# Ignore ssl\_certificate\_validation in Http filter plugin

**URL:** <https://discuss.elastic.co/t/ignore-ssl-certificate-validation-in-http-filter-plugin/265379>\
**Category:** Logstash\
**Created:** [February 24, 2021, 5:07pm UTC](https://discuss.elastic.co/t/ignore-ssl-certificate-validation-in-http-filter-plugin/265379 "2021-02-24T17:07:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![d71247](https://avatars.discourse-cdn.com/v4/letter/d/47e85d/32.png) [@d71247](https://discuss.elastic.co/u/d71247)\
**Post date:** [February 24, 2021, 5:07pm UTC](https://discuss.elastic.co/t/ignore-ssl-certificate-validation-in-http-filter-plugin/265379/1 "2021-02-24T17:07:40Z")

</div>

Hi Team,

I have installed logstash7.9.2 in the Linux server. I have created a configuration which will connect to the Ansible-tower rest API using http filter plugin.  
My question is there a way to disable ssl/tls verification in the mutate section ( Http filter plugin ) on the logstash pipeline configuration .  
The Logstash.conf file contains:

```auto
input {

    http {
    codec => json
                }

}

filter {

    http {
                url => "https://xxxxxxxxxxx/api/v2/jobs/%{[job_id]}/job_host_summaries/"
                verb => "GET"
                body_format => "json"
                headers => {
                "Authorization" => "xxxxxxxxxxxxxxxxxxxxx"
                }
                target_body => "host_summaries"

        }

mutate {
    add_field => { "host_tmp" => "%{[host_summaries][results][0][summary_fields][host][name]}" }
}

}

output {
    stdout { codec => rubydebug }
  }

```

---

<div class="post-metadata">

**Author:** ![d71247](https://avatars.discourse-cdn.com/v4/letter/d/47e85d/32.png) [@d71247](https://discuss.elastic.co/u/d71247)\
**Post date:** [March 1, 2021, 6:19pm UTC](https://discuss.elastic.co/t/ignore-ssl-certificate-validation-in-http-filter-plugin/265379/2 "2021-03-01T18:19:47Z")

</div>

how Ignore ssl\_certificate\_validation in Http filter plugin ?§

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 1, 2021, 8:01pm UTC](https://discuss.elastic.co/t/ignore-ssl-certificate-validation-in-http-filter-plugin/265379/3 "2021-03-01T20:01:24Z")

</div>

You cannot ignore it. There is an [open issue](https://github.com/logstash-plugins/logstash-filter-http/issues/13) requesting this, but I do not forsee it being implemented.

A couple of years ago the [ability](https://github.com/logstash-plugins/logstash-mixin-http_client/blob/73b1a6d089fafa6df3f00b4de7781072db71307b/lib/logstash/plugin_mixins/http_client.rb#L122) to set the :verify option on the [Manticore client](https://www.rubydoc.info/github/cheald/manticore/Manticore%2FClient:initialize) ssl parameter was removed from the http filter (note that that is a version of the code from 2016). It looks to me as though it would not have worked anyways.

You can download the certificate from whatever endpoint you are connecting to and add it to a truststore. However, it will still have to be a name-matched certificate. Just adding the cert or the CA cert will not get you around that.

---

<div class="post-metadata">

**Author:** ![d71247](https://avatars.discourse-cdn.com/v4/letter/d/47e85d/32.png) [@d71247](https://discuss.elastic.co/u/d71247)\
**Post date:** [March 2, 2021, 8:53am UTC](https://discuss.elastic.co/t/ignore-ssl-certificate-validation-in-http-filter-plugin/265379/4 "2021-03-02T08:53:29Z")

</div>

Thank you @Badger 😀

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2021, 8:53am UTC](https://discuss.elastic.co/t/ignore-ssl-certificate-validation-in-http-filter-plugin/265379/5 "2021-03-30T08:53:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
