# How to use ssl\_certificate\_authorities in Logstash?

**URL:** <https://discuss.elastic.co/t/how-to-use-ssl-certificate-authorities-in-logstash/379517>\
**Category:** Logstash\
**Created:** [June 26, 2025, 9:42am UTC](https://discuss.elastic.co/t/how-to-use-ssl-certificate-authorities-in-logstash/379517 "2025-06-26T09:42:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![HarimbolaSantatra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harimbolasantatra/32/136974_2.png) [@HarimbolaSantatra](https://discuss.elastic.co/u/HarimbolaSantatra)\
**Post date:** [June 26, 2025, 9:42am UTC](https://discuss.elastic.co/t/how-to-use-ssl-certificate-authorities-in-logstash/379517/1 "2025-06-26T09:42:04Z")

</div>

I have the same issue discussed in [this question](https://discuss.elastic.co/t/logstash-error-invalid-setting-for-elasticsearch-output-plugin/314196). The error log is:

```auto
sept. 12 14:57:47 local logstash[45016]: # File does not exist or cannot be opened /etc/logstash/certs/http_ca.crt
sept. 12 14:57:47 local logstash[45016]: ssl_certificate_authorities => "/etc/logstash/certs/http_ca.crt

```

The accepted answer is to change the file permissions but by default the file permission of files in `/etc/logstash` is all `root:root`.

What I want to know is:

1. _what is the best practice for dealing with this issue ?_
2. Should the `ssl_certificate_authorities` parameter be the path to the Elasticsearch CA cert ? I'm asking this because it seems to not be mentioned in the documentation. If this is the case, should we copy this certificate or put it in a shared folder.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 27, 2025, 3:00am UTC](https://discuss.elastic.co/t/how-to-use-ssl-certificate-authorities-in-logstash/379517/2 "2025-06-27T03:00:01Z")

</div>

> [@HarimbolaSantatra](#):
>
> The accepted answer is to change the file permissions but by default the file permission of files in `/etc/logstash` is all `root:root`.

This is the ownership, the permissions for `/etc/logstash/` and its file are to allow read for everyone, `certs` is not a default path, neither is `http_ca.crt` a default file, so you need to check if the permissions for the `certs` sub-directory and the `http_ca.crt` file allows read by everyone since the logstash service is executed under the `logstash` user.

> [@HarimbolaSantatra](#):
>
> what is the best practice for dealing with this issue ?

Not sure if there is one, this is unrelated to Logstash, it is related to Linux permissions.

Personally I prefer to have under `/etc/logstash` just the required configuration files, `logstash.yml`, `pipelines.yml` and `jvm.options`, everything else, including configuration for pipelines are stored under `/opt/logstash`, which is fully owned by the `logstash` user

> [@HarimbolaSantatra](#):
>
> Should the `ssl_certificate_authorities` parameter be the path to the Elasticsearch CA cert ? I'm asking this because it seems to not be mentioned in the documentation. If this is the case, should we copy this certificate or put it in a shared folder.

The path doesn't matter, it is a user choice, the `logstash` user just needs to have permissions to read it.

---

<div class="post-metadata">

**Author:** ![HarimbolaSantatra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harimbolasantatra/32/136974_2.png) [@HarimbolaSantatra](https://discuss.elastic.co/u/HarimbolaSantatra)\
**Post date:** [June 29, 2025, 4:00pm UTC](https://discuss.elastic.co/t/how-to-use-ssl-certificate-authorities-in-logstash/379517/3 "2025-06-29T16:00:08Z")

</div>

Ok I understand.

Another question: there's a `logstash` user so why it is that the permission of files under `/etc/logstash` are `root:root` ? What's the use of a `logstash` user in that case ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 29, 2025, 4:24pm UTC](https://discuss.elastic.co/t/how-to-use-ssl-certificate-authorities-in-logstash/379517/4 "2025-06-29T16:24:28Z")

</div>

> [@HarimbolaSantatra](#):
>
> Another question: there's a `logstash` user so why it is that the permission of files under `/etc/logstash` are `root:root` ?

Everything under `/etc` is owned by the `root` user and `root` group, this path is for, in most of the case, system-wide configurations, so the permissions should be limited to the root user.

> [@HarimbolaSantatra](#):
>
> What's the use of a `logstash` user in that case ?

The `logstash` use is used to run the Logstash service as it is not recommended to run Logstash with root permissions.

---

<div class="post-metadata">

**Author:** ![HarimbolaSantatra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harimbolasantatra/32/136974_2.png) [@HarimbolaSantatra](https://discuss.elastic.co/u/HarimbolaSantatra)\
**Post date:** [June 29, 2025, 5:33pm UTC](https://discuss.elastic.co/t/how-to-use-ssl-certificate-authorities-in-logstash/379517/5 "2025-06-29T17:33:25Z")

</div>

> [@leandrojmp](#):
>
> Everything under `/etc` is owned by the `root` user and `root` group, this path is for, in most of the case, system-wide configurations, so the permissions should be limited to the root user.

But if I'm not mistaken, for Elasticsearch, the files under `/etc/elasticsearch` are owned by `root:elasticsearch`.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 29, 2025, 8:26pm UTC](https://discuss.elastic.co/t/how-to-use-ssl-certificate-authorities-in-logstash/379517/6 "2025-06-29T20:26:42Z")

</div>

> [@HarimbolaSantatra](#):
>
> But if I'm not mistaken, for Elasticsearch, the files under `/etc/elasticsearch` are owned by `root:elasticsearch`.

Different tools may have different requirements, maybe there are some default cases where you need `/etc/elasticsearch/` to be owned by the `elasticsearch` group to make things easier for the user as some certificates and other configurations are created automatically.

In Logstash you will not have any path named `certs` created by default, as you will also not have any certificated created by default, it is all user configured, so it does not matter where they are, just that the `logstash` user running the Logstash service can read the files.

---

<div class="post-metadata">

**Author:** ![HarimbolaSantatra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harimbolasantatra/32/136974_2.png) [@HarimbolaSantatra](https://discuss.elastic.co/u/HarimbolaSantatra)\
**Post date:** [June 30, 2025, 6:56am UTC](https://discuss.elastic.co/t/how-to-use-ssl-certificate-authorities-in-logstash/379517/7 "2025-06-30T06:56:47Z")

</div>

Thanks for your responses! This is solved!
