# How to configure logstash input to accept https post from a third party service

**URL:** <https://discuss.elastic.co/t/how-to-configure-logstash-input-to-accept-https-post-from-a-third-party-service/235472>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [June 3, 2020, 6:02am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-input-to-accept-https-post-from-a-third-party-service/235472 "2020-06-03T06:02:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rndee](https://avatars.discourse-cdn.com/v4/letter/r/839c29/32.png) [@rndee](https://discuss.elastic.co/u/rndee)\
**Post date:** [June 3, 2020, 6:02am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-input-to-accept-https-post-from-a-third-party-service/235472/1 "2020-06-03T06:02:44Z")

</div>

Hi  
I have a third party service which posts json data to our logstash instance. It is working using http, now I want to harden the connection using https. The third-party service ssl certificate was already registered in my linux server (/etc/ssl/certs).

In my understanding my logstash instance acts as a browser does. So it should handle the ssl connection when I give it a valid system certificate store, which is located in /etc/ssl/certs.

My input side looks like this

```auto
input {
    http {
        ssl => true
        ssl_verify_mode => "peer"
        ssl_certificate_authorities => ["/etc/ssl/certs"]
        port => 8443
    }
} 

```

When I run the logstash the Error "\<LogStash::ConfigurationError: Certificate or JKS must be configured" shows up. I don't have a key and crt file from the Server which is sending the data, I could organize the .pem file. In the /etc/ssl/certs the servers-used certificate is already registered. I can trust. When I surf to this webpage I have to 'accept' the ssl neither, because it is in the system certification store.

As described here I should make use of certificate and key:  
Check the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http.html#plugins-inputs-http-ssl). "You can enable encryption by setting `ssl` to true and configuring the `ssl_certificate` and `ssl_key` options."

This input helped neither: [https://www.elastic.co/de/blog/tls-elastic-stack-elasticsearch-kibana-logstash-filebeat](https://www.elastic.co/de/blog/tls-elastic-stack-elasticsearch-kibana-logstash-filebeat)

Is it necessary to have a certificate which is global trusted to get that connection running?

Lukas

---

<div class="post-metadata">

**Author:** ![rndee](https://avatars.discourse-cdn.com/v4/letter/r/839c29/32.png) [@rndee](https://discuss.elastic.co/u/rndee)\
**Post date:** [June 16, 2020, 2:07pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-input-to-accept-https-post-from-a-third-party-service/235472/2 "2020-06-16T14:07:02Z")

</div>

Solution was:  
put it behind a nginx proxy which handles the ssl certification. Had to register a subdomain [loginput.company.com](http://loginput.company.com) which is pointing to the fix ip of the nginx proxy. the nginx proxy just forwards it and the input part gets easy:

```auto
input {
  http {
      port => <dest-port>
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2020, 2:07pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-input-to-accept-https-post-from-a-third-party-service/235472/3 "2020-07-14T14:07:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
