# Http: TLS handshake error from x.x.x.x:xxxx EOF

**URL:** https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414
**Category:** APM
**Tags:** nodejs, server
**Created:** [April 23, 2020, 8:47am UTC](https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414 "2020-04-23T08:47:18Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![Robert\_Bridgeman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_bridgeman/32/66912_2.png) [@Robert\_Bridgeman](https://discuss.elastic.co/u/Robert_Bridgeman)
#### Post date: [April 23, 2020, 8:47am UTC](https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414/1 "2020-04-23T08:47:18Z")

</div>

If you are asking about a problem you are experiencing, please use the following template, as it will help us help you. If you have a different problem, please delete all of this text 🙂

**Kibana version** : `7.6.2`

**Elasticsearch version** : `7.6.2`

**APM Server version** : `7.6.2`

**APM Agent language and version** : `node.js 3.5.0`

**Browser version** :

**Original install method (e.g. download page, yum, deb, from source, etc.) and version**: `yum`

**Fresh install or upgraded from other version?** `Fresh install`

**Is there anything special in your setup?** For example, are you using the Logstash or Kafka outputs? Are you using a load balancer in front of the APM Servers? Have you changed index pattern, generated custom templates, changed agent configuration etc.

`Yes, there's an ALB in front of the APM server, and one infront of the servers hosting the APM agents`

**Description of the problem including expected versus actual behavior. Please include screenshots (if relevant)**:  
`After configuring APM Server and the node.js agent, I see this in the logs: http: TLS handshake error from <ommitted_IP>:<ommitted_port>: EOF I'm able to see information from the APM Server itself, the agents are trying to send data.`

**Steps to reproduce** :

1. Install full stack, install apm
2. Configure apm server according to the docs, to include ssl and token auth (using self signed cert from elasticsearch-certutil)
3. Configure node.js agent as per docs: [https://www.elastic.co/guide/en/apm/agent/nodejs/current/configuring-the-agent.html#agent-configuration-object](https://www.elastic.co/guide/en/apm/agent/nodejs/current/configuring-the-agent.html#agent-configuration-object)

**Errors in browser console (if relevant)**:

**Provide logs and/or server output (if relevant)**:

`The only thing in the logs are the http: TLS handshake errors, from each server, on each port. No other errors from any other enabled service eg. auditbeat, metricbeat, kibana, elasticsearh. `

---

<div class="post-metadata">

### Author: ![felixbarny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felixbarny/32/27341_2.png) [@felixbarny](https://discuss.elastic.co/u/felixbarny)
#### Post date: [April 23, 2020, 10:42am UTC](https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414/2 "2020-04-23T10:42:23Z")

</div>

What's new in APM Server 7.6 is that is supports using TLSv1.3 by default. I'm not a node.js expert but in Java there are some versions where there's a bug in the TLSv1.3 implementation.

Try to remove `TLSv1.3` from the `supported_protocols` in APM Server: [https://www.elastic.co/guide/en/apm/server/current/agent-server-ssl.html#\_supported\_protocols\_2](https://www.elastic.co/guide/en/apm/server/current/agent-server-ssl.html#_supported_protocols_2)

---

<div class="post-metadata">

### Author: ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)
#### Post date: [April 23, 2020, 11:40am UTC](https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414/3 "2020-04-23T11:40:12Z")

</div>

Hi @Robert_Bridgeman,  
when using self-signed certificates you need to also configure the [`serverCaCertFile`](https://www.elastic.co/guide/en/apm/agent/nodejs/current/configuration.html#server-ca-cert-file) option for the nodejs agent.

---

<div class="post-metadata">

### Author: ![Robert\_Bridgeman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_bridgeman/32/66912_2.png) [@Robert\_Bridgeman](https://discuss.elastic.co/u/Robert_Bridgeman)
#### Post date: [April 23, 2020, 3:48pm UTC](https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414/4 "2020-04-23T15:48:36Z")

</div>

Thanks I will try that.

---

<div class="post-metadata">

### Author: ![Robert\_Bridgeman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_bridgeman/32/66912_2.png) [@Robert\_Bridgeman](https://discuss.elastic.co/u/Robert_Bridgeman)
#### Post date: [April 23, 2020, 4:43pm UTC](https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414/5 "2020-04-23T16:43:08Z")

</div>

@simitt is there an option for the client.key and the client.cer as well?

---

<div class="post-metadata">

### Author: ![Robert\_Bridgeman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_bridgeman/32/66912_2.png) [@Robert\_Bridgeman](https://discuss.elastic.co/u/Robert_Bridgeman)
#### Post date: [April 24, 2020, 3:38am UTC](https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414/6 "2020-04-24T03:38:39Z")

</div>

I disabled TLS v1.3 and enabled the severcacert function, the error is now gone. I'm not receiving any data from the agents. I do have it set to run before any other service, and still I'm getting no information back.

there's no errors in the logs.

---

<div class="post-metadata">

### Author: ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)
#### Post date: [April 24, 2020, 11:57am UTC](https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414/7 "2020-04-24T11:57:41Z")

</div>

Without any error logs from the agent or the server this is hard to figure out. Could you try to set it up in a testing environment without TLS configured to see if there is a general issue with the setup or something specific to TLS?

---

<div class="post-metadata">

### Author: ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)
#### Post date: [April 24, 2020, 8:28pm UTC](https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414/8 "2020-04-24T20:28:42Z")

</div>

> Yes, there's an ALB in front of the APM server

As a first step I'd try to directly connect the APM agent and APM server (without the ALB in between). IMO that's a component we generally don't test with our setup, so there's a chance for issues there. If it still doesn't work without the ALB I'd try to connect without TLS as Silvia suggested.

There are too many components involved right now and the first step should be to isolate the problem.

---

<div class="post-metadata">

### Author: ![Robert\_Bridgeman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_bridgeman/32/66912_2.png) [@Robert\_Bridgeman](https://discuss.elastic.co/u/Robert_Bridgeman)
#### Post date: [April 24, 2020, 8:45pm UTC](https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414/9 "2020-04-24T20:45:03Z")

</div>

I'll try that

---

<div class="post-metadata">

### Author: ![Robert\_Bridgeman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_bridgeman/32/66912_2.png) [@Robert\_Bridgeman](https://discuss.elastic.co/u/Robert_Bridgeman)
#### Post date: [April 27, 2020, 4:59pm UTC](https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414/10 "2020-04-27T16:59:54Z")

</div>

It was an issue with TLS on the client side. Cleared it up, it's working now. Thanks!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 18, 2020, 1:00pm UTC](https://discuss.elastic.co/t/http-tls-handshake-error-from-x-x-x-x-xxxx-eof/229414/11 "2020-05-18T13:00:12Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
