# Logstash cann not read encrypted key

**URL:** <https://discuss.elastic.co/t/logstash-cann-not-read-encrypted-key/324629>\
**Category:** Logstash\
**Created:** [February 3, 2023, 9:23am UTC](https://discuss.elastic.co/t/logstash-cann-not-read-encrypted-key/324629 "2023-02-03T09:23:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![AfeefGhannam](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@AfeefGhannam](https://discuss.elastic.co/u/AfeefGhannam)\
**Post date:** [February 3, 2023, 9:23am UTC](https://discuss.elastic.co/t/logstash-cann-not-read-encrypted-key/324629/1 "2023-02-03T09:23:26Z")

</div>

Hi,  
when we create an encrypted and compatible Logstash key, Logstash can not read the key and give the following error in log:

```auto
message=>"File does not contain valid private key: /etc/logstash/certs/logstash-pkcs8.key", :cause=>{:exception=>Java::JavaSecurity::NoSuchAlgorithmException, :message=>"PBES2 SecretKeyFactory not available"}

```

We generate the key using this command:

```auto
openssl pkcs8 -in input_key.key -topk8 -passin pass:password -out logstash.key -passout pass:password

```

When we generate the key without encryption **-nocrypt** , then is the key ok for Logstash and there is nor error in log.

Should we configure something extra to let Logstash accept the encryption of the key?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2023, 9:23am UTC](https://discuss.elastic.co/t/logstash-cann-not-read-encrypted-key/324629/2 "2023-03-03T09:23:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
