# How to configure SSL for logstash-input-tcp when running on windows?

**URL:** <https://discuss.elastic.co/t/how-to-configure-ssl-for-logstash-input-tcp-when-running-on-windows/85260>\
**Category:** Logstash\
**Created:** [May 10, 2017, 2:17pm UTC](https://discuss.elastic.co/t/how-to-configure-ssl-for-logstash-input-tcp-when-running-on-windows/85260 "2017-05-10T14:17:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tonni\_Hult](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tonni_hult/32/11992_2.png) [@Tonni\_Hult](https://discuss.elastic.co/u/Tonni_Hult)\
**Post date:** [May 10, 2017, 2:17pm UTC](https://discuss.elastic.co/t/how-to-configure-ssl-for-logstash-input-tcp-when-running-on-windows/85260/1 "2017-05-10T14:17:34Z")

</div>

Hi

I need help in getting the ssl configuration correct. We are running ELK on windows servers and are now sending the logs from nxlog to logstash over tcp, port 5000. Now we are switching over to ssl but I can't seem to get the configuration right.

For testing purpose I've created a self-signed certificate which I've converted from a .pfx to .cer and .key files. I've also opened up the certificate and removed the bits before ----BEING as instructed in [https://gist.github.com/ericharth/8334664](https://gist.github.com/ericharth/8334664)

We are running Logstash version 2.4.1 and my configuration is as below

```
tcp {
	port => 443
	codec => json
	ssl_enable => true
	ssl_cert => "<path_to_crt>"
	ssl_key => "<path_to_key>"
	ssl_key_passphrase => "<passphrase>"
	ssl_verify => false
	tags => "ssl_transfer"
}

```

For the path for example in ssl\_cert I've tried using "F:\cert.cer", "/f/cert.cer", "F:/cert.cer", "F:\cert.cer" but I can not get logstash to start up correctly. The errors I mainly get are these

{:timestamp=\>"2017-05-10T14:33:37.837000+0200", :message=\>"Could not inititalize SSL context", :exception=\>#\<OpenSSL::PKey::RSAError: Neither PUB key nor PRIV key:\>, :backtrace=\>["org/jruby/ext/openssl/PKeyRSA.java:285:in `initialize'", "C:/monitoring/logstash-2.4.1/vendor/bundle/jruby/1.9/gems/logstash-input-tcp-3.0.6/lib/logstash/inputs/tcp.rb:214:in`ssl\_context'",

{:timestamp=\>"2017-05-10T14:48:48.399000+0200", :message=\>"Invalid setting for tcp input plugin:\n\n input {\n tcp {\n # This setting must be a path\n # File does not exist or cannot be opened /F/certificates/funwithflagscertificate.crt\n ssl\_cert =\> "/F/cert.crt"\n ...\n }\n }", :level=\>:error}

Greatful for any help  
Tonni

---

<div class="post-metadata">

**Author:** ![Tonni\_Hult](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tonni_hult/32/11992_2.png) [@Tonni\_Hult](https://discuss.elastic.co/u/Tonni_Hult)\
**Post date:** [May 12, 2017, 8:36am UTC](https://discuss.elastic.co/t/how-to-configure-ssl-for-logstash-input-tcp-when-running-on-windows/85260/2 "2017-05-12T08:36:50Z")

</div>

I got it working by using the tip "Convert the .pfx file using OpenSSL" from this site [https://www.sslshopper.com/move-or-copy-an-ssl-certificate-from-a-windows-server-to-an-apache-server.html](https://www.sslshopper.com/move-or-copy-an-ssl-certificate-from-a-windows-server-to-an-apache-server.html) Regarding the path it worked fine with for example this

ssl\_cert =\> "c:\cert\certificate.cert"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2017, 8:37am UTC](https://discuss.elastic.co/t/how-to-configure-ssl-for-logstash-input-tcp-when-running-on-windows/85260/3 "2017-06-09T08:37:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
