https://github.com/elastic/beats/blob/4f5d1a1bee508e8fcd35531cfcc8509563314517/libbeat/common/transport/tlscommon/tls_config.go#L109-L118>

The `host` string which gets passed in actually ends up being the resolved IP address.

To confirm that this was the issue I hard coded it to "[elastic.co](http://elastic.co)" allows the certificate to be verified properly.

```auto
config.ServerName = "elastic.co"

```

I have reproduced this with the latest releases version (running from official Docker images) and also with the latest builds from the master branch.

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [March 19, 2020, 5:36pm UTC](https://discuss.elastic.co/t/heartbeat-tls-servername-not-being-set-correctly/224280/2 "2020-03-19T17:36:20Z")

</div>

Thanks so much @michael.russell. I've opened an issue here: [https://github.com/elastic/beats/issues/17123](https://github.com/elastic/beats/issues/17123)

I hope to tackle this fairly soon, I think the fix should be relatively simple here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 16, 2020, 5:36pm UTC](https://discuss.elastic.co/t/heartbeat-tls-servername-not-being-set-correctly/224280/3 "2020-04-16T17:36:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
