# Http input with ssl

**URL:** <https://discuss.elastic.co/t/http-input-with-ssl/115338>\
**Category:** Logstash\
**Created:** [January 12, 2018, 4:41pm UTC](https://discuss.elastic.co/t/http-input-with-ssl/115338 "2018-01-12T16:41:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![skydiablo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skydiablo/32/26527_2.png) [@skydiablo](https://discuss.elastic.co/u/skydiablo)\
**Post date:** [January 12, 2018, 4:41pm UTC](https://discuss.elastic.co/t/http-input-with-ssl/115338/1 "2018-01-12T16:41:46Z")

</div>

hey guys,  
im very happy with my current ES-Stack and all works fine... except my http input with SSL on ☹

if i enable the SSL, there is no way to push stuff to my endpoint, this is my conf:

```auto
input {
  http {
    host => "XXX.XXX.XXX.XXX"
    port => XXXX
    codec => "json"
    ssl => true
    keystore => "/etc/logstash/conf.d/ssl/keystore.jks"
    keystore_password => "xxxxxx"
    additional_codecs => {
      "application/json" => "json"
    }
    response_headers => {
      "Access-Control-Allow-Origin" => "*"
      "Content-Type" => "text/plain"
      "Access-Control-Allow-Headers" => "Origin, X-Requested-With, Content-Type, Accept"
    }
    type => "js_error"
  }
}

filter {
}

output {
  if[type] == "js_error" {
    elasticsearch {
      hosts => "http://localhost:9200"
      user => "xxxxxxxx"
      password => "xxxxxxxxxxxx"
      index => js_error
    }
  }
}

```

so nothing realy special magic... my certs are come from `letsencrypt`and keystore is build with `keytool` (i hope i have add all needed certs and root certs ?). but a simple `curl` test failed:

```auto
curl -X POST https://MY-DOMAIN:XXXX -H 'Content-Type: application/json' -d '{"message":"hello world"}'

```

ends in this error:

```auto
curl: (35) gnutls_handshake() failed: The TLS connection was non-properly terminated.

```

other seems nearly same problems, like:

- [Logstash HTTP input with SSL keystore](https://discuss.elastic.co/t/logstash-http-input-with-ssl-keystore/108550)

so any suggestions or tips?

greez & thx, sky...

---

<div class="post-metadata">

**Author:** ![skydiablo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skydiablo/32/26527_2.png) [@skydiablo](https://discuss.elastic.co/u/skydiablo)\
**Post date:** [January 15, 2018, 11:05am UTC](https://discuss.elastic.co/t/http-input-with-ssl/115338/2 "2018-01-15T11:05:46Z")

</div>

ok, it seems i missed the private-key into my keystore. but i cant insert my letsencrypt-cert ☹

letsencrypt returned me a `private.key` file (header calls: `-----BEGIN PRIVATE KEY-----`), if i try to import this file to a keystore like this:

```auto
keytool -import -keystore keystore.jks -trustcacerts -file private.key -alias private

```

its ends in this error:

```auto
keytool error: java.lang.Exception: Input not an X.509 certificate

```

so, how can i convert my letsencrypt private key file into an x509 cert?

---

<div class="post-metadata">

**Author:** ![skydiablo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skydiablo/32/26527_2.png) [@skydiablo](https://discuss.elastic.co/u/skydiablo)\
**Post date:** [January 17, 2018, 1:52pm UTC](https://discuss.elastic.co/t/http-input-with-ssl/115338/3 "2018-01-17T13:52:54Z")

</div>

ok, i have done it! this is my current script:

```auto
#!/bin/sh

DOMAIN=my-domain.tld
KEYSTOREPW=swssws
LOGSTASH_SSL_CONF=/etc/logstash/conf.d/ssl/$DOMAIN
LIVE=/etc/letsencrypt/live/$DOMAIN

sudo openssl pkcs12 -export -in $LIVE/cert.pem -inkey $LIVE/privkey.pem -out cert_and_key.p12 -name myalias -CAfile $LIVE/chain.pem -caname root -password pass:$KEYSTOREPW
sudo keytool -importkeystore -destkeystore keystore.jks -srckeystore cert_and_key.p12 -srcstoretype PKCS12 -alias myalias -srcstorepass $KEYSTOREPW -deststorepass $KEYSTOREPW -destkeypass $KEYSTOREPW
sudo keytool -import -noprompt -trustcacerts -alias root -file $LIVE/chain.pem -keystore keystore.jks -srcstorepass $KEYSTOREPW -deststorepass $KEYSTOREPW -destkeypass $KEYSTOREPW

sudo openssl pkcs12 -export -in $LIVE/fullchain.pem -inkey $LIVE/privkey.pem -out pkcs.p12 -name glassfish-instance -password pass:$KEYSTOREPW
sudo keytool -importkeystore -destkeystore keystore.jks -srckeystore pkcs.p12 -srcstoretype PKCS12 -alias glassfish-instance -srcstorepass $KEYSTOREPW -deststorepass $KEYSTOREPW -destkeypass $KEYSTOREPW
sudo openssl pkcs12 -export -in $LIVE/fullchain.pem -inkey $LIVE/privkey.pem -out pkcs.p12 -name s1as -password pass:$KEYSTOREPW
sudo keytool -importkeystore -destkeystore keystore.jks -srckeystore pkcs.p12 -srcstoretype PKCS12 -alias s1as -srcstorepass $KEYSTOREPW -deststorepass $KEYSTOREPW -destkeypass $KEYSTOREPW

sudo keytool -list -keystore keystore.jks -storepass $KEYSTOREPW

sudo cp -f keystore.jks $LOGSTASH_SSL_CONF

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2018, 1:53pm UTC](https://discuss.elastic.co/t/http-input-with-ssl/115338/4 "2018-02-14T13:53:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
