# Kafka plugin with PEM ssl

**URL:** <https://discuss.elastic.co/t/kafka-plugin-with-pem-ssl/308210>\
**Category:** Logstash\
**Created:** [June 27, 2022, 6:00am UTC](https://discuss.elastic.co/t/kafka-plugin-with-pem-ssl/308210 "2022-06-27T06:00:01Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mikhatanu](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Post date:** [June 27, 2022, 6:00am UTC](https://discuss.elastic.co/t/kafka-plugin-with-pem-ssl/308210/1 "2022-06-27T06:00:01Z")

</div>

Hello, is it possible to use PEM keystore type instead of JKS in the plugin

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 27, 2022, 3:50pm UTC](https://discuss.elastic.co/t/kafka-plugin-with-pem-ssl/308210/2 "2022-06-27T15:50:17Z")

</div>

That is a kafka question, not a logstash question. The input and output pass ssl\_keystore\_type and ssl\_truststore\_type through to the Apache kafka client library and my understanding is that that can handle PEM. See [here](https://codingharbour.com/apache-kafka/using-pem-certificates-with-apache-kafka/) for an example.

---

<div class="post-metadata">

**Author:** ![mikhatanu](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Post date:** [June 28, 2022, 3:31am UTC](https://discuss.elastic.co/t/kafka-plugin-with-pem-ssl/308210/3 "2022-06-28T03:31:04Z")

</div>

so the plugins are actually made by the kafka team?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 28, 2022, 4:28am UTC](https://discuss.elastic.co/t/kafka-plugin-with-pem-ssl/308210/4 "2022-06-28T04:28:58Z")

</div>

No, the plugin itself is supported by Elastic and the community here. However, the kafka plugins (like those for http, jdbc, memcache, mongodb, rabbitmq, s3 and many others) are just wrappers around open source libraries that implement APIs. The kafka input/output do not validate the ssl\_keystore\_type / ssl\_truststore\_type options, they are just passed through to the Kafka client library as ssl.keystore.type / ssl.truststore.type. The plugin has no knowledge of what values are acceptable for those options. It is just a string that is passed on.

When I said it is "not a logstash question" what I meant was that even someone who worked on the logstash plugins would not need to know whether Kafka supports PEM.

The Google search result that I linked to suggests that Kafka does now support PEM, but I cannot be sure. I am sorry if my initial answer was unclear.

---

<div class="post-metadata">

**Author:** ![mikhatanu](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Post date:** [June 28, 2022, 5:56am UTC](https://discuss.elastic.co/t/kafka-plugin-with-pem-ssl/308210/5 "2022-06-28T05:56:35Z")

</div>

so, for example, if i passed an options recognized in kafka but not written in the documentation of logstash kafka plugin, it will work?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 28, 2022, 4:05pm UTC](https://discuss.elastic.co/t/kafka-plugin-with-pem-ssl/308210/6 "2022-06-28T16:05:49Z")

</div>

No, the logstash plugin needs just enough support to allow the plugin option [to be set](https://github.com/logstash-plugins/logstash-input-kafka/blob/80ad0d8bb26e9b371f113e90dd56e3ee2a0e742e/lib/logstash/inputs/kafka.rb#L163) and to [pass it through](https://github.com/logstash-plugins/logstash-input-kafka/blob/80ad0d8bb26e9b371f113e90dd56e3ee2a0e742e/lib/logstash/inputs/kafka.rb#L338).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2022, 4:06pm UTC](https://discuss.elastic.co/t/kafka-plugin-with-pem-ssl/308210/7 "2022-07-26T16:06:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
