# Logstash and filebeat are not working with my private CA system

**URL:** <https://discuss.elastic.co/t/logstash-and-filebeat-are-not-working-with-my-private-ca-system/51195>\
**Category:** Beats\
**Created:** [May 27, 2016, 7:18pm UTC](https://discuss.elastic.co/t/logstash-and-filebeat-are-not-working-with-my-private-ca-system/51195 "2016-05-27T19:18:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sean\_Bollin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean_bollin/32/10000_2.png) [@Sean\_Bollin](https://discuss.elastic.co/u/Sean_Bollin)\
**Post date:** [May 27, 2016, 7:18pm UTC](https://discuss.elastic.co/t/logstash-and-filebeat-are-not-working-with-my-private-ca-system/51195/1 "2016-05-27T19:18:27Z")

</div>

I've created a root ca, and an intermediate ca. I signed my logstash server cert with the intermediate CA. I know my certificate system is working (as I'm using it on other software's and it's fine).

Problem is - does logstash and filebeat work with an intermediate CA or not? I see conflicting reports.

I've got the ssl set to true, ssl\_certificate is a PEM with my server cert -\> intermediate cert -\> root cert (in that order)

and then filebeat is set up to trust the root cert.

However, it's still not working. When I call logstash with openssl it only presents the Server cert.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 27, 2016, 8:50pm UTC](https://discuss.elastic.co/t/logstash-and-filebeat-are-not-working-with-my-private-ca-system/51195/2 "2016-05-27T20:50:31Z")

</div>

I was able to trust an intermediate CA in Filebeat, but it required using both the root and intermediate CA. See this issue: [Clarify intermediate CA usage in Logstash TLS docs · Issue #1494 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/1494)

> [@Sean\_Bollin](#):
>
> When I call logstash with openssl it only presents the Server cert.

After Logstash/JRuby [fix their handling of the CA chain](https://github.com/logstash-plugins/logstash-input-beats/issues/64), then the server should return the full chain, and Filebeat should no longer need the work-around I described in the issue.

---

<div class="post-metadata">

**Author:** ![Sean\_Bollin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean_bollin/32/10000_2.png) [@Sean\_Bollin](https://discuss.elastic.co/u/Sean_Bollin)\
**Post date:** [May 27, 2016, 10:08pm UTC](https://discuss.elastic.co/t/logstash-and-filebeat-are-not-working-with-my-private-ca-system/51195/3 "2016-05-27T22:08:18Z")

</div>

awesome, working now.

i saw your issue on github before, but i thought it was referring to concatenating the certs to the logstash server cert (which is sometimes needed)..

thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:51pm UTC](https://discuss.elastic.co/t/logstash-and-filebeat-are-not-working-with-my-private-ca-system/51195/4 "2017-07-05T21:51:26Z")

</div>


