# Kafka establishes tls1.2 with openssl, but not filebeat

**URL:** <https://discuss.elastic.co/t/kafka-establishes-tls1-2-with-openssl-but-not-filebeat/126824>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 4, 2018, 10:12pm UTC](https://discuss.elastic.co/t/kafka-establishes-tls1-2-with-openssl-but-not-filebeat/126824 "2018-04-04T22:12:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![cement](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cement/32/29525_2.png) [@cement](https://discuss.elastic.co/u/cement)\
**Post date:** [April 4, 2018, 10:12pm UTC](https://discuss.elastic.co/t/kafka-establishes-tls1-2-with-openssl-but-not-filebeat/126824/1 "2018-04-04T22:12:32Z")

</div>

Filebeat is configured to talk to kafka over tls, but it fails with "INFO kafka/log.go:36 Failed to connect to broker : tls: first record does not look like a TLS handshake"

openssl s\_client, using the same key, ca and cert, is able to connect.

Wireshark shows "Ignored Unknown Record" where the openssl connection has "Server Hello".

Relevant version info:

- go1.10 linux/amd64
- filebeat 7.0.0-alpha1 (amd64), libbeat 7.0.0-alpha1 [unknown built unknown]
- openssl 1.0.2g
- kafka 2.12-1.0.0

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 5, 2018, 2:25pm UTC](https://discuss.elastic.co/t/kafka-establishes-tls1-2-with-openssl-but-not-filebeat/126824/2 "2018-04-05T14:25:13Z")

</div>

Kafka requires some connection bootstrapping protocol. The bootstrapping first gets the cluster metadata from one of the brokers first. The meta-data is used to connect to the brokers. Check the kafka brokers advertised listeners actually configuring TLS.

Just using `openssl s_client` is only testing the initial connection during the bootstrap. The final step of actually connecting to the clusters is not simulated by `openssl s_client`.

---

<div class="post-metadata">

**Author:** ![cement](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cement/32/29525_2.png) [@cement](https://discuss.elastic.co/u/cement)\
**Post date:** [April 5, 2018, 3:52pm UTC](https://discuss.elastic.co/t/kafka-establishes-tls1-2-with-openssl-but-not-filebeat/126824/3 "2018-04-05T15:52:49Z")

</div>

Wireshark suggests the initial connection is failing.

Does a TLS connection happen before broker.GetMetadata ([github.com/elastic/beats/vendor/github.com/Shopify/sarama/client.go:633](http://github.com/elastic/beats/vendor/github.com/Shopify/sarama/client.go:633)) ? Further up the callstack is client.Connect() in [github.com/elastic/beats/libbeat/outputs/kafka/client.go:72](http://github.com/elastic/beats/libbeat/outputs/kafka/client.go:72)

---

<div class="post-metadata">

**Author:** ![cement](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cement/32/29525_2.png) [@cement](https://discuss.elastic.co/u/cement)\
**Post date:** [April 5, 2018, 8:58pm UTC](https://discuss.elastic.co/t/kafka-establishes-tls1-2-with-openssl-but-not-filebeat/126824/4 "2018-04-05T20:58:25Z")

</div>

Looks related to this [https://issues.apache.org/jira/browse/KAFKA-3647?focusedCommentId=15270520&page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel#comment-15270520](https://issues.apache.org/jira/browse/KAFKA-3647?focusedCommentId=15270520&page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel#comment-15270520)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 6, 2018, 10:53am UTC](https://discuss.elastic.co/t/kafka-establishes-tls1-2-with-openssl-but-not-filebeat/126824/5 "2018-04-06T10:53:15Z")

</div>

What exactly is wireshark suggesting? Can you share the pcap of filebeat trying to connect to kafka?

Can you share filebeat/kafka configs and logs?

How did you create your certificates?

---

<div class="post-metadata">

**Author:** ![cement](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cement/32/29525_2.png) [@cement](https://discuss.elastic.co/u/cement)\
**Post date:** [April 6, 2018, 8:29pm UTC](https://discuss.elastic.co/t/kafka-establishes-tls1-2-with-openssl-but-not-filebeat/126824/6 "2018-04-06T20:29:10Z")

</div>

Wireshark is suggesting kafka doesn't respond to filebeat's Client Hello with a Server Hello.

My issue is resolved now, but for future reference the problem was that kafka didn't use the same ciphers as filebeat.

"When creating the keystore on the server, you need to pass the -keyalg RSA argument or else the Kafka broker will operate using an extremely limited set of ciphers, none of which are supported by Golang. See #643 for more details."  
([https://github.com/Shopify/sarama/wiki/Frequently-Asked-Questions#why-cant-sarama-connect-to-my-kafka-cluster-using-ssl](https://github.com/Shopify/sarama/wiki/Frequently-Asked-Questions#why-cant-sarama-connect-to-my-kafka-cluster-using-ssl))

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2018, 8:29pm UTC](https://discuss.elastic.co/t/kafka-establishes-tls1-2-with-openssl-but-not-filebeat/126824/7 "2018-05-04T20:29:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
