# Logstash behavior with cacert field in elasticsearch output (6.4 logstash, 5.6 ES)

**URL:** <https://discuss.elastic.co/t/logstash-behavior-with-cacert-field-in-elasticsearch-output-6-4-logstash-5-6-es/179798>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [May 6, 2019, 3:29pm UTC](https://discuss.elastic.co/t/logstash-behavior-with-cacert-field-in-elasticsearch-output-6-4-logstash-5-6-es/179798 "2019-05-06T15:29:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![preddy75](https://avatars.discourse-cdn.com/v4/letter/p/a88e4f/32.png) [@preddy75](https://discuss.elastic.co/u/preddy75)\
**Post date:** [May 6, 2019, 3:29pm UTC](https://discuss.elastic.co/t/logstash-behavior-with-cacert-field-in-elasticsearch-output-6-4-logstash-5-6-es/179798/1 "2019-05-06T15:29:12Z")

</div>

Hi,

What exactly is behavior of logstash with this configuration?

output {  
elasticsearch {  
user =\> ""  
password =\> ""  
ssl =\> "true"  
ssl\_certificate\_verification =\> false  
hosts =\> []  
cacert =\> "/rootcafile.pem"  
manage\_template =\> false  
index =\> ""  
document\_type =\> "%{[@metadata][type]}"  
}  
}

Will it will verify the elasticsearch on the end via the rootca with have configured as part of the "cacert" property above? It will then send the user/password over the established SSL connection?

Below is a list of our overall config here. I have the situation listed above, then our common logstash case (which I understand), then our elastic server config. I am only uncertain above the case where we use the cacert in logstash and what exactly happens there in the flow.

a few logstash's

output {  
elasticsearch {  
user =\> ""  
password =\> ""  
ssl =\> "true"  
ssl\_certificate\_verification =\> false  
hosts =\> []  
cacert =\> "/rootcafile.pem"  
manage\_template =\> false  
index =\> ""  
document\_type =\> "%{[@metadata][type]}"  
}  
}

most of our other logstash's

output{  
elasticsearch {  
hosts =\> ["edited"]  
index =\> ""  
user =\> ""  
password =\> ""  
template =\> ""  
template\_name =\> ""  
template\_overwrite =\> true  
ssl =\> true  
ssl\_certificate\_verification =\> false  
truststore =\> ""  
truststore\_password=\> ""  
}  
}

elasticsearch server

searchguard:  
enterprise\_modules\_enabled: false  
ssl:  
transport:  
enable\_openssl\_if\_available: true  
enabled: true  
keystore\_type: JKS  
keystore\_filepath:   
keystore\_password:   
truststore\_type: JKS  
truststore\_filepath:   
truststore\_password:   
enforce\_hostname\_verification:   
http:  
enable\_openssl\_if\_available: true  
enabled: true  
keystore\_type: JKS  
keystore\_filepath:   
keystore\_password:   
truststore\_type: JKS  
truststore\_filepath:   
truststore\_password:   
# Admin users  
authcz.admin\_dn:  
-

Have read about the cacert here, but still would like to know the details of the specific config I posted.  
[https://www.elastic.co/guide/en/logstash/6.3/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-cacert](https://www.elastic.co/guide/en/logstash/6.3/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-cacert)

Thanks

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 7, 2019, 8:45am UTC](https://discuss.elastic.co/t/logstash-behavior-with-cacert-field-in-elasticsearch-output-6-4-logstash-5-6-es/179798/2 "2019-05-07T08:45:18Z")

</div>

> [@preddy75](#):
>
> Will it will verify the elasticsearch on the end via the rootca with have configured as part of the "cacert" property above?

No, it will not verify the certificate that Elasticsearch presents as you have explicitly asked it not to:

> [@preddy75](#):
>
> ssl\_certificate\_verification =\> false

> [@preddy75](#):
>
> It will then send the user/password over the established SSL connection?

yes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2019, 8:45am UTC](https://discuss.elastic.co/t/logstash-behavior-with-cacert-field-in-elasticsearch-output-6-4-logstash-5-6-es/179798/3 "2019-06-04T08:45:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
