# Logstash 2.0 plugin input-relp option ssl

**URL:** <https://discuss.elastic.co/t/logstash-2-0-plugin-input-relp-option-ssl/33393>\
**Category:** Logstash\
**Created:** [October 30, 2015, 4:00pm UTC](https://discuss.elastic.co/t/logstash-2-0-plugin-input-relp-option-ssl/33393 "2015-10-30T16:00:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![alicia](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@alicia](https://discuss.elastic.co/u/alicia)\
**Post date:** [October 30, 2015, 4:00pm UTC](https://discuss.elastic.co/t/logstash-2-0-plugin-input-relp-option-ssl/33393/1 "2015-10-30T16:00:33Z")

</div>

in logstash.log  
message=\>"SSL Error", :exception=\>#\<OpenSSL::SSL::SSLError: Unrecognized SSL message, plaintext connection?\>, :backtrace=\>["org/jruby/ext/openssl/SSLSocket.java:262:in `accept'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/jruby-openssl-0.9.12-java/lib/jopenssl19/openssl/ssl-internal.rb:106:in`accept'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-relp-2.0.3/lib/logstash/util/relp.rb:128:in `accept'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-relp-2.0.3/lib/logstash/inputs/relp.rb:123:in`run'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.0.0.rc1-java/lib/logstash/pipeline.rb:180:in `inputworker'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.0.0.rc1-java/lib/logstash/pipeline.rb:174:in`start\_input'"], :level=\>:error}

I have oepnjdk 7 and logstash 2.0 plugin input-relp option ssl

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 31, 2015, 11:18pm UTC](https://discuss.elastic.co/t/logstash-2-0-plugin-input-relp-option-ssl/33393/2 "2015-10-31T23:18:53Z")

</div>

It'd help if you provided your config.

---

<div class="post-metadata">

**Author:** ![alicia](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@alicia](https://discuss.elastic.co/u/alicia)\
**Post date:** [November 2, 2015, 8:14am UTC](https://discuss.elastic.co/t/logstash-2-0-plugin-input-relp-option-ssl/33393/3 "2015-11-02T08:14:55Z")

</div>

## in input-relp.conf

```
input {
        relp {
        port => 10514
        type => "logs"
        ssl_cacert => "/etc/pki/relp/ca.pem"
        ssl_cert => "/etc/pki/relp/server-cert.pem"
        ssl_key => "/etc/pki/relp/server-key.pem"
        ssl_enable => true
        }
}
```

## and in my client

```
$ModLoad omrelp
$ModLoad imtcp
$ActionQueueFileName fwdRule1 # unique name prefix for spool files
$ActionQueueMaxDiskSpace 1g # 1gb space limit (use as much as possible)
$ActionQueueSaveOnShutdown on # save messages to disk on shutdown
$ActionQueueType LinkedList # run asynchronously
$ActionResumeRetryCount -1 # infinite retries if host is down

$DefaultNetstreamDriver gtls

# certificate files
$DefaultNetstreamDriverCAFile /etc/pki/relp/ca.pem
$DefaultNetstreamDriverCertFile /etc/pki/relp/keepeek-test-cert.pem
$DefaultNetstreamDriverKeyFile /etc/pki/relp/keepeek-test-key.pem

# Provides TCP syslog reception
$InputTCPServerStreamDriverAuthMode x509/name
#$InputTCPServerStreamDriverAuthMode anon
$ActionSendStreamDriverMode 1 # run driver in TLS-only mode
$ActionSendStreamDriverPermittedPeer kibana-test.test

*.* :omrelp:ip_server:10514
```

## generate certificat with

> **[Using TLS with RELP](http://www.rsyslog.com/using-tls-with-relp/)**
>
> In this guide, we want to describe how to setup rsyslog with a RELP connection which is to be secured with TLS. For this guide you need at least rsyslog 7.5.1 and librelp 1.1.3 as well as gnutls 2.10.0 or above. These need to be installed on the...

Thanks

Alicia

---

<div class="post-metadata">

**Author:** ![pbmsys](https://avatars.discourse-cdn.com/v4/letter/p/57b2e6/32.png) [@pbmsys](https://discuss.elastic.co/u/pbmsys)\
**Post date:** [November 2, 2015, 10:40am UTC](https://discuss.elastic.co/t/logstash-2-0-plugin-input-relp-option-ssl/33393/4 "2015-11-02T10:40:12Z")

</div>

Seeing the same issue when parsing logs via TCP input from NXLOG.  
Logstash throws an SSL Error an exits.

/Peter

---

<div class="post-metadata">

**Author:** ![alicia](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@alicia](https://discuss.elastic.co/u/alicia)\
**Post date:** [November 3, 2015, 10:48am UTC](https://discuss.elastic.co/t/logstash-2-0-plugin-input-relp-option-ssl/33393/5 "2015-11-03T10:48:17Z")

</div>

may be that the problem from compatibility betwen gnutls and openssl : rsyslog has been written to use the gnuTLS library, and logstash has been written to use the openssl library ???

---

<div class="post-metadata">

**Author:** ![pbmsys](https://avatars.discourse-cdn.com/v4/letter/p/57b2e6/32.png) [@pbmsys](https://discuss.elastic.co/u/pbmsys)\
**Post date:** [November 4, 2015, 6:45am UTC](https://discuss.elastic.co/t/logstash-2-0-plugin-input-relp-option-ssl/33393/6 "2015-11-04T06:45:50Z")

</div>

@alicia Strange, that i see the same error parsing logs from NXLog.  
I have not figured out a solution though. you?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:24am UTC](https://discuss.elastic.co/t/logstash-2-0-plugin-input-relp-option-ssl/33393/7 "2017-07-06T05:24:08Z")

</div>


