# Logstash elasticsearch communication fails in ssl

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-communication-fails-in-ssl/223438>\
**Category:** Logstash\
**Created:** [March 13, 2020, 3:15am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-communication-fails-in-ssl/223438 "2020-03-13T03:15:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajit519](https://avatars.discourse-cdn.com/v4/letter/a/8baadc/32.png) [@ajit519](https://discuss.elastic.co/u/ajit519)\
**Post date:** [March 13, 2020, 3:15am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-communication-fails-in-ssl/223438/1 "2020-03-13T03:15:08Z")

</div>

Hi all,

I am running Elasticsearch(6.8.0) and Logstash(6.8.0) in SSL. I followed the steps as mentioned in docs. instead of generating certificate from elasticsearch utility i generated from openssl, this self signed certificate generated on different box. Here are the settings i applied.

elasticsearch.yml  
xpack.security.enabled: true  
xpack.security.http.ssl.enabled: true  
xpack.security.transport.ssl.enabled: true  
xpack.security.http.ssl.key: server\_key.pem  
xpack.security.http.ssl.certificate: server\_certificate.pem  
xpack.security.http.ssl.certificate\_authorities: ca\_certificate.pem  
xpack.security.transport.ssl.key: server\_key.pem  
xpack.security.transport.ssl.certificate: server\_certificate.pem  
xpack.security.transport.ssl.certificate\_authorities: ca\_certificate.pem  
xpack.security.transport.ssl.verification\_mode: certificate

logstash output config path  
output {  
elasticsearch {  
hosts =\> ["[https://localhost:9200](https://localhost:9200)"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][\_index]}"  
document\_type =\> "%{[@metadata][\_type]}"  
template\_overwrite =\> "true"  
cacert =\> '/data/nroot/ca\_certificate.pem'  
user =\> 'logstash\_system'  
password =\> Ar3woCkP8AVlbT5CACTy  
}  
}

whenever logstash elasticsearch plugin try to process the message it fails with error.**`- An unknown error occurred sending a bulk request to Elasticsearch. We will retry indefinitely {:error_message=>"Host name '127.0.0.1' does not match the certificate subject provided by the peer (O=server, CN=ms-axon-install.local)", :error_class=>"Manticore::UnknownException"`**

since i added xpack.security.transport.ssl.verification\_mode: certificate should ignore hostname verification. then why also this failing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2020, 3:15am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-communication-fails-in-ssl/223438/2 "2020-04-10T03:15:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
